CyberSafe · Security guide · Print this before you need it
Ransomware: first 72 hours
Hour 0–4 — Contain
- Name one commander. IT, legal, and leadership take direction from that person.
- Isolate affected identity and segments. Do not power-wipe yet.
- Assume email is hostile if the phish started there.
- Call insurer and IR path. CyberSafe: +264 81 390 6697
- Do not pay or negotiate from an infected machine.
Hour 4–24 — Preserve
- Snapshot VMs, collect logs, freeze mailbox evidence.
- Write a fact log: times, systems, what you already did.
- Tell staff a holding statement. No speculation on social media.
Hour 24–72 — Recover
- Restore from backups you have tested. Rebuild identity before file shares.
- Notify customers and regulators only with verified facts.
- Schedule the post-incident: which control would have shortened this.