DRP and BCP
What should you do after a cyberattack?
After a cyberattack, the first useful action is to stop the spread, not to reinstall as fast as possible. You isolate the affected systems, preserve the evidence, identify a copy that predates the intrusion, and only reconnect production once the path used by the attacker is understood, at least in broad terms.
Updated October 20264 min read5 sources cited
Key points
- Disconnect the affected machines from the network without shutting them down: memory may hold evidence, and CERT-MU cites unplugging the network cable as a containment measure.
- Do not pay the ransom: recovery is not guaranteed and payment funds the attacker.
- File a complaint before reinstalling with the Cybercrime Unit of the Mauritius Police Force, and check the claim notification deadline in your cyber insurance policy.
- If personal data is affected, notify the Data Protection Commissioner, within 72 hours where feasible (Data Protection Act 2017, section 25).
- Restore the latest copy made before the intrusion, on a clean network, not the most recent one on the infected network.
The first hours
This page is a decision framework. It does not replace an incident response provider or, depending on severity, reports to CERT-MU, the insurer, the police and the Data Protection Office.
- Appoint one decision-maker. One person, not a twenty-member chat thread. That person authorises disconnections. CERT-MU asks for every action to be documented, and the ANSSI, France’s national cybersecurity agency, recommends opening an incident log from the outset: who did what, and when.
- Isolate without wiping everything. Cut Internet access to the attacked network, then disconnect the suspect machines from the network (cable, Wi-Fi, VPN). Shutting down is not the right default reflex: memory may contain material useful for the analysis. That said, letting a server encrypt the rest of the network is worse. Do not switch on unaffected machines that were turned off either.
- Do not pay under pressure. Cybersecurity agencies, including the ANSSI, advise against paying: the ransom guarantees neither the key, nor that the attacker has not kept a copy of the data, nor that they will not come back, and it funds further attacks.
- Notify: management, your IT provider, the insurer, CERT-MU (report on MAUCORS+, hotline 800 2378), and your legal contact for the Data Protection Office if personal data is involved.
- Keep a record: time of discovery, what was disconnected, screenshots, ransom note, logs. Do not reformat the affected disks until a clean copy has been confirmed and the insurer or investigators have said whether the originals must be preserved.
Deadlines that apply
| Step | Deadline | Who |
|---|---|---|
| Cybercrime complaint | Before the machines are reinstalled | Mauritius Police Force (Cybercrime Unit) |
| Insurance claim | As set in the policy (deadline and required documents), often very short | Insurer |
| Personal data breach notification | Without undue delay, within 72 hours where feasible (DPA 2017, section 25) | Data Protection Commissioner (eDPO portal) |
| Informing the data subjects | Without undue delay, if the risk is high (section 26) | Affected customers and employees |
| Entry in the breach register | Always | Internal |
The complaint must be filed before the machines are reinstalled, so that the technical evidence is still available. For immediate assistance, report the incident on MAUCORS+, the national platform powered by CERT-MU, which forwards the case to the competent institution (CERT-MU hotline: 800 2378).
Getting back to a clean state
- Look for the latest backup made before the abnormal activity, not necessarily the most recent one. The most recent one is often already contaminated or encrypted.
- Check that this backup is outside the attacked network and that an attacker-controlled account can no longer delete it. This is where immutability proves its worth.
- Do not restore onto machines that are still connected to the compromised network. Restore onto a clean network, or onto isolated standby instances, after changing passwords and removing suspicious access.
The ANSSI, France’s national cybersecurity agency, describes remediation in four stages: containment, eviction of the attacker, eradication, then rebuilding. Restoring before eviction means handing the attacker a brand-new system. The details of the technical restart are in How do you restart your IT systems after ransomware?. The checklist of immediate actions is in Ransomware has just been triggered.
What not to believe
- “The antivirus removed everything, we can reopen.” It may have spotted the encryption, but not the accounts created three weeks earlier.
- “Yesterday’s backup is enough.” Not if the intrusion began three weeks ago.
- “The BCP has failed over, so we are safe.” If the standby site received the same encrypted files, it is in the same state. You need a historical version.
- “Everything will be back up in two days.” The ANSSI points out that after a major incident, remediation can take several weeks, or even several months. Plan a degraded mode for that period.
Afterwards
Post-incident report (CERT-MU recommends a lessons-learned meeting within two weeks), rotation of secrets, closing the entry point (an account without a second factor, deletable backups, no alerting), and a new restore test. An attack that leads to no change in practice will happen again.
At WeDoBack
Copies are stored on servers dedicated to backup, separate from production and outside the customer’s network. If the IMMUTABLE offer is in place for the period concerned, these copies cannot have been modified or deleted by the attacker. The DRP lets you restart servers on standby instances from a chosen version, which avoids restoring onto a network that is still suspect; activation during a disaster is billed per day. The encryption key is held by the customer: it must be available to restore. Support can be reached on +33 9 72 50 78 28 or at [email protected], from 9:00 to 13:00 and 14:00 to 17:30 (Paris time, i.e. 11:00 to 15:00 and 16:00 to 19:30 in Mauritius during European summer time, one hour later in winter). WeDoBack restores the systems it backs up. It does not, on its own, investigate the intrusion or notify the Data Protection Office: these roles must be covered elsewhere.
Frequently asked questions
Should computers be switched off after a cyberattack?
As a general rule, no: disconnect them from the network (cable, Wi-Fi) without switching them off, to preserve material in memory that is useful for the investigation. CERT-MU itself cites unplugging the network cable as a typical containment measure. Exception: if encryption is still in progress and cannot be stopped any other way, shutting down may become necessary.
How quickly should a complaint be filed?
As soon as possible, before reinstalling the machines, so that the technical evidence is still available. Complaints are filed with the Mauritius Police Force (Cybercrime Unit, Central CID). If you have cyber insurance, check your policy for the claim notification deadline and the supporting documents required, including proof of the complaint.
Is a ransomware attack a data breach that must be reported to the Data Protection Office?
Often, yes: customer or employee files encrypted, lost or copied by ransomware constitute a personal data breach within the meaning of the Data Protection Act 2017. Section 25 requires it to be notified to the Data Protection Commissioner without undue delay and, where feasible, within 72 hours; notification is made online via the eDPO portal. Section 26 requires the data subjects to be informed if the risk is high. Also keep a written record of every breach.
How long does it take to return to normal?
For a major incident, the ANSSI, France’s national cybersecurity agency, states that remediation can extend over several weeks, or even several months. The most critical services can restart earlier, on clean or standby infrastructure, while the rest is rebuilt.
Sources
Documents consulted in October 2026.
- Guideline on Incident Handling (v1.1) — CERT-MU
- eDPO: online notification of personal data breaches — Data Protection Office (Mauritius)
- Cyber crisis: keys to operational and strategic management (December 2021) — ANSSI, France’s national cybersecurity agency
- Cyberattacks and remediation: keys to decision-making (v1.0, December 2023) — ANSSI, France’s national cybersecurity agency
- DRP offer: recovery after a disaster — WeDoBack
Planning a backup, DRP or BCP project?
More than 20 years of experience protecting business data.
Request a quote+33 9 72 50 78 28Protect your data with WeDoBack
Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.
