A breach is usually found through a small sign: an antivirus alert, a user whose files won't open, strange traffic at three in the morning. What you do in the hour after that decides whether the incident is over in a day or drags on for months.
This checklist doesn't replace a full incident response plan. But if you don't have one, it keeps you away from the worst mistakes.
What not to do
- Don't switch the server off. Its memory holds evidence that disappears at power-off: running processes, open connections, sometimes the ransomware's encryption key. Disconnect it from the network instead.
- Don't delete or reinstall anything. Reinstalling the operating system wipes the attacker's way in along with everything else, and until you know that route, they come back through it.
- Don't announce it over company email or chat. If the attacker has the mailbox, they read your coordination too. Use the phone or a separate channel.
- Don't change passwords on an infected machine. A new password typed on it leaks the moment it's typed. Use a clean device.
- Don't contact the attacker or pay anything, at least until the scope of the incident and the state of your backups are clear.
The first hour, step by step
- Isolate, don't power off. Unplug suspect machines from the network or shut their switch ports. If ransomware is spreading, cut the links between network segments.
- Start writing things down now. Every action, with the exact time and who did it. You'll need this later for analysis, insurance and any formal report.
- Preserve the logs. Copy firewall, server and authentication logs before rotation deletes them.
- Put one person in charge. One coordinator decides and everyone reports to them. Ten people working at once without coordination destroy evidence.
- Check the state of the backups, without connecting the backup system to the infected network.
- Estimate the scope. Which machines and accounts are involved? Treat every account used on an infected machine as compromised.
- Tell the people who need to know. Management, and if needed a specialist incident response team. In Iran, security incidents can also be reported to the Maher Center, the national computer emergency response team.
If it's ransomware
- Keep the ransom note and a sample of the encrypted files. Free decryptors have been published for some ransomware families, and identifying exactly which one you have is the first step.
- Don't delete the encrypted files; if a key ever turns up, those are the files it will unlock.
- Before restoring from backup, make sure the attacker's way in is closed; otherwise the restored copy gets encrypted again.
Before the day of the incident
The best time to prepare is today: an emergency contact list on paper, a communication channel separate from company email, backups ransomware can't reach, and centralised logs an attacker can't erase. An organisation with those four starts its first hour with a plan, not a guess.