To be fair, if you are taken over by ransomware, it's probably the best decision to start from scratch and redesign your network so that this sort of thing is mitigated in the future.
Because if it's an insider threat then you should have protections in place to identify bad actors so that they know they will be caught if they even try. If you don't then what are you even doing?