Bu məzmun hazırda yalnız ingilis dilində təqdim olunur.
Timeline
Do
- Alert your incident response team and management immediately; have one person coordinate decisions.
- Cut network connectivity, keep systems running and take disk and memory images.
- Reset passwords for all admin and service accounts once the attacker is contained.
- Verify that backups are isolated from the network and unmodified.
- If personal data is affected, start the regulator notification process — under GDPR and KVKK this is due within 72 hours.
Don’t
- Don’t power off or reboot affected systems.
- Don’t restore from backups before the attacker’s access is cut.
- Don’t contact or pay the attacker without legal advice.
- Don’t discuss the incident over corporate email or chat that may be compromised.
Under attack right now?
Reach our team at [email protected] or through the Emergency Response page.
Preparation: before the attack
- 01
Immutable backups
At least one backup copy offline or immutable.
- 02
Exercises
A tabletop crisis exercise at least once a year.
- 03
Communication plan
Predefined out-of-band emergency communication channels.
- 04
Response retainer
An agreement in place with a response team to call during an incident.
To measure your readiness, see our Ransomware Readiness & Response service.
Əhatəni birlikdə müəyyən edək.
Ehtiyacınızı bildirin — mütəxəssislərimiz sizə xüsusi təklif hazırlasın.



