Dalarna University's logo and link to the university's website

du.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • chicago-author-date
  • chicago-note-bibliography
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Återställning efter ransomware attacker: En studie av praktisk hantering och prioritering av verksamhetskritiska system
Dalarna University, School of Information and Engineering.
Dalarna University, School of Information and Engineering.
Dalarna University, School of Information and Engineering.
Dalarna University, School of Information and Engineering.
2026 (Swedish)Independent thesis Basic level (degree of Bachelor), 10 credits / 15 HE creditsStudent thesisAlternative title
Recovery After Ransomware Attacks : A Study of Practical Response and Prioritization of Critical Systems (English)
Abstract [en]

Ransomware attacks have become one of the most serious threats to organizations' information security, causing extensive operational disruptions and significant economic losses. When an attack occurs, it is rarely possible to restore all systems simultaneously, making it critical to prioritize which systems should be recovered first. Despite this, many organizations lack structured methods for making these prioritization decisions, particularly under the time pressure and uncertainty that characterizes an active incident.

The purpose is to identify the factors that influence the prioritization of IT systems during recovery after ransomware attacks, and to develop a conceptual scoring model that can serve as decision support for organizations in the recovery process. The study is based on a qualitative research strategy with semi-structured interviews conducted with professionals in IT security and incident management, as well as IT managers within the Swedish grocery retail sector.

The results show that organizations primarily identify critical IT systems based on their business processes rather than technical characteristics. The most influential factors in prioritization decisions are economic impact, time criticality in terms of Recovery Time Objective, and system dependencies. Systems such as point-of-sale systems and payment terminals are identified as the most critical within grocery retail, as their failure immediately halts core business operations.

Based on these findings, a conceptual scoring model was developed that evaluates IT systems across six weighted factors, generating a priority score on a scale from 0 to 100. The model was positively received by all respondents, who described it as a useful tool for structuring prioritization decisions, particularly in smaller and medium-sized organizations that lack established frameworks for incident response.

The study contributes both a concrete artifact in the form of the scoring model, and increased understanding of the practical factors that influence IT system prioritization during ransomware recovery within the grocery retail sector.

Abstract [sv]

Ransomware-attacker orsakar omfattande driftstopp och ekonomiska förluster för organisationer. Vid en attack är det sällan möjligt att återställa alla system samtidigt, vilket gör prioritering av IT-system avgörande. Trots detta saknar många organisationer strukturerade metoder för att fatta dessa beslut under tidspress.

Syftet med studien är att identifiera faktorer som påverkar prioritering av IT-system vid återställning efter ransomware-attacker samt att utveckla en konceptuell poängmodell som beslutsstöd. Studien bygger på kvalitativa semistrukturerade intervjuer med yrkesverksamma inom IT-säkerhet och IT-ansvariga inom den svenska dagligvaruhandeln.

Resultaten visar att organisationer identifierar kritiska system utifrån affärsprocesser snarare än tekniska egenskaper. De viktigaste prioriteringsfaktorerna är ekonomisk påverkan, Recovery Time Objective och systemberoenden. Kassasystem och betalterminaler identifieras som mest kritiska då ett avbrott omedelbart stoppar kärnverksamheten.

En poängmodell utvecklades som utvärderar IT-system utifrån sex viktade faktorer och genererar en prioriteringspoäng från 0 till 100. Modellen mottogs positivt av respondenterna och beskrevs som särskilt användbar för mindre organisationer som saknar etablerade ramverk för incidenthantering.

Studien bidrar med en konkret prioriteringsmodell samt ökad förståelse för praktiska faktorer vid ransomware-återställning inom dagligvaruhandeln.

Place, publisher, year, edition, pages
2026.
Keywords [en]
Ransomware, IT recovery, system prioritization, business continuity, disaster recovery, critical systems, decision support
National Category
Information Systems
Identifiers
URN: urn:nbn:se:du-54049OAI: oai:DiVA.org:du-54049DiVA, id: diva2:2078954
Subject / course
Microdata Analysis
Available from: 2026-06-24 Created: 2026-06-24

Open Access in DiVA

fulltext(1217 kB)29 downloads
File information
File name FULLTEXT01.pdfFile size 1217 kBChecksum SHA-512
f9daf2813f0c8ba8e32efea2332fe3ebe706c50f9ce02d913c3d620a54b38320888ae68d69fdfa99b1a0b70aa8bff1037d446dc46cb84f2273b378d3da619e8e
Type fulltextMimetype application/pdf

By organisation
School of Information and Engineering
Information Systems

Search outside of DiVA

GoogleGoogle Scholar
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 184 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • chicago-author-date
  • chicago-note-bibliography
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf