Your preparation
0 of 0 safeguards readyMake the next decision with evidence
Stop encryption and lateral movement, preserve evidence, protect clean backups, and rebuild business services without reintroducing the attacker.
Capture before evidence disappears
- Record the first affected host, ransom note, file extensions, processes, accounts, network connections, scheduled tasks, and security alerts.
- Preserve volatile memory and forensic images where practical, plus identity, endpoint, VPN, email, cloud, firewall, storage, and backup logs.
- Inventory encrypted, deleted, exfiltrated, and unaffected systems by business service, owner, recovery priority, and backup state.
- Protect ransom messages, wallet details, contact channels, samples, and attacker claims without opening files on production devices.
Decisions that change the response
| Question | Act when | Action |
|---|---|---|
| Disconnect systems? | Encryption, destructive commands, command-and-control, or lateral movement is active. | Isolate affected network segments and identities; avoid powering off systems needed for volatile evidence unless damage continues. |
| Restore or investigate first? | Critical services are down but the entry path and persistence are unknown. | Run investigation and clean recovery in parallel. Never attach clean backups to a hostile environment. |
| Engage the attacker? | Leadership, counsel, insurer, sanctions review, and law enforcement have assessed the decision. | Use experienced responders. Do not improvise payment or communication from affected systems. |
Proof that recovery worked
- Known persistence, hostile accounts, command paths, and entry vectors are removed or blocked.
- Restored services come from verified images and backups in a segmented clean environment.
- Identity, endpoint, network, backup, and data-access monitoring show no continuing hostile behavior.
- Business owners validate data completeness and function before systems leave heightened monitoring.
Controls to put in place
- Keep immutable, offline or isolated backups with separate administration and tested restore objectives.
- Require phishing-resistant MFA, remove standing admin rights, segment networks, and harden remote access.
- Deploy managed endpoint detection and central logs that compromised administrators cannot erase.
- Maintain a clean-room rebuild plan, service priorities, insurer route, legal contacts, and out-of-band communications.
Assume identity, endpoints, and primary backups are unavailable. The team must isolate a test segment, invoke outside contacts, choose restore priorities, rebuild one service in a clean environment, and verify data.
Contact specialist responders, insurer, counsel, cloud and security providers, and appropriate law enforcement immediately. Treat claimed or possible data theft as a separate breach investigation.
What this means
Ransomware may include both encryption and data theft. Treat nearby identities, backups, cloud accounts, and connected devices as potentially compromised.
Warning signs
- Files become unreadable, renamed, or replaced with ransom notes.
- Security tools, backups, or logs are disabled.
- Unusual encryption, archiving, or outbound data transfer appears.
- An attacker claims to possess customer or company data.
Recover now
First 15 minutes
- Isolate affected devices and workloads from networks without powering them off unnecessarily.
- Protect backups and identity systems from the same attacker.
- Preserve ransom notes, logs, alerts, timestamps, and system images.
- Activate qualified security, legal, insurance, and law-enforcement contacts.
Today
- Determine affected systems, accounts, data, and likely initial access.
- Rebuild from known-good images and scan backups before restoration.
- Rotate credentials from clean devices after the access path is contained.
- Assess data theft and notification duties before making public claims.
Verify recovery
- Restored systems come from a trusted point before compromise.
- The initial access path and persistence are removed.
- Old credentials fail and clean monitoring shows no recurrence.
- Required customer or authority notifications are tracked.
Prepare now
Access
- Privileged access uses phishing-resistant MFA and separate admin accounts.
Backups and evidence
- Critical data has encrypted, offline or immutable backups.
- Restoration is tested and backup administration is isolated from production.
Contacts and ownership
- Security, legal, insurer, hosting, and law-enforcement routes are documented.
Practice
- A clean-environment restoration drill has been completed.
Common mistakes
- Restoring before removing the attacker. Clean systems can be reinfected.
- Assuming encryption means no data was stolen.
- Paying without qualified advice. Payment does not guarantee recovery or deletion.
Sources
Reported by the people who handled it
Lessons from real incidents
These are operator postmortems and official incident reports, condensed into one lesson you can reuse.Learning lessons from the cyber-attack
TL;DRAttackers exfiltrated data and encrypted or destroyed much of the server estate. Secure copies of digital collections survived, but missing clean infrastructure and legacy applications that could not run on the replacement environment made restoration slow and incomplete.
Learning to reuseBack up the recovery dependencies, not just the data. Prove that identity, networking, infrastructure, keys, vendors, and legacy applications can be rebuilt together on a trusted environment.
Read the full report(opens in a new tab)Cyber-attack on Hydro
TL;DRThe attack affected Hydro's global organization. Teams kept major operations running through labor-intensive manual workarounds while internal and external specialists reviewed, cleaned, and safely rebuilt PCs and servers from backups.
Learning to reuseBusiness continuity and technical recovery are parallel jobs. Rehearsed manual operations can preserve essential work while responders build a clean environment instead of reconnecting uncertain systems too early.
Read the full report(opens in a new tab)