What steps should I take if I have been the victim of a ransomware attack?
What should you do if you have been attacked?
The National Cyber Security Center NCSC advises the following steps:
Procedure after a ransomware attack:
Damage limitation
- Immediately disconnect infected systems from the network so that the encryption does not spread further.
- Ensure that the backup is safe.
- Contact IT service providers and specialised service providers.
Identification of the infected systems
“Log files” help to find out which systems are affected.
Detection
With the help of various “log files” and other software, one can find out the point of entry.
Criminal complaint and forensic investigation
If you file a criminal complaint, it needs a forensic investigation.
Backup of the encrypted data
In case your backup has also been encrypted, keep the encrypted data on an external data carrier in order to be able to access the data later (if the key turns up).
Reinstallation of the affected systems
Reinstall systems and restore data.
Under certain conditions, a partial or complete restoration of the data is possible even without a data backup. A decryption may work under certain circumstances if:
- the ransomware has not encrypted or deleted shadow copies in Windows
- Snapshots of virtual machines or previous file versions exist in cloud servises
- forensic recovery of deleted files is possible
- the ransomware has flaws in its encryption function or the key for decryption is known.
What can be done to protect oneself against cyberattacks?
This is the question that all companies are asking themselves at the moment.
MOUNT10 therefore launched the Swiss Cyber Defence Initiative in October 2020 with the cooperation of various industry partners such as Swisscom and Microsoft.
Swiss Cyber Defence DNA (SCD-DNA) is a guide for your SME to protect yourself easily and efficiently against cybercrime threats and major financial damage.
The guide is free of charge and solution-neutral.
Measure No. 1 refers to “Current unchangeable data backup / read-only backup”.
Source: https://www.ncsc.admin.ch/ncsc/de/home/infos-fuer/infos-unternehmen/vorfall-was-nun/ransomware.html