Ransomware (ransomware) encrypts your files and demands a ransom to give them back. Often, the attackers have also copied data and threaten to publish it. SMEs are hit as much as large companies, because the attacks are automated.
The first ten minutes
- Disconnect from the network the affected machines: cable unplugged, Wi-Fi turned off. That is what stops it spreading.
- Don’t switch it off if you can avoid it: the memory holds traces that help understand what happened.
- Unplug any backups still connected: external disk, network drive.
- Warn everyone not to open anything and not to “try” anything.
- Take a photo of the message on the screen.
What not to do
Do not pay in a hurry: nothing guarantees you will get your files back, and you will be marked as someone who pays. Do not delete or reinstall anything before understanding how it got in, otherwise the same door will be used again. Do not reply to the attackers without advice.
Who to call
- Your IT provider, first
- Your insurer, if you have cyber cover: it often imposes its own procedure
- The cantonal police, to file a complaint
- The Federal Office for Cybersecurity (NCSC), which collects reports and publishes advice
Personal data
If data about customers, patients or employees may have been copied, the Swiss data protection act (nFADP) may require you to report it to the Federal Data Protection and Information Commissioner (FDPIC) as soon as possible, and to inform the people concerned when this is necessary for their protection. Note down from the start what you observe and at what time: this log will be useful.
Getting back up and running
It all depends on the backups. If there is a recent one out of reach, the machines are cleaned or reinstalled, the way in is closed, all passwords are changed, and then the data is restored. Allow two days to two weeks depending on size. Without a backup, the only option is to check whether a decryption tool exists for that ransomware family: the No More Ransom project, backed by Europol, publishes them free of charge. That is not always the case.
How it got in
In small organisations, almost always through one of these three doors: a phishing email, remote access exposed on the internet without two-factor authentication, or software that was no longer updated. All three can be closed cheaply, beforehand.
Getting prepared
A tested off-site backup, two-factor authentication, updates kept on track, and a page that says who to call and in what order. Printed, because on the day, the computer will not open.
In short: isolate, delete nothing, call. And if you are reading this in calm times, now is the right moment for a security audit and a restore test.