What to Do After a Ransomware Attack: Utah Business Response Guide

What to Do After a Ransomware Attack: Utah Business Response Guide

Quick Summary: If you think ransomware is on your network, disconnect the affected systems, leave them powered on if you can, and use the phone instead of email. Then call your IT provider, your insurer and a lawyer, and report the attack to the FBI at ic3.gov. Do not wipe anything yet.

Ransomware locks your files and demands payment to unlock them. Many attackers also copy data and threaten to publish it, so ask your responder whether data left your network, because that affects notification. This guide draws on CISA, the FBI, the FTC, HHS, the U.S. Treasury and Utah's breach law, and labels our own advice "Practical advice, not from CISA." It is not legal advice.

What to do first

  1. Isolate the affected systems. Unplug the network cable or turn off Wi-Fi on affected computers, or have your IT person take the network offline at the switch. CISA's #StopRansomware Guide (September 2023) says to isolate impacted systems immediately.
  2. Disconnect before you power off. CISA says to power a device down only if you cannot disconnect it, because shutting down loses volatile memory that investigators can use.
  3. Do not wipe, reinstall or "clean" anything yet. The FTC's breach guide says not to destroy forensic evidence.
  4. Record the ransom note and keep a log. Practical advice, not from CISA: photograph the note and write down what was found, what was done and who was called, with times. The FBI's IC3 asks for details such as the file extension, ransomware variant, cryptocurrency address and ransom amount.
  5. Use out-of-band communication, such as phone calls. CISA says attackers may monitor your organization's communications, and recommends out-of-band communication, such as phone calls, while you isolate systems.
  6. Keep backup drives disconnected. CISA says backups should stay offline because many ransomware variants try to delete or encrypt accessible ones. Practical advice, not from CISA: do not plug a backup drive into the affected network to check it.

Who to call

Practical advice, not from CISA: call in roughly this order.

  1. Your IT provider or IT lead. Call them early so they can guide isolation and evidence capture.
  2. Your cyber insurance carrier. Find the policy and its claims hotline. Common practice, not from CISA, the FBI or the FTC: many policies require prompt notice and limit which firms they pay for, so read yours before hiring a responder.
  3. Legal counsel. The FTC says to consult legal counsel, and that you may consider counsel with privacy and data security expertise, who can advise on the federal and state laws that may apply.
  4. Law enforcement. Report to the FBI at ic3.gov and call your local police.
  5. CISA. Report at cisa.gov/report. CISA offers technical assistance.

The decision to pay

The FBI does not support paying a ransom. It says payment does not guarantee you will get your data back and encourages more attacks.

The Treasury's Office of Foreign Assets Control (OFAC) says in its September 2021 advisory that a payment can violate sanctions if it goes to a sanctioned person or a comprehensively sanctioned jurisdiction, and that a payer can be liable even without knowing. The U.S. government strongly discourages paying. OFAC treats a prompt, complete report to law enforcement or CISA, and ongoing cooperation, as significant mitigating factors. The advisory is guidance without the force of law, but the sanctions rules behind it are binding.

Practical advice, not from CISA: do not decide alone or under the attackers' deadline. Involve your lawyer, insurer and law enforcement first. CISA advises asking federal law enforcement about possible decryptors.

Recovery order

This order is based on CISA's response checklist. Steps 3 to 5 are for your IT person or responder; ask them about these.

  1. Find how they got in and close it. Identify the systems and accounts involved in the initial breach, including email accounts. CISA says securing access may include disabling VPNs, remote access servers, single sign-on resources and public-facing assets. Look for the earlier "dropper" malware that delivered the ransomware before rebuilding from backups.
  2. Clean and rebuild in priority order. List critical systems first and confirm what data each holds. CISA says to rebuild from pre-configured standard images, if possible.
  3. Reset credentials. After cleaning and rebuilding, CISA says to reset passwords for all affected systems, fix related vulnerabilities and remove the attackers' ways back in. Check for new or escalated accounts in Active Directory, the Windows service that manages logins. Practical advice, not from CISA: if you cannot show which accounts were touched, reset all of them.
  4. Confirm the incident is contained and eradicated, then declare it over. CISA has the designated IT or IT security authority declare it over, based on established criteria.
  5. Then reconnect and restore from clean, offline, encrypted backups. CISA says to avoid re-infecting clean systems, for example by adding only clean systems to a new recovery network segment (VLAN).

Notification duties

Which duties apply depends on the data and the law, so ask your lawyer. These are common categories, not a complete list.

Utah law

Utah Code 13-44-202 applies to a business that owns or licenses computerized data that includes personal information about a Utah resident, once it becomes aware of a breach of system security. Section 13-44-102 defines both terms. Personal information is a first name or initial and last name combined with, when unencrypted, a Social Security number, a financial account or card number with its access code, or a driver license or state ID number. A breach of system security is an unauthorized acquisition of computerized data that compromises the security, confidentiality or integrity of personal information.

The business must promptly and in good faith investigate the likelihood that the information has been or will be misused for identity theft or fraud. If misuse has occurred or is reasonably likely, it must notify each affected Utah resident in the most expedient time possible without unreasonable delay, after determining the scope and restoring the system's reasonable integrity. The statute sets no fixed number of days.

If the misuse relates to 500 or more Utah residents, the business must also notify the Attorney General's office and the Utah Cyber Center. At 1,000 or more, it must notify the nationwide consumer reporting agencies. This summary omits details and exceptions, such as a law enforcement delay.

Other laws and contracts

  • Health data (HIPAA). HIPAA applies to covered entities and business associates. Under 45 CFR 164.402, an unauthorized acquisition, access, use or disclosure of protected health information is presumed to be a breach unless a risk assessment shows a low probability of compromise. HHS's 2016 ransomware fact sheet applies this to ransomware. Individuals must be notified without unreasonable delay and no later than 60 calendar days after discovery (164.404). HHS must be notified too (164.408).
  • Payment card data. Contact your acquirer (merchant bank) and the card brands. PCI Security Standards Council guidance says each has its own rules on when a forensic investigation is required.
  • Financial businesses. Under the FTC Safeguards Rule (16 CFR 314.4(j)), a financial institution the FTC regulates, such as a tax preparation firm or mortgage broker, must notify the FTC no later than 30 days after discovery if unencrypted information of at least 500 consumers was acquired without authorization.
  • Other states and contracts. The FTC says every state has a breach notification law, so customers outside Utah may bring other laws into play. Contracts can also require notice.

What lowers the risk before the next attack

From CISA's prevention list, in plain words:

  • Phishing-resistant multifactor authentication (MFA), a second proof of identity beyond a password, for all services, particularly email, VPNs and accounts that access critical systems.
  • Patching, internet-facing servers first, plus regular vulnerability scanning.
  • Offline, encrypted backups that you test regularly. See our data backup plan guide.
  • Staff training on spotting and reporting suspicious messages.
  • Limited access. Give people only the access they need, keep administrator accounts separate from daily accounts, and audit for unused or unauthorized accounts quarterly.
  • A written incident response plan that you practice. CISA says to keep a hard copy and publishes tabletop exercise packages with ransomware scenarios. Practical advice, not from CISA: keep a contact sheet with your insurer, lawyer, IT provider and acquirer next to it.

How WITS fits

WITS IT Services is based in Lehi, Utah. Its engineers hold Cisco CCIE Enterprise Infrastructure and Kali Linux Professional certifications. WITS offers business cybersecurity, backup and recovery and IT compliance services. No IT provider can promise your data will be recovered after an attack, and WITS does not make that promise.

Next steps

If you are in an incident now, start with the first steps above. To prepare, call WITS at 385-313-9898 or start at witsitservices.com/get-started. A phone or video consultation is free for the first 30 minutes, then a flat fee applies.

Other Blogs

Slow Internet at Home or Work? Here's What's Really Going On

Slow Internet at Home or Work? Here's What's Really Going On

A slow connection is rarely just your ISP. Test your speed correctly, then find whether the modem, router, a device,...

Learn More
Security Camera Checklist Before Your Utah Summer Vacation

Security Camera Checklist Before Your Utah Summer Vacation

Heading out of town this summer? Use this Utah home security camera checklist covering placement, firmware, remote...

Learn More