Ransomware: what to do in the first hour
KINNEX Team5 min read
The first hour after discovering ransomware sets the cost of everything that follows. Having a plan written beforehand removes panic from the decisions.
Contain
- Disconnect affected machines from the network. Pull the cable or disable Wi-Fi; do not just shut down if you can avoid it, because memory can hold useful evidence.
- Disable shared accounts and any account that may be compromised.
- Isolate backup systems so they cannot be reached from the affected network.
Assess
Find out what is affected, how far it spread and what data may have left. Note the time, the ransom note and any file extensions.
Notify
Bring in your incident contact, management, your insurer if you hold cyber cover, and legal counsel. In India, incidents of certain kinds must be reported to CERT-In within the required period. Check current rules with your advisers.
Preserve
Keep logs, images of affected systems and the ransom note. Do not wipe machines until evidence is captured.
Avoid common mistakes
- Do not negotiate or pay without legal and expert advice.
- Do not restore onto a network that still has the attacker in it.
- Do not assume backups are clean; check before restoring.
Recover
Rebuild from known-good images, restore data from tested backups, reset all credentials and close the entry point before reconnecting.
Prepare now
Keep an incident contact list, an offline copy of this plan, immutable backups and a practised restore.