Skip to main content

You have been hacked

What to do in the first hour after a compromise, and what India requires in the first six: the containment order, the evidence that cannot be recreated later, and the CERT-In, RBI and SEBI filings that fall due meanwhile.

10 guides. Published by Security Brigade. Last reviewed .

Buying one

What it costs, who is qualified to do it, and what you receive at the end.

Ransomware recovery: the paths out, in the order they are tried

Data comes back one of four ways: a backup restore that has actually been verified, a free decryptor for the family you are really dealing with,…

What ransomware negotiation actually looks like

The sanctions question comes before the price question, and it decides whether there is anything to discuss at all. What a negotiation channel do…

Which ransomware is this, and what the family name decides

You know you are encrypted. You do not yet know by what — and the questions that follow are all questions about the family: whether a free decryp…

Business email compromise — the money left this morning

A payment went to an account that was not your supplier's. The instinct is to chase the money, and that is right — but a BEC is a mailbox intrusi…

How they got in — and why your logs decide whether you can answer

The morning after, the question is how. A short list of entry classes, each confirmed from a different record — and every one of those records is…

Website defacement, or a Google warning on your site: the first hour

A replaced homepage, or a Chrome warning on your site. What to copy before you touch the server, and the CERT-In clause that puts a defaced site…

What the ransom decision actually turns on

By the time the question reaches you it is usually framed as pay or don't. It is really five separate findings, and four of them can be establish…

Preserve it before you rebuild

Powering the machine off, restoring from backup, re-imaging, and quietly cleaning up: four reasonable instincts, each of which destroys something…

The six-hour report: what actually gets sent, and who else you owe

You noticed at 09:40. CERT-In is due by 15:40. What goes in the six-hour report, who sends it, and which other regulators are owed a filing too.

The first hour, and the first seventy-two

The order to work in from the moment you find out: what to stop doing, what to preserve, who to call, and what CERT-In's Direction (ii) of 28 Apr…

If this is happening now

Preservation first, and the filing is due either way.

The acts that end an investigation are the ones somebody reaches for in the first ten minutes: power it off, restore over the top, re-image it, clean up the page. Tell us what you have found and what has already been touched, and you will get the containment order, the preservation steps and your filing position in writing. Security Brigade has been CERT-In empanelled since 2008 and works incidents 24/7.

Also from Security Brigade