Do you have an emergency?
Contact Enduir to get assistance.
For Emergency Response
Experiencing a ransomware attack - follow these initial steps
-
Contain the Threat and the Damage
-
Do not shut down servers, but disable networking if possible
-
Disconnect systems from the Internet
-
Disable VPN and Remote access for everyone except critical IT staff
-
-
Gather your team
-
Contact your Cyber insurance broker or carrier for coverage support
-
Engage your external Counsel to provide legal coverage
-
Bring together your IT and Technology providers
-
Work with your legal, insurance and recovery provider to engage the remainder of the support team
-
-
Take stock of the situation
-
Identify and retain a copy of any ransom notes, do not delete as there may be a specific key for each impacted system
-
Do not contact the Threat Actors, leverage your insurance carrier for support
-
Determine the accessibility and viability of any backup
-
Identify the number of impacted systems
-
Know your inventory of Servers, Workstations and Critical applications
-
-
Develop a containment and recovery plan
-
Prepare for the long road to recovery. Most recovery efforts take weeks, not days so plan your resources and team accordingly
-
Determine the most critical business applications and determine a recovery order
-
Restore critical infrastructure such as Active Directory, DNS, Networking etc.
-
Deploy containment tools such as Endpoint Detection and Response (EDR) software to allow for quick identification and containment of malware
-
Rotate all passwords, including service accounts
-
Where possible, begin restoring systems from backups, working with forensics teams to identify and contain any persistent access
-
Continue working the plan, pivoting where necessary based on the information that becomes available from recovery teams and forensics experts
-