Modern ransomware often pairs encryption with data theft and leak threats (double extortion). Paying ransom does not fix legal duties, prove data stayed private, or guarantee a working decryptor. Preparation starts with backups (see 3-2-1), network segmentation, and least privilege so one PC cannot encrypt the whole estate via shared admin paths.
A runbook should list vendor and legal contacts, last verified backups, restore order (identity/DNS before apps), and external comms. Once a year, walk a “Monday morning total outage” tabletop without deleting production.
GDPR-style breach duties
If personal data was exfiltrated, you may need to notify a supervisory authority and sometimes data subjects — it depends on severity and risk. A clear timeline (“first access,” “exfiltration start,” “detection”) matters for counsel and insurers.
Prevention beats crisis spend
Mail filtering, MFA, patching, and user training are baseline — most incidents ride known bugs (VPN, RDP) or clicks, not exotic zero-days.
After an event, document actions: segment isolation, DNS changes, privileged password resets, disk imaging. Insurers often need structured evidence that the event falls under policy — ad-hoc chaos complicates claims.