Practical guide
A response plan for a ransomware attack on the firm
Ransomware is malicious software that encrypts data and demands a ransom to release it. For a management firm this means losing access to the accounting, owners' registers and documents of dozens of condominiums in minutes. This guide is not about generic prevention but about what to do when the attack is already under way: how to isolate the systems, assess the damage, restore from backups and handle the notification obligations set out in Regulation EU 2016/679. A written plan, tested in advance, is the difference between a few hours of downtime and the permanent loss of the data.
First steps in a ransomware attack
- Immediately disconnect the affected computers from the network, without shutting them down if possible
- Isolate the backup media so it does not get encrypted too
- Do not pay the ransom on impulse: first assess the recovery options
- Record the time, date and symptoms of the attack for the reconstruction
- Alert the person in charge and, if any, the IT support provider
- Check which data was encrypted and whether it was also exfiltrated
- Restore from verified backups, starting with the most critical data
- Assess the obligation to notify the supervisory authority within 72 hours if personal data is involved
Recognizing the attack and isolating the systems
The first signs are files that no longer open, changed extensions and an on-screen ransom demand. The moment ransomware is suspected, the absolute priority is to stop it from spreading: disconnecting the computer from the network, turning off wifi and unplugging any shared drives prevents the encryption from reaching the firm's other systems.
If possible, do not shut down the affected computer: its memory may hold information useful for the analysis. Isolating the backup media at once is equally important, because many ransomware strains specifically look for the spare copies to render them unusable and force payment.
Assessing the damage before reacting
Before any decision you need to understand the scope of the damage: which machines are affected, which data is encrypted and whether the cloud management system, which runs on separate infrastructure, remained intact. A firm working in the cloud has a decisive advantage, because the main data does not reside on the affected computer.
You must also assess whether the data was only encrypted or also copied to the outside. Exfiltration turns the incident into a possible personal data breach with stricter notification obligations. Every observation should be recorded: it will be needed for the restore, for the communication to owners and for any report.
- Scope: which computers and media are affected
- Data: what is encrypted and what remained intact in the cloud
- Exfiltration: determine whether the data was copied outside
- Backups: identify the last clean copy to start from
Why not to pay the ransom on impulse
Paying the ransom does not guarantee the data will be recovered and it fuels further attacks. The correct strategy is to restore from backups: if the firm has applied a solid rule, with at least one offline or immutable copy, the ransom route becomes unnecessary. This is precisely why a copy isolated from the network is the most effective defence against ransomware.
The decision, should it ever arise, must be taken with a cool head and the support of a competent technician, not in the first minutes of panic. The written plan exists precisely to remove the emotional urgency and follow a rational sequence.
Restore and obligations to the authority and the owners
The restore starts from the last copy verified as intact, giving priority to the most critical data: accounting in progress, financial reports, owners' register. Before reconnecting the systems you must make sure the threat has been removed, otherwise the restored data would be encrypted again.
If owners' personal data is involved, Article 33 of Regulation EU 2016/679 requires you to assess notifying the breach to the supervisory authority within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the individuals. Where the risk is high, the individual owner must also be informed. Keeping documentation of the incident and the countermeasures is part of the accountability obligation.
Reducing the risk with AmministraPro
Keeping management data on a cloud platform like AmministraPro reduces the firm's attack surface: accounting, documents and the owners' register do not reside on the individual computer, so ransomware hitting one workstation does not compromise the central archive, which is protected and replicated on dedicated infrastructure.
Discover the security and archiving features on the /funzioni page and evaluate the plans on the /prezzi page to set up a firm more resilient to IT incidents.
Frequently asked questions
Should I pay the ransom to get my data back?
No, not as a first choice. Paying does not guarantee recovery and encourages new attacks. The correct route is restoring from backups: if the firm keeps at least one offline or immutable copy, payment becomes unnecessary. Any decision must be taken with a competent technician, not in the first minutes.
Must a ransomware attack be notified to the authority?
If owners' personal data is involved, Article 33 of Regulation EU 2016/679 requires you to assess notifying the supervisory authority within 72 hours of becoming aware of the breach, unless a risk to the individuals is unlikely. If the risk is high, the owner must also be informed. Keep documentation of the incident.
Is my cloud system safe if ransomware hits my PC?
Largely yes. The data in a cloud management system lives on infrastructure separate from the firm's computer, so ransomware that encrypts a local workstation does not reach the central archive. It remains prudent to protect the workstations and keep an independent backup of any data you hold locally.
What is the first thing to do when I discover the attack?
Isolate the systems at once: disconnect the computer from the network, turn off wifi and unplug shared drives to stop the encryption from spreading. Then secure the backup media, which ransomware tends to seek out. Only afterwards move on to assessing the damage and restoring.
Try AmministraPro
Accounting, thousandths-based cost splitting, meetings, communications and artificial intelligence in a single Italian software, compliant with UNI 10801 and GDPR.
