A ransomware attack does not begin when the ransom note appears — the note is the end of the operation. For days or weeks before it, the attacker was inside the network escalating privileges and quietly destroying your backups. This guide from Namra Tech and the Rased team sets out the order of actions that genuinely limits the damage.
Hour one — contain, do not investigate: disconnect affected machines from the network without powering them off (shutdown destroys memory-resident evidence), revoke administrative sessions and keys, stop cloud sync so encrypted files do not overwrite clean copies, and temporarily close remote access.
Hour two — secure the backups: confirm an isolated, immutable copy exists and block all writes to it. The most expensive mistake is a rushed restore onto an environment that has not been cleaned, which lets the attacker encrypt the clean copy too.
Document in parallel: the ransom note, the encrypted file extension, the earliest timestamp, affected hosts, and the accounts used. This material is the basis of digital forensics, which identifies the entry point — without it the incident repeats after recovery because the vulnerability stays open.
Why paying is a bad decision: payment guarantees neither a working key nor deletion of the stolen copy, it marks your company as a repeat target known to pay, and depending on the recipient it can create legal exposure. The practical route is recovery from a clean backup with the vulnerability closed, not buying a promise from an attacker.
Legal duties and reporting: if customer personal data is affected, Egypt's Personal Data Protection Law imposes notification duties within a defined period, and regulated sectors (banking, fintech, healthcare) have additional channels. Decide in advance who signs off on notification and who speaks to customers.
Recover in stages, not all at once: rebuild a clean environment, reset every password and key, restore the systems the business cannot trade without first (invoicing, inventory, accounting), then the rest under heightened monitoring for two weeks — attackers usually leave a way back in.
The prevention that would have stopped this: mandatory two-factor authentication on all administrative and remote access, least-privilege user rights, patched systems, 3-2-1 backups with one immutable copy and periodic restore tests, and continuous monitoring that catches lateral movement before the encryption stage — the core job of the Rased operations center.
Penetration testing and red team exercises surface the same paths an attacker would use, but at a time you choose and in a report you can act on. See also the SOC guide and securing an online store.
Rased is the cybersecurity arm of Namra Tech, led by Khalid Namra: monitoring, incident response, forensics, and penetration testing. For a live incident or to build a written response plan before one happens, reach us from the contact page or via rasedsolutions.com.
