The first hours: step by step
- Isolate. Disconnect infected systems from the network to stop the spread. Do not shut machines down blindly — it can destroy evidence.
- Assemble the response team. Pre-assigned roles: who leads, who handles IT, who handles communications.
- Assess the scope. What is affected, which processes are down, whether there is a data breach.
- Activate the continuity plan. Switch critical processes to backup options (see BCP).
- Communications. Agreed messages for customers, partners and staff; notify the regulator if required.
- Recovery. Bring systems back from isolated backups by priority (see DRP).
- Post-incident review. Causes, lessons, fixes — so it does not happen again.
What to prepare in advance
- Response team roles and contacts (on paper / in a messenger, available offline).
- Isolated backups and a tested recovery procedure.
- Communication templates for customers and partners.
- A ransomware-scenario drill.
FAQ
What is the very first thing to do in an attack?
Isolate infected systems from the network to stop the spread, and assemble the pre-assigned response team. Do not shut machines down blindly — you can destroy evidence.
Should you pay extortionists for decryption?
Usually no: payment does not guarantee recovery and encourages new attacks. Rely on isolated backups and a recovery plan.
Do you have to report an attack?
For certain organisations and data, notifying the regulator is required by law. Even when silence is formally allowed, root-cause analysis matters more than concealment.
Is your team ready for the first hour of a crisis
Plans are tested by scenarios, not by reading. The assessment shows the gaps, the corporate format works them through with your team on your processes.