So You’ve Been Hit by Ransomware – Here Are Some Critical Next Steps

June 21, 2021

by Prototype:IT

Benefits of Managed Services

Ransomware has become a consistent threat to many businesses including SMBs, resulting in daily attacks and loss of business continuity.  These breaches can be very costly, and in some cases, catastrophic and non-recoverable for loss of data and potentially shutting the doors to your business.

If your company experiences such an attack and your business screeches to a sudden halt, panic, and confusion in the “terror of the moment” can create further error and resulting damage.

Hopefully, your business never becomes the victim of such an attack but here are some important steps towards proper actions, including thinking ahead with effective disaster recovery planning.

1. Immediately Execute Your Business Continuity Plan

Your first critical step is to immediately implement your business continuity plan including disaster recovery.  Wait—your company has not invested in such a plan and related assets yet?  In today’s business environment of ever-increasing threats, business continuity and disaster recovery planning should be a top priority.

If you do have a plan in place, even if more general (ex. natural disasters) and not specifically designed for cyber threats, execute it immediately.  A cyberattack focused plan is, of course, more effective in these scenarios, but ensuring your firm’s business continuity is an essential initial step in this crisis. If your company’s foresight has allowed you to plan, now is the time to execute on that plan.

2. Focus on Damage Control

Once your business continuity plan is fully in motion, your focus must now quickly shift to the attack response, especially with regards to limiting the amount and spread of damage.  And with the continued evolution of ransomware and attacks, including polymorphic spread, the attack can occur quickly and become infectious across your entire business.  As such, the speed with response is critical to the lifeline of your company.

And damage control does equate to effective mitigation of the attack’s spread, including recovering affected systems, rebuilding impacted portions of the environment, and capturing as much forensic data as possible for review and future prevention.  While the “heat of the moment” can create a first thought of literally shutting everything down, you should instead focus on disconnecting network assets to limit the attack’s radius, but not shutting down the power given that doing so can result in the loss of vital data and analytics including reference data for the attack itself.

3. “Business-wide” Response

With the continuous evolution of ransomware, including multi-pronged attacks that not only hold your data hostage but also threaten a damaging leak, your response must involve more than your internal IT staff and/or IT support provider.  You’ll need to quickly engage other functional areas and parties including your insurance provider, your legal department, key partners and vendors, and even your marketing group to provide vital communications to staff and potentially clients, and to begin developing public relations material for brand damage control.

4. Take Your Communications and Data Back-Ups Offline

Accurate and expedient communications are key during the attack response period.  But conducting such communications through your business email or communications platforms such as internal instant messaging may undermine your mitigation efforts.  Given the high probability of your attacker monitoring communications over your network, you may be providing them with the details and status of your response.  Taking these communications outside of your company’s normal applications and offline will bolster your chances of successful resolution.

As a business continuity and disaster recovery best practice, your company should already be not only performing local back-ups, but also off-site storage of back-ups to ensure data redundancy and enhanced recovery.  But if this not the case in your business and you identify a ransomware attack in real time, you need to quickly disconnect your backups from the network and move them offline.  Sadly, if you have not realized the attack until hours after initiated, it could be too late to prevent a disastrous impact.  As such, the best response is to proactively have the right business continuity and disaster recovery plans and solutions in place prior to a cyberattack ransomware event.

5. Remain Vigilant with Real-Time Threat Monitoring

As discussed above, your response’s effectiveness will depend heavily how quickly your systems and solutions detect the threat.  For example, whether they’ve been able to gain access to and already encrypt your data. If discovery comes after this point, your ability to fight back with a strong response is severely limited.  And therefore, 24×7 proactive monitoring, cutting edge security solutions and the right team are essential to best-in-class network security.

The best safeguard when it comes to data and network security is proactive prevention that leverage a knowledgeable, effective 24×7 support team. This gives your company the control and power to identify, isolate and mitigate cyberattacks including ransomware, and ensure a safe, secure environment for your business, customers, and data.

Free Network Assessment:

Get In Touch

Newsletter