Disconnect the affected systems from the network, but do not switch them off. Do not pay straight away, preserve evidence, and check the backup before restoring anything: if it was encrypted or infected too, restoring makes things worse. Report the incident, even while you do not yet know everything.
The first hour
- Isolate, do not power off
- Pull the network cable and turn off wifi. Powering down wipes memory, and that sometimes holds keys and traces needed later.
- Establish how far it reaches
- Which systems, which drives, which backup locations? Network shares and connected cloud folders are often caught as well.
- Do not change passwords from an infected system
- Do that from a device you know is clean.
- Record what you see
- Photos of the message, timestamps, file names. This is needed later for the report and the investigation.
The first day
- Check the backup before restoring
- Was the backup online or disconnected? Restoring from an infected backup simply brings the problem back.
- Report the incident
- Where personal data is involved, there is a duty to notify the supervisory authority, in principle within 72 hours. Reporting to the police is possible alongside that.
- Tell the people it affects
- Customers, suppliers and staff would rather hear it from you than from someone else.
- Paying is a last resort
- Payment offers no guarantee, funds the next attack and can be legally problematic. Discuss it only once every other route is closed.
Afterwards
- Rebuild clean
- Cleaning an infected system is less reliable than reinstalling from a clean base.
- Find out how they got in
- Without that answer the same door stands open again next month.
- Revisit access
- Multi-factor authentication, fewer rights per account, and a backup that cannot be reached from the network.
We help limit the damage, restore safely and close the route it came in through. That last part is what stops it happening again six months from now.
More on this →