US officials: Do these 7 things after a ransomware attack

As ransomware attacks persist, the federal government is developing recommendations for companies on how to respond to an attack. The Cybersecurity and Infrastructure Security Agency recommended hospitals to follow these seven steps:

Advertisement
  1. Determine which systems have been affected and isolate them immediately.
  2. If unable to disconnect devices from the network, turn them off to avoid further spread.
  3. Triage affected devices for restoration.
  4. Document what has occurred, based on initial analysis.
  5. Get help from a third-party incident response provider.
  6. If mitigation prospects look slim, take a system image and memory capture of a sample of affected devices. Be mindful of preserving evidence. Collect relevant logs and samples of malware binaries.
  7. Consult federal law enforcement regarding decryptors available as researchers have broken encryption algorithms for some ransomware variants. 

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Register to Attend Webinar

The hidden cost of lost clinical time and how leading health systems are responding

Friday, August 7
12:00 PM - 1:00 PM CDT

Presenters: Kassaundra McKnight-Young, Zebra TechnologiesGregory Carras, Zebra TechnologiesJennifer Gene, Levata

Advertisement

Next Up in Cybersecurity

Advertisement

Comments are closed.