There were over 187 million ransomware attacks in 2019. That’s over 500,000 attacks on businesses every single day. If you have not yet been a victim of a ransomware attack, the odds are that it is just a matter of time. And if you have already been breached, you’re not immune. When that day comes, it is essential that you know what to do to minimize the impact to you, your team, and your business.
When that day comes, it is essential that you know what to do to minimize the impact to you, your team, and your business. Here is a quick overview of the steps your organization will need to take to deal with an active ransomware attack:
Establish a communications and update protocol with a designated contact for each business vertical. For example, commit to updating all relevant team leads every three hours on the situation. This is an important step to avoid people constantly asking for updates and preventing your team from focusing on containment.
Even after an attack is over, it is more than likely that your attackers still have a foothold in your network. It is critical that you identify any active malware, or persistent leftovers that are still communicating to the command-and-control (C2) server. Common persistence techniques include:
Now it’s time to revisit the legal team. It’s important to report to all entities, such as your legal team and insurance company. You should also determine if reporting to law enforcement is needed and required.
Talk to a Cybersecurity Advisor today at IRM Consulting & Advisory Check out our Marketplace
Our diverse industry experience and expertise in Cybersecurity, Information Risk Management and Regulatory Compliance is endorsed by leading industry certifications for the quality, value and cost-effective services we deliver to our clients.