🚨 IMMEDIATE ACTIONS (Minutes 0 - 60)
[ ] 1. Isolate the Infection
Do not turn the infected computers off. This can destroy forensic evidence in RAM.
- Unplug the ethernet cables from the back of the infected computers/servers.
- Turn off the Wi-Fi on infected laptops.
- If you cannot identify the infected machine, physically unplug the main internet switch from your firewall to stop data from leaving the building.
[ ] 2. Secure Your Backups
If hackers encrypt your primary data, they will immediately search for and destroy your backups.
- Physically unplug external backup hard drives from the server.
- Log into your cloud backup provider (e.g., AWS, Veeam) from a clean, uninfected personal device and change the administrative password.
[ ] 3. Call the Cavalry
You cannot handle a major breach alone. Bring in the experts.
- Cyber Insurance: Call the hotline on your Cyber Insurance policy. They will assign you an Incident Response “Breach Coach” and a forensics team. Do not attempt to negotiate a ransom without their legal guidance.
- IT Provider (MSP): Call your outsourced IT provider and declare an emergency.
đź“„ SECONDARY ACTIONS (Hours 1 - 24)
[ ] 4. Preserve the Evidence
- Do not delete any phishing emails.
- Do not reinstall Windows or wipe the servers until the forensics team tells you they have captured the necessary logs.
[ ] 5. Force a Global Password Reset
Once the environment is confirmed safe to operate in by your IT team:
- Force all employees to reset their passwords.
- Ensure Multi-Factor Authentication (MFA) is strictly enforced for all remote access (VPNs, Email).
[ ] 6. Notification & Legal Compliance
- Legal Counsel: Consult with a privacy attorney (often provided by your insurance).
- Law Enforcement: File a report with the FBI’s Internet Crime Complaint Center (ic3.gov) or your local FBI field office.
- Customers: If customer data (credit cards, medical records) was stolen, work with your legal counsel to draft the required breach notification letters according to your state’s laws.
Preparedness is everything. Do not wait for a breach to happen to find the phone numbers for your insurance and IT provider. Write them at the top of this sheet right now and hang it in the server room.