Cyberattack: the first 24 hours
What happens in the first few hours decides the rest: how long you are down, the final bill, and what you will be able to prove to your insurer afterwards. Here is the order that holds.
Restarting everything. The first reflex is to reinstall and get back to work. It destroys the evidence, and with it any chance of knowing how the attacker got in. Without that answer, you leave the same door open for a second visit.
Paying before qualifying. Payment guarantees neither full data recovery nor non-publication. It is a board decision, taken after qualification, with the insurer and legal counsel, never within the hour of discovery.
Communicating at random. A badly calibrated internal message reaches a customer or the press within hours. Total silence for two days produces the same effect, only worse.
Isolate the network rather than the machines: cut inter-site links, remote access and outbound connections. Leave compromised machines powered on if you can, since volatile memory holds part of the evidence.
Cut the backups off from the rest of the network immediately. They are the next target in almost every ransomware case, and they are also your only way back.
Open a fallback communication channel outside the affected systems: mobile messaging, a printed list of numbers. Internal directories are typically unavailable at the exact moment you need to call everyone.
Qualify. What is affected, since when, which data, which backups are intact. Until those four answers are written down, no restoration decision is reliable.
File a police complaint within 72 hours. Under the French law of January 2023 on the interior ministry's programming, insurance cover for a cyber-ransom payment is conditional on filing a complaint within 72 hours of becoming aware of the offence. That clock starts without waiting for you.
Notify the data protection authority within 72 hours if personal data is involved, under Article 33 of the GDPR. An incomplete initial notification, completed later, beats a late one.
Tell your insurer the same day: most policies require the insurer's prior agreement before incident-response costs are committed.
Restoration happens on rebuilt machines, not cleaned ones. Restoring a compromised system onto itself reinstalls the attacker along with the data.
Reset credentials before reconnecting, starting with privileged and service accounts. Ransomware almost always fires after weeks of quiet presence, with credentials that are still valid the day after the crisis.
Reopen in waves, with a checkpoint between each, and watch for the attacker's return over the following weeks. Re-infections usually happen within the month.
A printed, current contact list: insurer, legal counsel, incident-response provider and business owners. A crisis is handled with the Saturday-morning phone, not the intranet directory.
Backups whose restoration has been tested for real, on new hardware, stopwatch in hand. A backup that has never been restored is a hypothesis, not a plan.
One crisis exercise a year, two hours, board included. It is the only way to discover before the attack that nobody knows who has the authority to stop production.
Should we pay the ransom?
It is a board decision, taken after qualification, with the insurer and legal counsel. Payment guarantees neither full recovery nor non-publication of the data, and it directly funds the next campaign. It is never decided within the hour of discovery.
When must the data protection authority be notified?
Within 72 hours of becoming aware of the breach, whenever personal data is involved and the risk to individuals is not negligible, under Article 33 of the GDPR. If the investigation is still running, the regulation allows a partial initial notification, completed later.
Will our insurance cover the incident?
It depends on the policy, but two conditions come up almost every time: notify the insurer before committing response costs, and file a police complaint within 72 hours for anything involving a ransom payment, a condition set by the French law of January 2023. Both are worth checking cold, not on the day of the attack.
This maps to our Cybersecurity and resilience offer, or talk it through with the founder.
Let's talk about your situation.
A 30-minute call with the founder, no strings attached. Reply within 24 business hours.
Your details are used only to answer your enquiry: never sold, never used for cold outreach. Privacy policy.