If you're wondering how to undo ransomware damage after encryption has already started, your options depend entirely on whether a decryptor exists for your variant and how clean your backups are.
Restore from clean backups
Make sure you know how to delete ransomware executables fully and that your environment is completely malware-free before restoring backups. Plug into an infected system, and you just reinfected yourself. Once you've verified your environment, restore from your most recent clean backup.
No backups? Your options narrow quickly. Visit nomoreransom.org to see if free decryptors are available for your variant. If none exist, consider bringing in professional forensics and start documenting your process for your insurance company. Do not pay the ransom. According to Verizon, 64% of ransomware victims declined to pay last year, up from 50% in the previous two years.
Reset credentials
Cybercriminals are savvy, and they most likely nabbed your passwords, too. After containment, and before you re-enable any connected systems, reset all passwords—especially for admin accounts, service accounts, and any account with elevated privileges. Enable multi-factor authentication (MFA) wherever possible.
Validate before reconnecting
Make sure your systems are clean before reconnecting them to your network. Run your endpoint security solutions, check for malicious processes and scheduled tasks, and investigate how the attacker may have maintained persistence.
Rushing through the reconnection phase causes more failed recoveries than almost anything else.