We talk often about stolen data. We rarely talk about the silence of the cash registers.

Key points

  • A ransomware attack shut down every store in the chain for more than a week.
  • The dominant cost was not the ransom, but the halt in operations.
  • The company refused to pay, and employee data was published.
  • A backup that has never been restored is not a backup, it is an assumption.

What happened at London Drugs?

On April 28, 2024, the LockBit ransomware group struck London Drugs’ head office. The chain closed all eighty of its stores across western Canada for more than a week. The company refused to pay the ransom demanded.

The attackers then published employee records (human resources, medical, and financial information) on the dark web. This is how double extortion works: pay to decrypt, then pay again to prevent publication.

Refusing to pay is a defensible decision, and Canadian authorities recommend it. It comes with a cost, in this case the disclosure of employee data, and that cost needs to be planned for: affected individuals must be supported, which means thinking it through beforehand.

Why does downtime cost more than the ransom?

Because ransomware doesn’t just steal data, it shuts down the business. Every day without point of sale, logistics, or billing carries a real cost, and that cost keeps accumulating throughout the rebuild, long after the attack itself has stopped.

This is no longer an “IT” problem: the entire operation grinds to a halt. A retailer that can no longer process payments doesn’t defer its revenue to the next day, it loses it.

flowchart TD A[LockBit intrusion at head office] --> B[Systems encrypted] B --> C[80 stores closed for more than a week] B --> D[Ransom demanded] D --> E[Refusal to pay] E --> F[Employee data published]

London Drugs could absorb the shock. A small or medium-sized business rarely can. Without cash reserves, an extended shutdown is not something you recover from, which is what makes recovery a more pressing question than prevention alone.

How does a small business actually prepare?

The only real defense fits in three numbers, the 3-2-1 rule: three copies of your data, on two types of media, with one copy off-site and isolated. Add to that a written recovery plan, rehearsed in advance, spelling out who does what, in what order, with which contacts, when the day comes.

  • Three copies, two media types, one off-site and isolated. Isolation is the piece most often missing: a backup reachable from the same network as what it backs up gets encrypted along with everything else.
  • A restoration that has already been tested. The green report you receive every morning tells you the job ran, not that a file can actually be recovered from it. We run this test as part of our assessments, and it sometimes changes the entire conversation.
  • A written recovery plan. In the first hours, someone has to decide between restoring quickly and preserving evidence. Those tradeoffs need to be worked out ahead of time, with names attached.
  • A restart order. Which system comes back first, which one can wait. Without that list, you end up restarting whatever is easiest rather than whatever actually unblocks the business.

RISS helps small and medium-sized businesses build backups that are genuinely isolated, test them, and rehearse the crisis scenario so recovery isn’t improvised.

FAQ

Should you pay a ransom?

Canadian authorities have been consistent: paying is not recommended. It guarantees neither data recovery nor that the data won’t be published, it funds the criminal ecosystem, and it marks you as a payer for future attacks. The real answer is built before the incident: an organization with healthy, tested backups doesn’t have to face that question under pressure, which is precisely when decisions go wrong.

Does our cloud provider protect us?

Partially, and not in the way most people assume. A cloud service protects against hardware failure, not against your own files being encrypted through a compromised account, nor against a deletion that syncs across every copy. What actually protects you is keeping immutable prior versions and a copy outside the account’s own perimeter. This capability often already exists in licenses you’re paying for, and it’s frequently turned off.

How long does recovery take?

That depends entirely on what was prepared beforehand, not on how sophisticated the attack was. An organization that has tested its restoration process is looking at hours or days; one that discovers the state of its backups only when it needs them is looking at weeks. We don’t quote a standard timeline, because a number given without first assessing your actual setup would be meaningless to you.

Sources