Back to all articles

Ransomware and recovery — before the ransom note appears

Modern ransomware often pairs encryption with data theft and leak threats (double extortion). Paying ransom does not fix legal duties, prove data stayed private, or guarantee a working decryptor. Preparation starts with backups (see 3-2-1), network segmentation, and least privilege so one PC cannot encrypt the whole estate via shared admin paths.

A runbook should list vendor and legal contacts, last verified backups, restore order (identity/DNS before apps), and external comms. Once a year, walk a “Monday morning total outage” tabletop without deleting production.

GDPR-style breach duties

If personal data was exfiltrated, you may need to notify a supervisory authority and sometimes data subjects — it depends on severity and risk. A clear timeline (“first access,” “exfiltration start,” “detection”) matters for counsel and insurers.

Prevention beats crisis spend

Mail filtering, MFA, patching, and user training are baseline — most incidents ride known bugs (VPN, RDP) or clicks, not exotic zero-days.

After an event, document actions: segment isolation, DNS changes, privileged password resets, disk imaging. Insurers often need structured evidence that the event falls under policy — ad-hoc chaos complicates claims.