PS ProTech(305) 699-5652
← All posts

All professional firms

The first hour of a ransomware attack

· PS ProTech · 3 min read

Someone opens a file and it won't load. Then a note appears on the screen demanding payment. What your firm does in the next hour decides how bad this gets.

Print this. A plan you can only read on a locked computer is no plan.

Minute zero to ten: stop the spread

Disconnect the affected computer from the network. Unplug the network cable and turn off Wi-Fi. Don't turn the computer off; it may hold evidence, and some recovery options need it running.

Disconnect anything that looks affected next. If files on the shared drive are changing names or won't open, disconnect that too.

Tell everyone to stop. One message to all staff, by phone or text if email is affected: don't open shared files, don't plug in drives, don't try to fix it.

Ransomware spreads across a network. The first ten minutes are about limiting how far it gets.

Minute ten to thirty: make the calls

Call your IT provider. This is the moment they exist for. If you don't have one, you need an incident response firm, and your insurer can name one.

Call your cyber insurer. Most policies require prompt notice and many require you to use their approved responders. Calling first can protect your coverage.

Don't contact the attacker, and don't pay. That decision comes later, with advice. Paying doesn't guarantee your files back, and in some cases it can be unlawful.

Minute thirty to sixty: work out what you have

Your responders will lead this, but you can gather the answers:

  • What's affected? Which computers, which drives, which cloud accounts.
  • When did it start? The first odd thing anyone noticed.
  • Are the backups safe? Where are they, and are they separate from the network that was hit?
  • Was anything taken? Modern attacks often copy files before locking them, then threaten to publish. That changes your obligations.

Write everything down with times. You'll need it for your insurer and possibly for regulators.

The hours after

Change passwords from a clean device, starting with email and administrator accounts.

Decide who needs to be told. If client information was accessed or taken, you may have to notify clients and regulators, and for some professions the deadlines are short. Get legal advice early. Our industry pages set out what's at stake for law firms, accounting firms and others.

Restore from backup, once your responders confirm the attacker is out. Restoring too early can put you straight back where you started.

What decides how this goes

Three things, all of which are settled before the attack:

  1. Whether you have backups the attacker couldn't reach. See backup and recovery.
  2. Whether the attack was caught early. Protection that watches for ransomware behavior, and monitoring that someone acts on, can stop it at one machine. See endpoint security and SIEM and managed detection and response.
  3. Whether you had a plan. Firms that have written down who to call lose hours. Firms that haven't lose days.

Write your one-page plan now

It needs four things: the phone numbers of your IT provider and insurer, how to disconnect a computer, who has authority to make decisions, and where the backups are.

If you'd like help working out where you stand, our free IT and cybersecurity review covers recovery, and the security checklist lets you check the basics yourself.

See what it costs for your firm.

Build a plan in two minutes. No call required.