Friday evening, 7:40 pm. A ransom note appears on the screens in accounting, the file server is unreachable, the IT phone is ringing off the hook. What happens in the following hours decides whether the company is working again on Monday or stands still for three weeks. An emergency plan does not need a hundred pages for that. It needs to exist, be known, and sit in the drawer you can open even without working IT.
The first 60 minutes: Contain
- Disconnect affected systems from the network – pull the network cable, disable Wi-Fi. But: do not power off. Memory contains traces that are decisive for the analysis and sometimes for decryption.
- Cut connections: pause VPN access, site-to-site links and cloud synchronisation so the malware cannot spread further.
- Lock accounts: change passwords of administrator and service accounts, disable suspicious accounts, terminate sessions in Microsoft 365.
- Protect backups: take backup systems offline immediately before they are encrypted too. Many attackers look for the backups first.
- Do not delete anything, do not reinstall. The reflex to “just rebuild” destroys evidence and leaves the root cause in the dark.
The first 4 hours: Organise
An incident is not an IT fault but a company crisis. The plan defines who leads the crisis team (usually the management), who coordinates the technical response, who communicates internally and externally and who documents. Everything is logged with timestamps – on paper or on a clean device.
Now external partners are brought in: the incident response provider, the cyber insurer (many policies require notification within a few hours), legal counsel if needed. Contact details belong in the plan in printed form – in an emergency the address book on the server is not available.
The first 24 hours: Understand and report
The forensic analysis answers three questions: how did the attacker get in, which systems and data are affected, and is the attacker still active? Only with these answers can a recovery be planned that does not end in a repeat of the attack.
Reporting obligations run in parallel. If personal data is affected, the data protection authority must be notified within 72 hours (Art. 33 GDPR). NIS2 entities report significant incidents to the BSI within 24 hours. Filing a criminal complaint with the cybercrime contact point of the state police is advisable and often a prerequisite for the insurance.
The ransom question
In the vast majority of cases we advise against paying. A payment guarantees neither working decryption nor deletion of stolen data, and it finances the next attack. Before the question is even asked, the following should be checked: are there intact backups? Is there a public decryption tool (for example via the No More Ransom project)? How long does a clean recovery really take?
What belongs in the plan
| Section | Content |
|---|---|
| Alerting | Who reports to whom, which numbers apply – also at night and on weekends |
| Roles | Crisis lead, technical lead, communication, documentation, deputies |
| Immediate actions | Checklist for the first 60 minutes, understandable for non-technical staff |
| Contacts | Service providers, insurer, lawyer, authorities, key customers – printed |
| Systems | Which systems are critical, in which order they are restored |
| Communication | Templates for employees, customers, suppliers; who talks to the press |
| Reporting duties | Deadlines and forms for GDPR, NIS2, insurance, police |
Practise before it gets serious
A plan that only sits on the shelf fails in an emergency. A two-hour tabletop exercise per year – “It is Friday evening, the file server is encrypted, what do we do?” – reliably reveals which number is outdated, which role remains unfilled and whether the backups can actually be restored. We facilitate such exercises, create the plan with you and stand ready with an incident response retainer when the exercise becomes reality.