DRP and BCP
What should you do after a cyberattack?
After a cyberattack, the first useful action is to stop the spread, not to reinstall as quickly as possible. Affected systems are isolated, evidence is preserved, a copy predating the intrusion is identified, and production is only reconnected once the route used by the attacker is understood, at least in broad terms.
Updated in October 20264 min read5 sources cited
Key points
- Cut the network links of affected machines without switching them off: memory contains evidence useful to the investigation.
- Do not pay the ransom: recovery is not guaranteed and payment funds the attacker.
- With cyber insurance, check the complaint and claim deadlines in your contract: they vary by country and insurer.
- If personal data is affected, your country’s data protection authority must be notified within 72 hours when the breach poses a risk (GDPR, Article 33; for example the APD in Belgium, the CNPD in Luxembourg, the CNIL in France).
- Restore the latest copy predating the intrusion, on a clean network, not the most recent one onto the infected network.
The first few hours
This page is a decision framework. It does not replace an incident response provider nor, depending on severity, the reports to the insurer, the police and the data protection authority.
- Appoint one decision-maker. One person, not a chat thread with twenty participants. That person authorises disconnections. The ANSSI, France’s national cybersecurity agency, recommends opening an incident log from the outset: who did what, and when.
- Isolate without wiping everything. Cut Internet access to the attacked network, then disconnect suspicious machines from the network (cable, Wi-Fi, VPN). Switching off is not the right default reflex: memory may contain information useful for the analysis. However, letting a server encrypt the rest of the network is worse. Do not switch back on any unaffected machines that were off either.
- Do not pay in a panic. European authorities and No More Ransom (Europol and partners) advise against paying: the ransom guarantees neither the key, nor that the attacker holds no copy of the data, nor that they will not return, and it funds new attacks.
- Alert senior management, the IT provider, the insurer, and the legal contact for the data protection authority if personal data is involved.
- Keep a record: time of discovery, what was disconnected, screenshots, ransom note, logs. Do not reformat affected disks until a clean copy has been confirmed and the insurer or the investigators have said whether the originals must be preserved.
The deadlines that apply
| Step | Deadline | Who |
|---|---|---|
| Filing a complaint (if cyber insurance) | Depends on the contract and the country: check it without delay | Police in your country |
| Insurance claim | According to the contract, often very short | Insurer |
| Notification of a personal data breach | 72 hours at the latest, if the breach poses a risk | Data protection authority |
| Informing the individuals concerned | Without undue delay, if the risk is high | Affected customers and employees |
| Entry in the breach register | Always | Internal |
The complaint must be filed before machines are reinstalled, so that the technical evidence is still available. To be pointed in the right direction quickly, contact your country’s national CSIRT (list maintained by the EU CSIRTs Network).
Getting back to a clean state
- Look for the latest backup predating the abnormal activity, not necessarily the most recent one. The most recent one is often already contaminated or encrypted.
- Check that this backup is outside the attacked network and that an account controlled by the attacker can no longer delete it. This is where immutability proves its worth.
- Do not restore onto machines still connected to the compromised network. Restore onto a clean network, or onto isolated standby instances, after changing passwords and removing any questionable access.
The ANSSI describes remediation in four stages: containment, eviction of the attacker, eradication, then rebuilding. Restoring before eviction means handing the attacker a brand-new system. Details of the technical restart are in How do you restart your IT systems after ransomware?. The immediate action checklist is in Ransomware has just been triggered.
What not to believe
- “The antivirus removed everything, we can reopen.” It may have seen the encryption, but not the accounts created three weeks earlier.
- “Yesterday’s backup is enough.” Not if the intrusion dates back three weeks.
- “The BCP has failed over, so we are safe.” If the standby site received the same encrypted files, it is in the same state. A historical version is needed.
- “Everything will be up and running in two days.” The ANSSI points out that after a major incident, remediation can take several weeks or even several months. Plan a degraded mode for that period.
Afterwards
Post-incident report, change of secrets, closing the entry route (account without a second factor, deletable backup, no alerting), a new restore test. An attack that does not lead to changes in practice will happen again.
At WeDoBack
Copies are stored on servers dedicated to backup, separate from production and outside the customer’s network. If the IMMUTABLE offer is in place for the period concerned, these copies cannot have been modified or deleted by the attacker. The DRP makes it possible to restart servers on standby instances from a chosen version, which avoids restoring onto a network that is still questionable; activation during a disaster is billed per day. The encryption key is held by the customer: it must be available in order to restore. Support can be reached on +33 9 72 50 78 28 or at [email protected], from 9:00 to 13:00 and from 14:00 to 17:30 (Paris time). WeDoBack restores the systems that are backed up. It does not, on its own, investigate the intrusion or notify the data protection authority: these roles must be provided for elsewhere.
Frequently asked questions
Should computers be switched off after a cyberattack?
As a general rule, no: disconnect them from the network (cable, Wi-Fi) without switching them off, so that evidence held in memory is preserved for the investigation. There is one exception: if encryption is still in progress and cannot be stopped any other way, shutting down may become necessary.
How soon must a complaint be filed?
As early as possible, before machines are reinstalled. If you have insurance covering cyber risk, check the deadlines for reporting the claim and filing a complaint in your contract: they vary by country and insurer. The complaint is filed with the police in your country, online where possible.
Is a ransomware attack a data breach that must be reported to the data protection authority?
Often, yes: the GDPR defines a breach as the destruction, loss, alteration or unauthorised disclosure of personal data. Customer or employee files encrypted by ransomware fall within this definition, and the GDPR (Article 33) then requires the data protection authority to be notified. Every breach is recorded in the internal register; it must be notified to that authority within 72 hours whenever it poses a risk to individuals, and the individuals concerned must be informed if the risk is high.
How long does it take to get back to normal?
For a major incident, the ANSSI, France’s national cybersecurity agency, states that remediation can take several weeks or even several months. The most critical services can restart earlier, on a clean or standby infrastructure, while the rest is being rebuilt.
Sources
Documents consulted in October 2026.
- No More Ransom: advice and tools against ransomware — Europol and partners
- Guidelines 9/2022 on personal data breach notification (French version) — EDPB
- Cyber crisis: keys to operational and strategic management (December 2021) — ANSSI (French agency)
- Cyberattacks and remediation: keys to decision-making (v1.0, December 2023) — ANSSI (French agency)
- DRP offer: recovery after a disaster — WeDoBack
Planning a backup, DRP or BCP project?
More than 20 years of experience protecting business data.
Request a quote+33 9 72 50 78 28Protect your data with WeDoBack
Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.
