Signature scenario · Ransomware

Ransomware: the first hours decide the losses

By the time the ransom note appears, the technical battle is mostly over. What remains is a management battle — and it is won or lost on decisions that should have been written down long before.

What the first hours actually look like

Detection is rarely a clean alarm: a server behaves oddly, a share becomes unreadable, a supplier reports strange mail from your domain. Then the cascade: systems freeze one by one, phones fill, nobody is sure what still works, and every minute of indecision widens the encryption. The organisations that come out with survivable losses are not the ones with the best firewalls — they are the ones where the next five decisions had names attached before the day.

The five decisions, prepared in advance

DecisionThe questionWho must hold the pen
IsolateDisconnect networks and sites — accepting operational stop — yes or no, when?A named person reachable 24/7, with written authority
DeclareTrigger the continuity plan and crisis structure — on what threshold?Duty leadership; the threshold defined, not debated
Operate degradedWhich activities continue manually, which stop safely?Operations, from the pre-built manual-mode plans
CommunicateStaff, clients, regulator, insurer — who says what, when?One voice; holding statements drafted in peacetime
Preserve evidenceImages, logs, timelines — before restoring anythingIT with the incident scribe; the insurer and any investigation depend on it

The mistakes that multiply the loss

The one-page artefact that changes everything: the first-hours card — five decisions, named holders, deputies, thresholds, contact numbers. Laminated, offline, at three locations. Cost: a workshop. Value on the day: the difference between an incident and a catastrophe.

The UAE layer

For UAE organisations the event carries legal clocks alongside the operational ones: personal-data breach obligations, sector notification expectations (for financial institutions, prompt customer notification under the Central Bank framework), and evidence standards your insurer and — where relevant — authorities will apply. The notification decision path belongs in the plan with counsel's number on it, because the clock starts at detection, not at your first meeting.

Frequently asked questions

Should we call the authorities?

Prepare the answer before the event with counsel: which notifications are mandatory for you (data protection, sector regulators), which are advisable, and who makes the call. The wrong answer is discovering the obligations afterwards.

When do we involve the insurer?

Early — most cyber policies require prompt notification and some specify approved responders. Late notification is a classic ground for coverage disputes. The insurer's hotline belongs on the first-hours card.

Do we need external incident response on retainer?

At mid-size and above, a pre-agreed responder shortens the worst day materially — no procurement in a crisis, known rates, familiarity with your environment. At minimum: have the shortlist and contract template ready.

The signature scenarios hub

Thirteen questions show whether your first hours are ready.

Request a gap assessmentTake the free readiness check
NCEMA-ready gap assessment