Ransomware – What next?
Encryption Trojans (ransomware) can cause considerable damage, especially if your data backups are also affected. In the event of such an incident, remain calm and act with caution.
The main aim of post-incident clean-ups is to find the infection route and prevent a new infection. Restart the affected systems and restore data using existing backups.
If the necessary expertise is not available in your authority, seek support from a specialised company.
The following points are to be observed in the event of an incident involving ransomware:
Damage limitation
Disconnect infected systems from the network immediately. To do this, disconnect the network cable from the computer and switch off any WLAN adapters you may have.
Identifying infected systems
Log files can help identify affected systems, e.g. by using them to detect access to network drives. The metadata of encrypted files can also provide information about infected systems, e.g. which user accounts created the files. Back up your log files.
Detection
Forensic investigations
Decide at an early stage whether a forensic investigation should be carried out. This is particularly important if you want to file criminal charges. In this case, inform the prosecution authorities at an early stage and discuss the next steps (monitoring the malware, countermeasures, etc.).
Cache data and hard disks should be properly backed up by a specialist employee or service provider before attempting further repairs or restarting the affected systems. Forensic investigations are almost impossible after this point.
Backing up encrypted data
If the backup was also encrypted, it is recommended to keep and back up the encrypted data so that it can be decrypted at a later time, should a solution be found. In some cases, security and prosecution authorities have been able to gain access to keys or decryption methods during their investigations.
Reinstalling affected systems
Before you start restoring the data, you must reinstall the infected systems. The operating system used should come from a trusted data storage device.
Under certain circumstances, a partial or complete recovery of the data is also possible without a backup of the data. Decryption may work under certain circumstances if:
- the ransomware did not encrypt or delete shadow copies in Windows;
- snapshots of virtual machines or previous file versions exist in cloud services;
- the forensic restoration of deleted files is possible;
- the ransomware contains errors in its encryption function or the decryption key is known.
Nomoreransom.org (https://www.nomoreransom.org/) offers tips on identifying malware and the possibility to download known keys. It is a joint project by the Dutch police and Europol, in which the Swiss Confederation also participates.
Reporting obligations and criminal charges
Reporting to NCSC
On 7 March, the Federal Council introduced a reporting obligation for cyberattacks on critical infrastructure, which will come into force on 1 April. Operators of critical infrastructure will be required to report cyberattacks to the National Cyber Security Centre (NCSC) within 24 hours of discovery. After submitting the initial report within 24 hours of discovering the incident, they have 14 days to complete their report.
Reporting to the FDPIC
In accordance with Article 24 of the new Federal Act on Data Protection (nFADP), which enters into force on 1 September 2023, data security breaches must now be reported to the FDPIC if the persons affected by the data leak are exposed to an increased risk of their privacy or basic rights being infringed as a result. The requirement applies to private individuals, businesses and federal bodies. Reports to the FDPIC must be submitted as soon as possible.
Criminal charges
File criminal charges with the cantonal police where your company is based. They will then initiate the necessary investigation.
Advice on ransom payments
The NCSC recommends not paying a ransom. Once the ransom has been paid, there is no guarantee that the criminals will not publish the data anyway, or otherwise try to profit from it. Moreover, every successful ransom attempt motivates the attackers to continue, finances the further development of attacks and encourages their spread.
If you are still considering paying the ransom, the NCSC urgently recommends that you discuss this step with the cantonal police.
