2.2 What to Do in the Event of a Cyber Attack?
In order to initiate measures in the event of a cyber attack, a cyber attack contingency plan should be drawn up for such a case. Because here, too, prevention is better than cure. The content of the plan depends on the type of attack and the IT environment of the institution. Here, it is a good idea to consult a security expert – they can offer you help with the cyber attack, assisting you with the question: “Cyber attack, what to do?”.
In the event of a network intrusion, the first thing to do is damage limitation. The next steps depend on the scope of the attack. In the case of a local attack, it is sometimes sufficient to change the admin password. However, if you suspect a widespread attack, you may have to take some systems offline. In this case, it is a matter of damage limitation until you have traced the source of the cyber attack.
Remember that every cyber attack is a criminal act. You need to gather evidence both for your cyber attack insurance and for law enforcement. Especially if an attack has already been stopped, quick action is necessary – because hackers often cover their tracks.