Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security

Ransomware Just Hit. What to Do in the First 24 Hours

Direct answer: Isolate rather than shut down, preserve evidence, get legal and insurance involved before you negotiate anything, and start the notification clock deliberately. The most expensive mistakes in the first day are wiping machines to restore faster and telling customers something you have to correct later.

First hour

Isolate affected systems from the network. Do not power them off if you can avoid it, because memory holds evidence you will want. Disable the compromised accounts you know about. Get everyone communicating on a channel the attacker is not in, which usually means not your normal chat if identity was compromised.

Call your cyber insurer before doing anything else expensive. Policies frequently require you to use their approved responders, and engaging your own first can affect the claim.

What not to do

Do not rebuild immediately. Restoring over the evidence means you will never know how they got in, and you will restore the same weakness. Do not pay or open negotiation without legal advice, sanctions screening and insurer involvement. Do not tell customers "no data was accessed" before anyone has established that.

Establish scope before you communicate

The questions that matter: what was accessed as opposed to encrypted, whether personal information was involved, which customers are affected, and whether data was taken as well as locked. Modern ransomware usually exfiltrates first, so encryption without exfiltration is the exception rather than the assumption.

Before you need it. Incident response on retainer means the contracts, the access and the runbooks already exist when the pager goes off. See how a retainer works

The Canadian notification clock

Under PIPEDA you must report breaches of security safeguards that create a real risk of significant harm to the Privacy Commissioner of Canada and notify affected individuals, as soon as feasible, and keep records of all breaches regardless. Quebec's Law 25 has its own obligations if you hold data on Quebec residents. Health information brings PHIPA and the Ontario Commissioner into it.

Your customer contracts almost certainly have their own notification windows, often far shorter than the statutory ones. Check them on day one, not week two.

After

A written post-incident review covering root cause, what worked and what did not, with owners and dates. You will need it for insurers, for customers, and for the security reviews that follow, because buyers will ask about the incident for years and a clear account of what changed is what closes the conversation.

If you are in this now and have no retainer, contact us and say it is live. If you are reading this beforehand, which is the better time, On-Call Incident Response puts the relationship and the SLA in place before you need them, and a tabletop is how you find out whether the plan works while it is still cheap to find out.

What isolation actually means in practice

"Isolate the affected systems" is easy to write and harder to execute at two in the morning. There are two containment jobs and they need to happen in parallel. Network containment stops the encryption spreading: pull the switch port or apply the network isolation action in your EDR console, which keeps the agent talking to you while cutting everything else. Identity containment stops the attacker walking back in through a door you did not know was open. That means revoking active sessions and refresh tokens rather than only resetting passwords, because a stolen session token survives a password change in most identity providers. Disable any federation or SAML trust you cannot vouch for, suspend service principals and app registrations created in the past ninety days, and check for mailbox forwarding rules and newly enrolled authenticator devices on privileged accounts.

If the intruder reached your directory, assume every credential in it is compromised, including service accounts nobody has touched in years and the accounts your backup software uses. In an Active Directory environment, plan on rotating the krbtgt account twice with a gap between rotations, and understand that doing so before you have finished investigating will destroy some of the telemetry you need. That tension between containment and evidence is the defining problem of the first day, and the way through it is to decide deliberately, with someone recording what was decided and when, rather than to let each engineer make the call alone.

Hours two to eight: establish what you can still trust

Once spread has stopped, the question becomes which parts of your estate are still trustworthy enough to rebuild from. Work through it in a fixed order. Confirm whether your backups exist, whether they are reachable, and whether they were encrypted or deleted, because competent ransomware operators target the backup infrastructure first and often days before they deploy the payload. Check whether your backup repository is immutable or air-gapped, and check the retention window against the date of first intrusion rather than the date of encryption. Restoring from a snapshot taken three days ago is worthless if the attacker had been resident for six weeks.

Then start pulling the evidence that expires. Volatile artefacts go first: memory from at least one representative encrypted host, running process lists, and network connection state. After that, collect the logs with short retention clocks. Cloud identity sign-in logs, unified audit logs, VPN and firewall logs, and EDR telemetry all have default retention periods measured in weeks, and some of them are shorter than the investigation will take. Export them to storage the attacker cannot reach, note the hashes, and record who collected what and when. That collection log becomes the backbone of every conversation that follows with insurers, regulators and customers.

The ransom question, handled properly

Paying is a legal and commercial decision, not a technical one, and the people qualified to make it are your counsel, your insurer and your board. Several mechanics are worth understanding before the question arrives. Sanctions screening is mandatory: paying a group that is designated under Canadian or US sanctions regimes exposes the company and its officers to liability irrespective of the circumstances, and the attribution work that establishes which group you are dealing with takes time. Decryptors supplied by ransomware operators frequently work slowly, corrupt a proportion of files, and require per-host execution, so even a successful payment rarely restores faster than a clean rebuild from good backups.

The second half of the extortion is the part that catches companies out. Almost every serious operation now steals data before encrypting it, then demands a separate payment not to publish it. There is no enforceable way to verify deletion. A signed certificate of destruction from a criminal group is worth nothing evidentially, and paying does not remove your notification obligations, because the exposure already happened. Treat exfiltration as a data breach the moment you find evidence of large outbound transfers, staging archives, or an unfamiliar file transfer utility on a server, and start the assessment of whose personal information was in those files immediately rather than waiting for confirmation.

Insurance and privilege, in the right order

Cyber policies are more prescriptive than most executives realise until they read one during an incident. Notice provisions are often measured in hours and can be triggered by "circumstances likely to give rise to a claim" rather than confirmed loss, so notifying early costs you nothing and notifying late can cost you the claim. Most policies carry a panel of approved breach counsel and approved forensic providers, with rates already negotiated. Engaging your own responder before the insurer approves it frequently makes those fees non-recoverable, even when the work was necessary and competent.

Retaining counsel first, and having counsel retain the forensic firm, is standard practice for a reason. It gives the investigation a reasonable claim to legal privilege, which matters because forensic reports get requested in litigation and by regulators. Privilege is not automatic and it is not absolute, but the structure of the engagement letters determines whether you have any argument at all. Also check your sublimits before you commit to spending. Business interruption, ransom payment, forensic costs and notification costs are usually separate buckets, and the notification bucket runs out fastest when you have a large consumer base.

Communications that do not create a second problem

Your first external communication should say four things and nothing else: that you have identified a security incident, that you have engaged external specialists, that you are investigating scope, and when you will update next. Then meet that update commitment even when there is nothing new, because silence is what turns an incident into a reputational event. Avoid any characterisation of data exposure until forensics supports it. The correction you have to issue later is remembered far longer than the original statement.

Do not neglect internal communication. Staff will hear about it, and in the absence of information they will speculate to customers, on social media, and to journalists. Give them a short factual brief, a named person to route enquiries to, and clear instruction not to discuss specifics. Brief your customer-facing team separately with an approved holding response, because they will be asked before your formal notification goes out. And check your material contracts on day one for notification windows, because enterprise agreements commonly require notice within twenty-four or forty-eight hours of becoming aware, which is far tighter than any statutory clock and is the obligation companies most often miss.

Rebuilding without reinfecting yourself

The rebuild is where recovery either holds or repeats. Stand up a clean environment rather than restoring into the compromised one. That means new infrastructure, freshly built domain controllers rather than restored ones where possible, and a staged migration of workloads with each system checked before it joins the clean network. Restore data, not systems, where you can, because data restores carry less risk of bringing the persistence mechanism back with them. Patch and harden before reconnecting, not after, and put multi-factor authentication on remote access and privileged accounts as part of the rebuild rather than as a follow-up project, since the initial access vector in these cases is very often a remote access service without it.

Sequencing matters as much as speed. Identity and directory services come first, then backup infrastructure, then the systems the business needs to bill and serve customers, then everything else. Publish that order to the executive team early, because otherwise every department will lobby for its own system to be next and the technical team will spend the day arbitrating instead of rebuilding.

When you should not call us

If you already hold a cyber policy with a panel forensic provider, call the insurer's hotline rather than us. Their responder is pre-approved, the rates are settled, and bringing in an unapproved firm first can put your claim at risk. We would rather you make the covered call than the fast one, and if the panel firm needs local support afterwards, that conversation can happen once the claim is protected.

If you are a ten-person company with cloud-only infrastructure, immutable backups you have tested a restore from, and no personal information beyond your own staff records, a full incident response engagement may be more than the situation warrants. Rebuild from the known-good snapshot, rotate every credential, force reauthentication across your identity provider, and spend the money on closing the access path instead. The case for engaging a firm strengthens sharply when personal or health information may have left the building, when a regulator or an enterprise customer is going to ask questions, or when you cannot establish how the intruder got in. Where a retainer earns its cost is in the hours it removes at the start, since the contracts, the access and the escalation path already exist. That is what an incident response retainer buys, and it is worth arranging while nothing is on fire. If you want the underlying controls examined first, our security work starts from the access paths these cases actually use, and contact us if you need to establish which of those two conversations you are in.

Before you need it. Incident response on retainer means the contracts, the access and the runbooks already exist when the pager goes off.

See how a retainer worksOr talk about a retainer

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on incident response. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.