Incident response
Ransomware May Be Involved
Quick answer
Separate affected systems, avoid destroying evidence, and involve your providers and qualified incident responders. Do not try to investigate broadly from an affected device.
Who this is for: Businesses seeing encrypted files, ransom notes, or suspicious widespread system activity.
What to do
- 01Disconnect affected systems from networks where safe to do so.
- 02Do not wipe or rebuild before preserving useful evidence.
- 03Contact your IT provider, insurer, legal counsel, and relevant authorities as appropriate.
- 04Identify clean backups and restore only after the entry point is addressed.
What this does not cover
This is immediate educational guidance, not a substitute for a qualified incident-response team or legal advice.
This page is educational information, not legal advice or a professional security audit. Check the official requirements and get qualified help when your circumstances require it.
Continue exploring