CRA full compliance required 453 days left What it means for you
THZ Networks Under attack? SOS — incident response, any hour of any day

GUIDES

The first hour of a ransomware incident

What to do, in order, before anyone who knows what they are doing has arrived — and the two instincts that destroy the evidence.

Disconnect. Do not power off.

Pull the network, not the plug. Memory holds the encryption keys, the running processes and often the operator's own tooling; powering a machine off throws all of it away and can make the difference between recovering and paying.

The second instinct to resist is restoring immediately over the top. A restore onto an estate the attacker still has access to gives you the same incident again, this time without the backup.

Start the clocks, in writing

Note the time you became aware. Two deadlines may now be running: a NIS2 early warning within 24 hours if you are in scope, and a GDPR breach notification within 72 hours if personal data was reachable. They go to different authorities and they are not the same assessment.

Write down what you know and when you knew it as you go. Reconstructing a timeline a week later from memory is the single most expensive part of most incidents.

Preserve before you clean

Keep the logs. Firewall, VPN, domain controller, mail gateway and endpoint, and check the retention window before somebody helpfully rotates them. The entry point is usually visible in logs that are days old, not in the machine that is encrypted.

Take an image of at least one affected system before it is rebuilt. Nobody has ever regretted having it.

Say less, to fewer people, on a channel they do not control

Assume email and chat are readable by whoever is inside. Move incident coordination to something out of band — phones, a separate messaging service — and keep the circle small until you know what happened.

Then call somebody who does this for a living. Our number is on the under-attack page, and it is answered.