We sat down for a tabletop exercise fairly confident, because the recovery side of our ransomware plan was genuinely good. Immutable backups, tested restores, a rebuild order for the domain, isolated network segments, documented sequences. The first hour of the exercise went exactly as written.
Then the facilitator asked who declares that this is a ransomware incident rather than a large outage, and the room went quiet in a way that told us more than the previous hour had.
Nothing after that question had an owner. Our cyber insurance policy requires the insurer to be notified before we engage any external responder, and the forensics firm we had informally assumed we would call was not on their approved panel, so calling them first would have cost us the cover. Nobody could say who was authorised to decide whether to pay, or whether that decision belonged to the chief executive, the board or the audit committee, and the honest answer turned out to be that it had never been discussed. Our regulatory notification clock starts at the point of awareness, and no one could define who declares awareness or logs the time. The legal team had never seen the plan.
The most uncomfortable detail was logistical. Our contact list lived in the directory. Our incident coordination happened in the collaboration platform. In the scenario we were rehearsing, both of those are either encrypted or untrusted, and the plan assumed we would be using them to run the response.
So the technical plan did not change much. Everything else did. There is now a named person who declares the incident type, with two deputies, because it will happen at an inconvenient hour. The insurer's panel numbers and policy conditions are in the plan, not in a filing cabinet. The payment decision has a documented authority and a documented process, agreed in advance while everyone is calm. There is an out of band communications route that does not depend on our own identity provider, and a printed contact card that a handful of people keep at home.
Recovery capability is the part of ransomware preparedness that engineers enjoy building, so it is usually the part that is finished. The decisions are the part that stalls an organisation for two days, and they cost nothing to settle beforehand.
– Serguey Shinder
Top comments (0)