TheCyberNews

Ransomware Crisis Simulator

Experience a cyberattack from the perspective of a small business owner. Can you make the right choices under pressure to save your company?

INCIDENT_RESPONSE.EXE

Ransomware Simulator

Monday Morning, 8:00 AM

You walk into your small accounting firm. You sit down with your coffee, wiggle the mouse, and your screen lights up red. A skull logo stares back at you. "ALL YOUR FILES ARE ENCRYPTED. SEND 2 BITCOIN ($100,000) IN 48 HOURS OR YOUR CUSTOMER DATA WILL BE DELETED AND PUBLISHED ONLINE." What is your very first move?

The Golden Rules of Incident Response

  • 1

    Containment is priority #1. Ransomware is designed to spread across a network as fast as possible. The moment you suspect an infection, unplug the machine from the internet and the local network to save the rest of your office.

  • 2

    Do not reboot. Restarting an infected computer destroys the volatile memory (RAM), destroying crucial forensic evidence that investigators need.

  • 3

    Never pay the ransom. You are funding organized crime. There is zero guarantee they will give you the decryption key. Often, they take your money and demand a second payment to not leak the data.

  • 4

    Backups are your only true defense. If you have an "air-gapped" (disconnected) backup of your data, a ransomware attack is just a minor inconvenience. You simply wipe the computers and restore the files.