Most institutions discover their true restore time during the incident, which is exactly the wrong moment to find out.

Every institution eventually faces the question of whether it can operate without its systems. Ransomware simply asks that question without warning, and usually on the worst possible day of the month.
The difference between institutions that recover in days and those that lose months is decided long before the incident, in unglamorous decisions about backups, plans and practice.
A backup sitting on the same network the attacker reached is not a backup. Recovery depends on copies kept offline or otherwise isolated, retained far enough back that they predate the intrusion, and restored in a test at least once so you know how long a restore genuinely takes. Most institutions discover their restore time during the incident, which is exactly the wrong moment.
A response plan needs named decision makers, an escalation path that works outside office hours, a communication approach for staff, customers, regulators and funders, and a clear position on payment agreed in advance rather than under pressure.
Then rehearse it. A tabletop exercise lasting two hours will expose gaps a written plan never reveals, usually within the first fifteen minutes, and almost always in areas nobody expected.
Keep isolated offline backups
Test restores, not just backups
Name your incident decision makers
Build an out of hours escalation path
Agree a payment position early
Run a tabletop exercise
Nakawa, Kampala, Uganda
Uganda and East Africa
Onsite and remote
John Doe joined UHA
12 people registered today
ECG Interpretation Workshop