How to recognise an attack
- Files with new, unknown extensions that can no longer be opened
- Text files or on-screen notices with a ransom demand in many folders
- Unusually high disk and network activity, systems become sluggish
- Antivirus disabled, shadow copies deleted, backup jobs failing
- Logins at unusual times, new administrator accounts nobody created
Immediate measures: the first minutes
- Disconnect affected devices from the network: pull the network cable, switch off Wi-Fi. Do not power off, the memory may contain traces that the analysis needs
- If unsure, disconnect the entire network from the internet (router or firewall) to stop downloads and data exfiltration
- Protect backup systems immediately: unplug external disks, take NAS and backup servers off the network, do not open cloud backup access on infected devices
- Inform employees: no more logins, no USB sticks, no unauthorised restarts
- Take photos of the ransom note and the screens, note the times
- Call the IT provider or emergency contact, not by email from the affected system
What you should not do
Do not pay a ransom, at least not without advice: there is no guarantee of working decryption, and payments finance the next wave. Do not delete files and do not reinstall systems before the cause is known, otherwise the attacker returns through the same gap. Do not try decryption tools from the internet, they are often malware themselves. And do not switch everything off in a panic: a targeted approach is faster than frantic action.
Recovery
After containment, it is clarified how the attacker got in: usually via phishing emails, open remote access or unpatched systems. Then the affected systems are cleanly rebuilt and the data restored from a backup that predates the attack. Passwords of all accounts are changed, remote access is reviewed, multi-factor authentication is enabled. Only then does the network go back online. With working backups this takes one to three days for a small business, without backups much longer or it does not succeed at all.
Reporting obligations
- GDPR: if personal data is affected, the data protection authority must be informed within 72 hours, in Austria the Datenschutzbehörde, in Germany the state authority
- Cyber insurance: report immediately, many policies require notification within 24 hours and provide forensic experts
- Police: file a report, in Austria via any police station to the Cybercrime Competence Center (C4), in Germany via the Central Cybercrime Contact Point of the respective state
- Inform customers and partners if their data is affected or invoices with wrong bank details may have been sent
Prevention
The most effective measures are unspectacular: tested backups with an immutable copy, multi-factor authentication for email, VPN and remote access, timely updates, no administrator rights in daily work, staff training against phishing and an emergency plan with phone numbers printed out in the cupboard. Anyone who implements these points survives an attack as an operational disruption instead of an existential crisis.
Frequently asked questions
Should we switch off the server?
No, disconnect it from the network first. Switching off loses volatile traces, and some malware continues encrypting on restart. Disconnecting stops the spread, switching off not necessarily.
How quickly do we have to inform the data protection authority?
Within 72 hours of becoming aware, if personal data may be affected. A preliminary report with later additions is allowed and better than a late complete one.
Do you also help during an ongoing incident?
Yes. Initial assessment by phone or WhatsApp, then containment, analysis and recovery, remotely or on site in Vienna.
Need help implementing this? I implement it for you, remotely or on site in Vienna, at a fixed price or based on effort. Send request →