Problem
In a wiper attack there is nothing to decrypt.
The only way back is restoration.
With ransomware there is at least a key. With a wiper there is none. Nothing to negotiate, nothing to decrypt, nobody to pay. The only way back is restoration.
Two cases, both publicly documented:
~6 months NotPetya 2017 at Merck: tens of thousands of machines
disabled; restoration took around six months.
9 days At Maersk roughly 49,000 endpoints were affected. Bringing
back the identity infrastructure alone took nine days.
Both companies had detection. Both had backups. What was missing was the layer in between: a verified, ordered, automatic return to operation.