Home›Guides›DRP and BCP

DRP and BCP

What should you do after a cyberattack?

After a cyberattack, the first useful action is to stop the spread, not to reinstall as quickly as possible. Affected systems are isolated, evidence is preserved, a copy predating the intrusion is identified, and production is only reconnected once the route used by the attacker is understood, at least in broad terms.

Updated in October 20264 min read5 sources cited

Key points

  • Cut the network links of affected machines without switching them off: Cybermalveillance.gouv.fr, the French government’s cyber-assistance platform, points out that memory contains evidence.
  • Do not pay the ransom: recovery is not guaranteed and payment funds the attacker.
  • With cyber insurance, a complaint must be filed within 72 hours to be compensated (French law of 24 January 2023).
  • If personal data is affected, the CNIL, France’s data protection authority, must be notified within 72 hours when the breach poses a risk.
  • Restore the latest copy predating the intrusion, on a clean network, not the most recent one onto the infected network.

The first few hours

This page is a decision framework. It does not replace an incident response provider nor, depending on severity, the reports to the insurer, the police and the CNIL.

  1. Appoint one decision-maker. One person, not a chat thread with twenty participants. That person authorises disconnections. The ANSSI, France’s national cybersecurity agency, recommends opening an incident log from the outset: who did what, and when.
  2. Isolate without wiping everything. Cut Internet access to the attacked network, then disconnect suspicious machines from the network (cable, Wi-Fi, VPN). Switching off is not the right default reflex: memory may contain information useful for the analysis. However, letting a server encrypt the rest of the network is worse. Do not switch back on any unaffected machines that were off either.
  3. Do not pay in a panic. Cybermalveillance.gouv.fr advises against paying: the ransom guarantees neither the key, nor that the attacker holds no copy of the data, nor that they will not return, and it funds new attacks.
  4. Alert senior management, the IT provider, the insurer, and the legal contact for the CNIL if personal data is involved.
  5. Keep a record: time of discovery, what was disconnected, screenshots, ransom note, logs. Do not reformat affected disks until a clean copy has been confirmed and the insurer or the investigators have said whether the originals must be preserved.

The deadlines that apply

StepDeadlineWho
Filing a complaint (if cyber insurance)72 hours after becoming aware of the attack, to be compensatedPolice, gendarmerie or public prosecutor
Insurance claimAccording to the contract, often very shortInsurer
Notification of a personal data breach72 hours at the latest, if the breach poses a riskCNIL
Informing the individuals concernedWithout undue delay, if the risk is highAffected customers and employees
Entry in the breach registerAlwaysInternal

The complaint must be filed before machines are reinstalled, so that the technical evidence is still available. For immediate assistance, Cybermalveillance.gouv.fr directs victims to the 17Cyber service.

Getting back to a clean state

  • Look for the latest backup predating the abnormal activity, not necessarily the most recent one. The most recent one is often already contaminated or encrypted.
  • Check that this backup is outside the attacked network and that an account controlled by the attacker can no longer delete it. This is where immutability proves its worth.
  • Do not restore onto machines still connected to the compromised network. Restore onto a clean network, or onto isolated standby instances, after changing passwords and removing any questionable access.

The ANSSI describes remediation in four stages: containment, eviction of the attacker, eradication, then rebuilding. Restoring before eviction means handing the attacker a brand-new system. Details of the technical restart are in How do you restart your IT systems after ransomware?. The immediate action checklist is in Ransomware has just been triggered.

What not to believe

  • “The antivirus removed everything, we can reopen.” It may have seen the encryption, but not the accounts created three weeks earlier.
  • “Yesterday’s backup is enough.” Not if the intrusion dates back three weeks.
  • “The BCP has failed over, so we are safe.” If the standby site received the same encrypted files, it is in the same state. A historical version is needed.
  • “Everything will be up and running in two days.” The ANSSI points out that after a major incident, remediation can take several weeks or even several months. Plan a degraded mode for that period.

Afterwards

Post-incident report, change of secrets, closing the entry route (account without a second factor, deletable backup, no alerting), a new restore test. An attack that does not lead to changes in practice will happen again.

At WeDoBack

Copies are stored on servers dedicated to backup, separate from production and outside the customer’s network. If the IMMUTABLE offer is in place for the period concerned, these copies cannot have been modified or deleted by the attacker. The DRP makes it possible to restart servers on standby instances from a chosen version, which avoids restoring onto a network that is still questionable; activation during a disaster is billed per day. The encryption key is held by the customer: it must be available in order to restore. Support can be reached on +33 9 72 50 78 28 or at [email protected], from 9:00 to 13:00 and from 14:00 to 17:30 (Paris time). WeDoBack restores the systems that are backed up. It does not, on its own, investigate the intrusion or notify the CNIL: these roles must be provided for elsewhere.

Frequently asked questions

Should computers be switched off after a cyberattack?

As a general rule, no: disconnect them from the network (cable, Wi-Fi) without switching them off, so that evidence held in memory is preserved for the investigation. Cybermalveillance.gouv.fr, the French government’s cyber-assistance platform, allows one exception: if encryption is still in progress and cannot be stopped any other way, shutting down may become necessary.

How soon must a complaint be filed?

As early as possible, before machines are reinstalled. If you have insurance covering cyber risk, French law requires a complaint to be filed within 72 hours of becoming aware of the attack in order to be compensated. The complaint is filed with the police, the gendarmerie or in writing with the public prosecutor.

Is a ransomware attack a data breach that must be reported to the CNIL?

Often, yes: the CNIL, France’s data protection authority, defines a breach as the destruction, loss, alteration or unauthorised disclosure of personal data. Customer or employee files encrypted by ransomware fall within this definition, and Cybermalveillance.gouv.fr asks for the CNIL to be notified in that case. Every breach is recorded in the internal register; it must be notified to the CNIL within 72 hours whenever it poses a risk to individuals, and the individuals concerned must be informed if the risk is high.

How long does it take to get back to normal?

For a major incident, the ANSSI, France’s national cybersecurity agency, states that remediation can take several weeks or even several months. The most critical services can restart earlier, on a clean or standby infrastructure, while the rest is being rebuilt.

Planning a backup, DRP or BCP project?

More than 20 years of experience protecting business data.

Request a quote+33 9 72 50 78 28

Protect your data with WeDoBack

Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.