Preserve evidence before remediating, capture the short-retention logs immediately, notify your insurer before retaining anyone, and engage counsel early. The decisive question is not whether to pay but what data left the environment — notification and regulatory duties follow from the theft, not from the encryption.
The first hours, in the order that matters
Preserve, then contain. The operational instinct is to reimage infected systems and restore service. That destroys the artifacts needed to establish what the attacker reached — and scope is the finding everything else depends on. Image affected systems where feasible before rebuilding them.
Capture the volatile and short-lived evidence. Memory on affected hosts, which is gone at reboot. Firewall, VPN, proxy and endpoint logs, which are the primary record of data leaving and are frequently rotated within days. Cloud audit logs, where default retention is short.
Notify your insurer before retaining anyone. Most policies require prompt notice and restrict which forensic firms, breach counsel and notification vendors may be used. Retaining a trusted firm on day one, before calling the insurer, can leave those costs uncovered even though the work was necessary.
Engage counsel, so the investigation proceeds under privilege where that is available, and so the analysis of notification duties starts on day one rather than after the forensics conclude.
Do not improvise contact with the attacker. Every message is potentially discoverable and may be read by a regulator.
Paying is a legal question first
Payments to sanctioned entities carry strict-liability exposure under OFAC rules, and attribution of a group to a sanctioned actor is frequently uncertain at exactly the moment the decision has to be made. That analysis belongs with counsel, and often a specialist negotiation firm, before any engagement begins.
Separately, the commercial case for paying is weaker than it appears. Attacker-supplied decryption tools are often slow and imperfect, restoring from them can take longer than restoring from backup, and a promise to delete stolen data is unverifiable by construction. Paying does not resolve the notification obligation, because that obligation arises from the exfiltration.
Scope is the deliverable
Everything downstream turns on one finding: what data left, and whose it was. Attackers stage data before exfiltrating, route it through ordinary cloud services to blend with normal traffic, and delete logs on the way out.
An investigation that cannot establish scope forces the worst-case assumption — notifying everyone whose data was in the affected systems rather than those actually involved. The gap between those two populations is frequently an order of magnitude, and closing it is where the forensic spend pays for itself several times over.
What separates a fast recovery from a slow one
In our experience it is almost never the sophistication of the attack. It is whether the backups were genuinely offline and whether anyone had tested restoring from them before the day it mattered. Organisations that recover in days have both; organisations that recover in months usually discover, during the incident, that the backups were reachable from the network the attacker had already compromised.
From our work
Need this looked at properly?
Our examiners and testifying experts work these questions for a living. Tell us what you're facing.
Reviewed by Law & Forensics. See our editorial standards.
