Ransomware in a small business: what to do in the first four hours

·

Ilustración: un candado cerrado junto a un reloj que marca las primeras cuatro horas

If you are reading this with an encryption under way, go straight to the first point. If you are reading it calmly on an ordinary Tuesday, all the better: this is prepared beforehand, not during.

Hour 0: contain

  • Disconnect from the network the affected machines. Cable out or Wi-Fi off. Do not shut them down completely just yet if you can avoid it: there is useful information in memory.
  • Isolate the backups before anything else. If the ransomware reaches them, the conversation is over.
  • Cut off remote access: VPN, remote desktop, supplier access. Whatever it came in through, it can come in through again.

Hour 1: assess the scope

Before touching anything else, you need to know what is encrypted and what is not: workstations, servers, shared folders, backups, and whether there are signs that they have taken data as well as encrypting it. That last part changes your legal obligations.

This is also the moment to decide who is in charge: one person coordinates and communicates. In a crisis, five people making decisions in parallel do more damage than the incident itself.

Hour 2: obligations

If personal data has been compromised, the GDPR gives you 72 hours to notify the supervisory authority. It is not optional and it does not wait until you have got the service back. It is worth identifying in advance who writes that notification.

You never pay the ransom without having exhausted the restore route first. And even having exhausted it, paying is no guarantee that you will recover anything.

Hours 3 and 4: recover in the right order

The temptation is to restore everything at once. That is a mistake: you restore first whatever keeps the business running, and only onto machines that have already been cleaned or rebuilt.

  • Directory and authentication first: without identity, nothing else works.
  • Then the system that invoices or produces. The one that stops the company if it is down.
  • Email and shared files next.
  • Workstations last, rebuilt from a clean image.

What avoids 90% of these days

Immutable backups, two-factor authentication on every remote access, network segmentation so that an infected machine cannot reach the server, and users without administrator rights on their own machine. It is not glamorous, but it is what works.


Has this raised a question about your own infrastructure?

Book 30 minutes with a MagicBoxDesk engineer. No strings attached.

Book a call