Ransomware

Ransomware India SMB: day zero पर ये 6 steps पहले करें

Ransomware India SMB day-zero playbook — disconnect, note photograph, strain ID, backups isolate, CERT-In 6-hour report, insurance/counsel। Pay कब सोचें।

CyberSathi Desk
Ransomware India SMB: day zero पर ये 6 steps पहले करें

पहले: pay मत करो। अभी नहीं।

Screen पर ransom note हो तो पहला फैसला payment नहीं — containment है। Pay कभी rational हो सकता है; first move कभी नहीं।

Ransomware India SMB cases में day-zero गलतियाँ — shutdown, same-network backups, attackers से पहले बात — recovery और insurance दोनों खराब करती हैं।

Related: Why Indian businesses pay ransoms · Data-breach notification मतलब क्या · Phishing email 30 seconds

Day-zero checklist (इसी क्रम में)

  1. Disconnect — shut down नहीं। Network cables / Wi-Fi काटें ताकि encryption freeze हो; volatile evidence wipe न हो।
  2. Ransom note photograph करें। Full screen — timer, wallet address, contact instructions। CERT-In और insurer दोनों को चाहिए।
  3. Strain identify करें। Note ID Ransomware पर upload करें। Strain बताता है free decryptor है या नहीं।
  4. Backups physically isolate करें। Backup server same network पर हो तो मान लें encrypt हो रहा है — cable खींचें / offline copy सुरक्षित करें।
  5. CERT-In को report करें। 2022 directive के तहत 6-hour window real है। incident@cert-in.org.in पर जो है भेजें। Portal/guidance: CERT-In।
  6. Outside counsel + cyber-insurance broker — attackers से बात करने से पहले। Premature engagement coverage void कर सकता है।

Money-mule / UPI side trails अलग topic: Money mule account · Report habit: cybercrime.gov.in · 1930 FAQ: 1930

Pay करना है या नहीं

Clean answer नहीं। Considerations:

  • Public decryptor उपलब्ध है? (हाँ → never pay)
  • Backups actually restorable हैं, या सिर्फ “present”?
  • असली threat encryption है या data-exfiltration + leak?
  • Insurer क्या require / forbid करता है?

ज़्यादातर SMBs जो pay करते हैं — उनके पास tested restore procedure नहीं होती। इस quarter backups restore test करें — day-zero से पहले।

Entry अक्सर phishing / remote access से: Phishing checklist · AnyDesk refund scam · WhatsApp scam India

Frequently asked questions

Ransomware India SMB पर सबसे पहला कदम क्या है?

Containment: network disconnect (clean shutdown नहीं), note photograph, backups isolate — pay decision बाद में।

CERT-In को कब बताएँ?

जितना जल्दी हो; directive 6 hours की बात करती है। Email incident@cert-in.org.in + जो evidence है attach/describe करें।

Free decryptor कैसे पता चले?

Strain ID tools (जैसे ID Ransomware) से। Decryptor मिले तो ransom मत दो — restore/decrypt path follow करें।

Insurance से पहले attacker से बात क्यों नहीं?

Premature negotiation / payment conditions coverage void कर सकती हैं। Broker + counsel पहले।

Official resources

Read next