- Disconnect all computers and servers from the Internet ( to stop hack and stop encrypting )
- Find the Source of the Hack ( Sometimes this can be as easy as finding the server and PC that started Encryption )
- Restore Servers from a backup to a point in time before the hack and rebuild and compromised workstations
- Check customer passwords on https://hashcast.axur.com/pricing or haveibeenpwned
Tools
- MFA , MFA , MFA
- Windows and Software and Hardware Updates everywhere ( Reduce attack vector )
- Install a good antivirus like SentinelOne to stop future hacks
- Make sure your Router has things like IPS and Web Filtering
- Make sure you have a good spam filter in front
- Run pingcastle.com report on AD Security
- https://pariswells.com/blog/research/ioc-scanners-after-crypto
- Randomize Local Administrator passwords with a tool like Local Administrator Password Solution (LAPS) to prevent lateral movement using local accounts with shared passwords
- User Phish Testing