A Familiar Situation
Ransomware doesn't announce itself politely. It usually shows up as a monitoring alert flagging unusual file activity across several servers in the middle of the night, files being encrypted in real time. By the time a response team gets there, part of the environment may already be locked, with a ransom note left behind. This is exactly the scenario good backup and disaster recovery planning is built for, see our cyber security tips for how to reduce the odds of it happening in the first place.
Here's how we approach that scenario when it happens.
How We Approach It
- Immediately isolate affected systems from the network to stop the spread
- Confirm the scope of the compromise and identify which backups remain clean
- Coordinate with the client's cyber insurer and their specialist incident response and legal advisors, that's a conversation for the right specialists, not something an IT provider should handle alone
- Rebuild affected systems from clean, immutable offsite backups rather than paying for a decryption key
- Aim to restore full operation within 48 hours of initial detection
- Follow up with a full Essential 8 uplift, enforced MFA, EDR and network segmentation, so the same door can't be used twice
What You Can Expect
Businesses with the right backup architecture in place can be back operating within days using their own clean backups, without paying a ransom or negotiating with an attacker directly. The bigger win comes after: a genuinely hardened environment and a tested recovery plan, instead of relying on hope.
This page describes our general approach to a common type of incident, illustrative rather than a specific named client, with results that will vary by business and the severity of the incident. If you'd like to understand your own ransomware readiness, get in touch for a free assessment.