If this is happening right now
Do not turn anything off.
Disconnect affected machines from the network, but leave them powered on. Shutting down destroys the evidence needed to work out what happened, and your insurance claim may depend on it.
We answer during business hours, and after hours the phone reaches someone who can help. You do not need to be a client.
The first hour, in order.
Work down this list. The first two matter most and are the ones people most often get wrong.
-
1
Disconnect from the network. Do not power anything off.
Unplug the network cable or turn off wifi on affected machines. Leave them running. Powering down destroys evidence held in memory that is often the only way to determine what was taken and how they got in, and your insurer may require that analysis.
-
2
Stop all outgoing payments right now
Call your bank directly on a number you already know. If any wire or ACH went out in the last 72 hours, say the words "fraudulent wire, please initiate a recall." Speed matters more than certainty here, recall windows are short.
-
3
Do not pay anything, and do not reply
Do not contact whoever is demanding payment. Do not click their links or open their portal. Every interaction gives them information, and paying is a decision for later, with your insurer and counsel involved.
-
4
Call your cyber insurance carrier before anyone else you hire
Most policies require you to use their approved responders and to notify them within a set window. Hiring your own firm first can void coverage. The number is on your policy documents.
-
5
Assume email is compromised and move to another channel
Coordinate by phone or text, not email or chat. If an attacker is in the mailbox, they are reading your response plan as you write it, and this is exactly how a second fraudulent payment gets approved.
-
6
Write down everything, with times
What you saw, when, who noticed, what you did. Rough notes on paper are fine. Your insurer, your lawyer, and whoever investigates will all need this, and nobody will remember accurately in three days.
Whatever else you do, not these.
-
Do not turn machines off or reboot them
-
Do not delete anything, including the ransom note
-
Do not restore from backup until someone has confirmed how they got in
-
Do not reset every password from a machine that may be compromised
-
Do not tell staff to "keep working around it" on the same network
-
Do not post about it publicly before you have advice
Once it is contained.
The urge afterwards is to restore everything and move on. Resist it for a few days. Restoring into an environment where the original route in is still open is how businesses get hit twice in a month, and the second time is usually worse.
Before you go back to normal, someone needs to establish how they got in, what they reached, whether anything is still running, and what data left the building. That last one determines your legal notification obligations, which have deadlines.
We help businesses through this whether or not they are clients, and whether or not they become clients. If you are in the middle of it right now, call. If you are reading this because you want to be ready, start with the self-assessment, question nine asks how long you would be down, and most people discover they have never actually worked it out.
Not an emergency, but it could have been? That is the best possible time to look.
Take the assessment