Contain and preserve.
Identify affected systems and accounts, isolate coordinated paths, preserve evidence instructions, and record who can authorize destructive action.
Exit proof: scope record + containment authorityRebuild trusted coordination.
Establish known-clean administrator access, out-of-band contacts, insurer and counsel routes, vendor escalation, time source, and a recovery decision channel.
Exit proof: trusted identity + communication pathAccept the recovery environment.
Confirm the target network, devices, management tools, security controls, updates, logging, and restore method before introducing backup data.
Exit proof: accepted target + rollback pointRestore, validate, reconcile.
Recover by clinical dependency, let authorized owners test real work, record exceptions, and reconcile appointments, messages, orders, results, images, charges, and files.
Exit proof: workflow acceptance + reconciliation ownerThe incident authority defines when recovery work can reconnect to production. A system being online is not the same as the practice accepting the workflow.

