Ransomware attacks are designed to cause maximum disruption in minimum time. Attackers increasingly combine encryption with data theft, threatening to publish sensitive information unless a ransom is paid. The organizations that recover fastest are those that prepared before the attack.
Questions every leadership team should be able to answer
- Do we have offline or immutable backups, and have we tested restoring them in the last quarter?
- Is multi-factor authentication enforced on email, remote access and administrator accounts?
- Do we know which systems and data are most critical to keep operating?
- Is there an incident response plan with named decision-makers and out-of-band contact details?
- Do we have access to experienced incident responders at any hour?
- Have we rehearsed a ransomware scenario with the executive team?
If you are attacked
Isolate affected systems from the network without powering them off, preserve evidence, switch to trusted communication channels and contact incident responders immediately. Avoid engaging with attackers or making payment decisions before you understand the scope of the incident and your legal obligations.
The iRES 24/7 Cyber Incident Response Centre provides rapid triage, containment, forensics coordination and recovery support, alongside executive situation reporting and regulatory notification guidance.
Want to discuss this with our team?
Our practitioners are happy to talk through what it means for your organization.
Book a conversation



