Help, we have been hit by a ransomware attack. What now?
Phase 1. Getting help
The steps in this article are sound. Yet cybercrime changes so incredibly quickly that we recommend engaging an external specialist. A good ethical hacking team knows exactly what the ripple effects and risks are for your network and systems.
Phase 2. Investigation
Objective: establish clarity so you can take the right steps.
- How far does this attack extend?
- What is the impact?
- Where is that impact greatest?
- What needs to be set in motion immediately?
- Who around us needs to be informed?
Phase 3. Containment
Objective: limit damage by preventing spread
Isolate affected systems and restrict incoming or outgoing traffic, depending on the impact. To isolate a system immediately, unplug its network cable or switch off Wi-Fi. NEVER switch the systems off or unplug their power, because that erases all traces.
Phase 4. Removal
Objective: clean up your network
Examine your systems, remove all malicious elements and close off attackers' access.
Phase 5. Recovery
Objective: restore normal access
Restore clean backups. You can now gradually increase access to and availability of systems and applications again.
Bonus tip: look after your IT staff. They have probably endured considerable stress during this ordeal, and you will need them for some time yet…
Phase 6. Consolidation
Objective: increase your security level so you are not hit again in future.
Reflect and evaluate. Put everything you learn into clear processes to increase your maturity level. Develop a clear decision and communication tree to prevent panic-driven reactions.
