Task5:

Scenario
	A ransomware attack has encrypted all files stored on Ghaymah Block Storage.
	Users can no longer access their files, and the attacker demands payment in exchange 	for the 	decryption key.
________________________________________
1. Emergency Response Plan (First 60 Minutes)

	0–15 Minutes: Identification & Isolation
	Objectives
•	Confirm that a ransomware attack has occurred. 
•	Prevent the malware from spreading. 
	Actions
•	Disconnect affected virtual machines from the network. 
•	Disable access to shared Block Storage volumes. 
•	Block suspicious IP addresses using firewall rules. 
•	Stop scheduled synchronization tasks. 
•	Notify the security and incident response teams. 


	15–30 Minutes: Investigation
	Objectives
	Determine the scope of the attack. 
	Actions
•	Review system and application logs. 
•	Identify the ransomware entry point. 
•	Determine which servers and storage volumes are affected. 
•	Preserve logs and forensic evidence. 
•	Check whether backups are intact. 

	30–45 Minutes: Containment & Eradication
	Objectives
	Remove the ransomware and stop further encryption. 
	Actions
•	Isolate infected systems. 
•	Scan all virtual machines with antivirus/EDR tools. 
•	Remove malicious processes and scheduled tasks. 
•	Rotate compromised credentials. 
•	Patch exploited vulnerabilities. 

	45–60 Minutes: Recovery Preparation
	Objectives
	Prepare for service restoration. 
	Actions
•	Verify the integrity of backups. 
•	Restore critical services in a test environment.  
•	Validate restored data.  
•	Monitor systems for reinfection. 
Gradually return services to production. 
Timeline Summary
Time	Activity
0–15 min	Detect attack and isolate affected systems
15–30 min	Investigate logs and identify affected resources
30–45 min	Remove ransomware and secure infrastructure
45–60 min	Restore from backups and validate services
________________________________________

2. Ghaymah Backup & Recovery Strategy

Recovery Point Objective (RPO)
	Definition: The maximum acceptable amount of data loss.
	Proposed Value: 15 minutes
	This means backups or snapshots should occur at least every 15 minutes for critical data.
________________________________________
Recovery Time Objective (RTO)
	Definition: The maximum acceptable downtime before services are restored.
	Proposed Value: 1 hour
	Critical applications should be operational again within one hour.
________________________________________
Backup Strategy
	Daily Incremental Backups
	Capture only changes made since the previous backup.
	Advantages:  Faster , Less storage usage 
________________________________________
Weekly Full Backup
	Create a complete copy of all Block Storage volumes.
	Advantages:  Faster restoration, Simplified disaster recovery 
________________________________________
Monthly Offline Backup
	Store a copy outside the production environment.
	Purpose: Protection against ransomware encrypting online backups. 
________________________________________
3-2-1 Backup Rule
The organization should follow the 3-2-1 backup strategy:
•	3 copies of the data (one primary + two backups). 
•	2 different storage media (e.g., Block Storage and external storage/object storage). 
•	1 off-site or offline backup stored separately from the production environment. 
________________________________________
3. Comprehensive Prevention Plan
Identity & Access Management (IAM)
•	Enable Multi-Factor Authentication (MFA). 
•	Apply the Principle of Least Privilege. 
•	Review user permissions regularly. 
•	Rotate passwords and API keys. 
________________________________________
Network Security
•	Enable firewalls. 
•	Segment production and backup networks. 
•	Restrict remote administration access. 
•	Use VPN for administrative access. 
________________________________________
Endpoint Security
•	Deploy Endpoint Detection and Response (EDR). 
•	Keep operating systems and software patched. 
•	Disable unnecessary services. 
•	Enable application allow-listing where appropriate. 
________________________________________
Backup Protection
•	Use immutable backups where possible. 
•	Encrypt backup data. 
•	Test backup restoration regularly. 
•	Store backups in separate locations. 
________________________________________

Container Security
•	Scan container images using Trivy before deployment. 
•	Avoid running containers as root. 
•	Store secrets securely. 
•	Continuously monitor container activity. 
________________________________________
Monitoring & Detection
•	Deploy a SIEM solution to centralize logs. 
•	Configure alerts for: 
o	Multiple failed logins. 
o	Unusual file modifications. 
o	Mass file encryption. 
o	Privilege escalation attempts. 
________________________________________
Security Awareness
•	Train employees to recognize phishing emails. 
•	Conduct regular security awareness sessions. 
•	Simulate phishing campaigns. 
•	Define clear incident reporting procedures. 
________________________________________
Conclusion
A successful ransomware response depends on rapid detection, immediate isolation, reliable backups, and tested recovery procedures. 
By implementing layered security controls—including strong IAM, network segmentation, continuous monitoring, secure container practices, and a resilient backup strategy based on the 3-2-1 rule—organizations using Ghaymah Cloud can significantly reduce the impact of ransomware attacks and recover services efficiently.
