01/20/2022
Serving as an Incident Response and Recovery Coordinator, I have helped many businesses who were victimized by Ransomware attacks and did not have an incident response plan.
Why should you have a plan: Because they had no plan, and their IT team began re-imaging the computers right away. In the process, they destroyed a lot of evidence. When this happens we'll probably never know exactly how the attack started. Ransomware is a top cyber risk for everyone. You need a response plan that senior decision-makers trust.
What should your next steps be: If you don't have a plan, make one. If you do have a plan, test it.
What you should do if you dont have a plan: Don't create a plan from scratch. Find a template.
How to do it: Start by Google searching for "ransomware playbook" and pick one to be your template. Spend a couple of hours studying the template and customize it for your organization. Finally, get two hours with a handful of likely responders and update the playbook together.
Tag, comment, share if you think this would be helpful to someone you know!