Ransomware: what to do in the first hour

KINNEX Team5 min read


The first hour after discovering ransomware sets the cost of everything that follows. Having a plan written beforehand removes panic from the decisions.

Contain

  • Disconnect affected machines from the network. Pull the cable or disable Wi-Fi; do not just shut down if you can avoid it, because memory can hold useful evidence.
  • Disable shared accounts and any account that may be compromised.
  • Isolate backup systems so they cannot be reached from the affected network.

Assess

Find out what is affected, how far it spread and what data may have left. Note the time, the ransom note and any file extensions.

Notify

Bring in your incident contact, management, your insurer if you hold cyber cover, and legal counsel. In India, incidents of certain kinds must be reported to CERT-In within the required period. Check current rules with your advisers.

Preserve

Keep logs, images of affected systems and the ransom note. Do not wipe machines until evidence is captured.

Avoid common mistakes

  • Do not negotiate or pay without legal and expert advice.
  • Do not restore onto a network that still has the attacker in it.
  • Do not assume backups are clean; check before restoring.

Recover

Rebuild from known-good images, restore data from tested backups, reset all credentials and close the entry point before reconnecting.

Prepare now

Keep an incident contact list, an offline copy of this plan, immutable backups and a practised restore.

Bring us the site, the challenge or the target outcome

Book an infrastructure assessment, or reach KINNEX directly by phone or WhatsApp.