I have seen talk about the issue of your restore image containing unpatched (or even zero day) vulnerabilities. So you need to worry about your restored systems quickly becoming compromised again.
Also that your backups should be pulled to an independent backup system instead of pushed so the compromised machine can't potentially ruin your backups. (Then you would need to wait longer for your off site backup to restore your backup.)
If you can't audit that it was simply a successful phishing attempt and you just need to revoke keys and passwords. I suppose a super expensive solution would be to use multiple operating systems and software platforms so you have a chance to get yourself back up and running on a different environment with different vulnerabilities that aren't being presently being attacked?
I'm excited to hear from someone who sounds like a professional.
I suppose this is really a more general question of how do I prevent remote code execution? Traffic analysis probably has to be done on an independent gateway? I assume that's hard in a large network vs botnet... Block Tor ips from any ports except your application/web ports? Because I'd like to support the good guys on Tor...