- Job title
- Network Administrator
- Sector
- Insurance
- Organization type
- boutique agency
- Joined
- Jan 2025
- Message
- 80
We are a family-run business in Gebze distributing wholesale hardware and industrial supplies, with 20 office staff and 40 field workers. Last Tuesday morning at 07:00, I was woken up by a phone call from our warehouse manager. No one could log into the accounting and inventory software, every PDF and data file on the server had its extension changed, and there was a text file on the desktop demanding the crypto equivalent of about 1,300,000 TL.
In a panic our IT guy ran into the server room and immediately pulled the main network cables. However, because our network-attached storage (NAS) unit was mapped to the server as a persistent drive letter we discovered that the automatic daily backups stored on it had also been encrypted. All we had left was an external hard drive backup, kept locked in the company safe, which luckily had been taken 16 days earlier.
The first 24 hours were absolute chaos: arguing over whether to pay the ransom, field shipments grinding to a halt being unable to issue an e-fatura, and the humiliation of not knowing what to tell our clients. We learned some very painful lessons from this nightmare. What is the proper first-response protocol during a disaster like this?