Ransomware India SMB: day zero पर ये 6 steps पहले करें
Ransomware India SMB day-zero playbook — disconnect, note photograph, strain ID, backups isolate, CERT-In 6-hour report, insurance/counsel। Pay कब सोचें।

पहले: pay मत करो। अभी नहीं।
Screen पर ransom note हो तो पहला फैसला payment नहीं — containment है। Pay कभी rational हो सकता है; first move कभी नहीं।
Ransomware India SMB cases में day-zero गलतियाँ — shutdown, same-network backups, attackers से पहले बात — recovery और insurance दोनों खराब करती हैं।
Related: Why Indian businesses pay ransoms · Data-breach notification मतलब क्या · Phishing email 30 seconds
Day-zero checklist (इसी क्रम में)
- Disconnect — shut down नहीं। Network cables / Wi-Fi काटें ताकि encryption freeze हो; volatile evidence wipe न हो।
- Ransom note photograph करें। Full screen — timer, wallet address, contact instructions। CERT-In और insurer दोनों को चाहिए।
- Strain identify करें। Note ID Ransomware पर upload करें। Strain बताता है free decryptor है या नहीं।
- Backups physically isolate करें। Backup server same network पर हो तो मान लें encrypt हो रहा है — cable खींचें / offline copy सुरक्षित करें।
- CERT-In को report करें। 2022 directive के तहत 6-hour window real है।
incident@cert-in.org.inपर जो है भेजें। Portal/guidance: CERT-In। - Outside counsel + cyber-insurance broker — attackers से बात करने से पहले। Premature engagement coverage void कर सकता है।
Money-mule / UPI side trails अलग topic: Money mule account · Report habit: cybercrime.gov.in · 1930 FAQ: 1930
Pay करना है या नहीं
Clean answer नहीं। Considerations:
- Public decryptor उपलब्ध है? (हाँ → never pay)
- Backups actually restorable हैं, या सिर्फ “present”?
- असली threat encryption है या data-exfiltration + leak?
- Insurer क्या require / forbid करता है?
ज़्यादातर SMBs जो pay करते हैं — उनके पास tested restore procedure नहीं होती। इस quarter backups restore test करें — day-zero से पहले।
Entry अक्सर phishing / remote access से: Phishing checklist · AnyDesk refund scam · WhatsApp scam India
Frequently asked questions
Ransomware India SMB पर सबसे पहला कदम क्या है?
Containment: network disconnect (clean shutdown नहीं), note photograph, backups isolate — pay decision बाद में।
CERT-In को कब बताएँ?
जितना जल्दी हो; directive 6 hours की बात करती है। Email incident@cert-in.org.in + जो evidence है attach/describe करें।
Free decryptor कैसे पता चले?
Strain ID tools (जैसे ID Ransomware) से। Decryptor मिले तो ransom मत दो — restore/decrypt path follow करें।
Insurance से पहले attacker से बात क्यों नहीं?
Premature negotiation / payment conditions coverage void कर सकती हैं। Broker + counsel पहले।
Official resources
- CERT-In ·
incident@cert-in.org.in - National Cyber Crime Reporting Portal · Helpline 1930
- MeitY
- Reserve Bank of India (regulated entities / payment disruption context)

