Category: Cybersecurity

  • Ransomware: what to do in the first few hours (response plan)

    Ransomware: what to do in the first few hours (response plan)

    Files start showing up with strange extensions, there’s a ransom note on the desktop and machines begin falling one after another. At that moment you don’t need a treatise on cybersecurity: you need to know what to do in the next sixty minutes. Because what you decide right there —and above all what you do out of sheer panic— is the difference between a bad day and two weeks with the business at a standstill.

    This is not a prevention article. It assumes it’s already happening and gives you the incident response plan step by step: what to touch, what not to touch, who to call and in what order to recover. Save it before you need it, because when you do need it you won’t have time to go looking for it.

    Why the first few hours decide everything

    Ransomware doesn’t encrypt at the speed of light. By the time you see the ransom note, the encryption is still spreading across the network: every minute an infected machine stays connected means more shared folders, more servers and —what hurts most— more backups falling. The window to contain the damage is measured in minutes, not hours. That’s where it’s decided whether you open tomorrow or not.

    The other enemy in that first hour is panic. The instinctive reaction —shut everything down, reboot servers, start deleting whatever looks infected, pay the ransom to get it over with quickly— is almost always the wrong one. Containing isn’t reacting fast; it’s reacting in the right order. A company that isolates with a cool head recovers from backup in two days. One that improvises on frayed nerves ends up with the incident spread wide, the evidence destroyed and no clean backup to fall back on.

    Ransomware doesn’t punish technical failure; it punishes improvisation. Those with a written plan execute; those without one argue while the encryption spreads.

    The right first steps, in order

    This is the script for the first hour. Don’t improvise it: follow it exactly, from top to bottom.

    • Isolate the affected machines from the network. Unplug the cable, turn off Wi-Fi, cut the VPN. The goal is to stop the spread immediately. Isolation comes first, always, before investigating anything.
    • Don’t shut things down blindly. Disconnecting from the network is not the same as powering off cold. Shutting down wipes volatile information that helps you understand what happened and how they got in, and in some cases it even complicates data recovery. Isolate, but leave the machines running unless the person leading the incident tells you otherwise.
    • Protect the backups right now. Before anything else, make sure the backups can’t be reached from the compromised network. If the ransomware gets to them, the conversation is over. Disconnect them or verify that they are isolated and immutable.
    • Cut off remote access and privileged accounts. VPN, remote desktop, vendor access and administrator accounts. Whichever way they got in they can get in again, and often the attacker is still inside watching how you react.
    • Preserve the evidence. Photograph the ransom note, note the time, don’t delete logs or encrypted files. That information is gold for understanding the scope, for the insurer and, if needed, for the police report.
    • Activate the plan and put one person in charge. Someone coordinates, decides and communicates; everyone else executes. Alert your managed cybersecurity provider and start documenting what’s affected. In a crisis, five people deciding in parallel do more damage than the attack itself.

    With this done, the fire is contained. Now it’s time to assess the scope calmly: what’s encrypted, what isn’t, and whether there are signs that data was also stolen —what’s known as double extortion— because that changes your legal obligations.

    What NOT to do under any circumstances

    Half of a good response is not making the mistakes that turn an incident into an irreversible disaster. These are the four that cost the most.

    • Don’t pay blindly. Paying doesn’t guarantee you’ll get your data back —many decryptors fail or only work halfway—, it marks you as someone who pays and it funds the next attack. It’s the last option, never the first, and only after thoroughly assessing whether you can restore from backup.
    • Don’t restore over the infected system. Recovering your data on a system that’s still compromised, or without closing the entry point, restarts the nightmare within hours. First you clean or reinstall; then you restore.
    • Don’t hide it. Keeping the incident quiet so nobody finds out exposes you to penalties for failing to notify and destroys trust when it eventually comes out —and it will come out. Well-managed transparency protects you; silence makes it worse.
    • Don’t delete logs or files. “Cleaning up” on your own destroys the evidence you need to understand the scope, comply with the law and collect on the insurance. Don’t touch the logs: they’re your best ally.

    Notification and obligations: the legal clock is ticking too

    While you contain and recover, there’s a second clock running that many people ignore until it’s too late. If the attack compromised personal data —of customers, employees or suppliers—, the GDPR requires you to notify the breach to the supervisory authority within 72 hours of becoming aware of it. It doesn’t wait until you’ve recovered the service and it’s not optional: failing to notify adds a fine on top of the disaster you already have.

    And there are more fronts to handle in parallel, without leaving them for the end:

    • Communication to those affected. If the breach poses a high risk to customers or employees, on top of the supervisory authority you have to inform them directly. Prepare a clear, honest message, not an empty statement.
    • Notice to the insurer. If you have a cyber-risk policy, report it as soon as possible: many require immediate notification and give you access to a response team. Acting on your own can leave you without cover.
    • Police report and authorities. Filing a report and alerting the reference channels such as the national cybersecurity authority creates an official record and gives you support. The documentation you preserved in the first hour is exactly what’s needed here.

    Having identified in advance who drafts the notification, who talks to the insurer and who talks to the customers is what lets you meet these deadlines without stalling the technical recovery. Improvising it with the business at a standstill is the recipe for missing all three.

    How MagicBoxDesk helps you: incident response and recovery from a clean backup

    All of the above sounds simple written down in calm. At three in the morning, with the business down and the phone ringing, it isn’t. That’s why the greatest value isn’t having the plan in a PDF, but having someone on the other end who executes it with you. At MagicBoxDesk we build, maintain and trigger that response plan as a service, as part of your outsourced IT, with remote and on-site support across Spain.

    • Incident response with a defined, rehearsed plan: who isolates, who decides, who gets alerted and in what order, so you act in minutes instead of improvising for days.
    • Containment and scope analysis: we isolate what’s affected, preserve evidence and determine whether data was stolen, without destroying the information you’ll need later.
    • Immutable, isolated backups, with restores tested regularly, so that when the moment comes there really is a clean copy to go back to.
    • Recovery in the right order: identity and authentication first, then whatever bills or produces, then email and files, and the workstations last, reinstalled from a clean image.
    • Support with legal obligations: breach notification on time, communication to the insurer and to those affected, with the paperwork in order.
    • Closing the entry point before reconnecting, so the attack doesn’t start all over again the moment everything comes back up.

    Ideally we should talk before the incident, not during. Preparing the plan, the backups and the access costs a fraction of what a ransom or two weeks of downtime costs, and it’s what turns a crisis into a rough moment. If you already have it on top of you, we’re here to help you contain and recover too.

    At MagicBoxDesk we take care of your security and your response plan so you can focus on your business. Ask for a no-obligation quote and we’ll tell you what you really need so that the first hours of a ransomware attack work in your favour and not against you.

  • ISO 27001 for an SME: is it worth it? Cost, benefit and when to certify

    ISO 27001 for an SME: is it worth it? Cost, benefit and when to certify

    Before you ask yourself how to implement ISO 27001, there’s a question that decides everything else: does certification actually pay off for your company? Because getting certified costs money, your people’s hours and a commitment that doesn’t end the day they hand you the badge, but renews every year. And it isn’t worth it for every SME. For some, hugely so. For others, it’s throwing budget away on vanity.

    This article isn’t about where to start or about implementation checklists. It’s about making the decision with real judgement: what the certificate genuinely gives you, when the return is obvious, how much it costs without inflated figures, and what alternative you have if what you want is to be secure but nobody is demanding the paperwork from you yet.

    What ISO 27001 really gives you (and what it doesn’t)

    First, to clear the smoke: ISO 27001 does not make you immune to an attack. It’s not an antivirus, nor a firewall, nor a guarantee that no ransomware will get in. It’s an information security management system: an orderly, audited way of knowing what data you hold, what risks it runs and what you do to handle them. The certificate proves that this system exists and works, not that you’re invulnerable.

    So what do you get in exchange for the effort? In practice, three concrete things. The first is a commercial key: it opens doors that stay shut without the badge —large clients, public tenders, international contracts—. The second is demonstrable trust: it shortens sales cycles and spares you the endless security questionnaires that big accounts send you before signing. And the third, the most underrated, is real internal order: to get certified you have to put in writing who accesses what, how backups are made and what happens when something fails. That order is worth it even if you never hang the certificate on the wall.

    The useful question isn’t “should I get certified?”, but “how much business am I losing by not being certified?”. With that number on the table, the decision makes itself.

    When certification IS worth it

    ISO 27001 pays off when there’s a clear commercial or regulatory reason behind it. If you recognise yourself in any of these cases, the answer is usually yes without much deliberation:

    • A client demands it to keep working with you. It’s the most common case and the easiest to decide: if losing that account hurts more than the cost of getting certified, it’s worth it. Full stop.
    • You want to bid for public tenders or land large accounts. In many tender specifications and vendor approval processes the certificate is an entry requirement: without it, they won’t even assess you.
    • You handle third parties’ sensitive data. If you’re a technology provider, manage client data or handle critical information, certification is the argument that clears the doubts of whoever hires you.
    • You operate in a regulated sector or within a demanding supply chain. More and more companies pass their obligations —including the pressure of regulations like NIS2— down to their suppliers. They ask you for it even if the law doesn’t directly oblige you.
    • You’re in a growth phase and want to play in a different league. If your goal is to sell to larger companies or expand abroad, the certificate stops being a luxury and becomes a condition for competing.

    And the other way round: if nobody’s asking you for it, you don’t sell to large accounts and your real priority is simply not getting a nasty surprise, maybe you don’t need the badge yet. You need the controls. We talk about that further down.

    What it really costs

    This is where many get a surprise, because the cost of ISO 27001 isn’t a single invoice. It’s four different line items, and it’s worth seeing them all before deciding:

    • Implementation consultancy. The support to set up the system: scope, risk analysis, policies and controls. It’s the most visible item and varies a lot depending on the size of your company and how orderly your starting infrastructure is.
    • Your team’s internal time. The hidden cost that nobody budgets for. Your people have to provide information, approve policies and apply what gets documented. If nobody has hours for the project, it drags on and ends up costing more.
    • Certification audit. Invoiced by an independent accredited body, separate from the consultancy. It’s the one that issues the certificate after reviewing your system in two stages.
    • Annual maintenance. The certificate lasts three years, but every year there’s a surveillance audit. An abandoned system collapses on its own, so you have to keep it alive: that means hours and, often, tools.

    I’m not going to give you a fixed figure because it would be a lie: it depends on your size, the scope you define and how much you’ve already done. And that’s the good news. The more orderly your technical foundation is —tested backups, access control, patches up to date—, the cheaper the implementation, because you’re already meeting half the standard without knowing it. The fastest way to send the cost through the roof is to certify the whole company at once when you could have started with a defined scope and expanded it later.

    The alternative: implementing the controls without certifying

    Here’s the nuance almost nobody tells you: what protects you isn’t the certificate, it’s the controls. The badge is the accreditation that a third party has verified those controls exist. If nobody’s asking you for the paperwork, you can keep the part that genuinely shields you and save yourself the external audit and its annual renewal.

    In practice that means implementing the measures that come from the standard itself —risk analysis, backups that actually restore, access control, incident management, team training, supplier control— but without going through the certification body. You have good security, you effectively meet a good chunk of what your clients demand and you avoid the recurring cost of the certificate. It’s the smart route when your priority is not getting a nasty surprise, not winning a tender.

    The added advantage is that that work isn’t wasted: the day a client demands ISO 27001 from you, you’ll already have 70% of the road done and certification will be a matter of formalising and documenting, not a project from scratch. Starting with the controls and certifying when the moment comes is, almost always, the most cost-effective decision. A solid foundation of cybersecurity and compliance is exactly that starting point.

    How MagicBoxDesk helps you decide (and get all the way to the certificate)

    Most consultancies sell you the certificate without asking whether you need it. At MagicBoxDesk we do the opposite: the first thing is to tell you honestly whether certification pays off for your company or whether implementing the controls is enough. We look at who’s asking you for it, what business is at stake and what state your infrastructure is in, and on that basis we give you a recommendation with numbers, not a sales pitch.

    And if the answer is that it does pay off, we take you all the way. Since we run the outsourced IT department of SMEs and companies across Spain, we don’t limit ourselves to drafting policies: we start from your backups, your access and your real systems, we implement the technical controls that underpin the standard and we support you right up to the certification audit. Afterwards we stay with you with monitoring, backups and managed cybersecurity so the annual surveillance audits are passed without surprises. You can see everything we cover on our services page.

    So before you spend a single euro on a certificate you might not need —or let a contract slip away for not having one—, let us tell you straight. Request a no-obligation quote and we’ll tell you whether it pays off for you, how much it would really cost you and in what realistic timeframe you’d have it ready.