Ransomware Crisis Simulator
Experience a cyberattack from the perspective of a small business owner. Can you make the right choices under pressure to save your company?
Ransomware Simulator
Monday Morning, 8:00 AM
You walk into your small accounting firm. You sit down with your coffee, wiggle the mouse, and your screen lights up red. A skull logo stares back at you. "ALL YOUR FILES ARE ENCRYPTED. SEND 2 BITCOIN ($100,000) IN 48 HOURS OR YOUR CUSTOMER DATA WILL BE DELETED AND PUBLISHED ONLINE." What is your very first move?
The Golden Rules of Incident Response
- 1
Containment is priority #1. Ransomware is designed to spread across a network as fast as possible. The moment you suspect an infection, unplug the machine from the internet and the local network to save the rest of your office.
- 2
Do not reboot. Restarting an infected computer destroys the volatile memory (RAM), destroying crucial forensic evidence that investigators need.
- 3
Never pay the ransom. You are funding organized crime. There is zero guarantee they will give you the decryption key. Often, they take your money and demand a second payment to not leak the data.
- 4
Backups are your only true defense. If you have an "air-gapped" (disconnected) backup of your data, a ransomware attack is just a minor inconvenience. You simply wipe the computers and restore the files.