1.1 KiB
1.1 KiB
Ransomware Incident Response & Recovery Plan
1. First 60-Minute Emergency Action Plan
- Min 00-15 (Containment): Immediately isolate compromised Ghaymah Block Storage volumes via Network Policies. Revoke all API keys and IAM tokens associated with the affected storage node.
- Min 15-30 (Triage & Assessment): Identify encryption entry point, identify affected snapshot IDs, and confirm immutable backup status.
- Min 30-60 (Eradication): Terminate infected container instances and flush compromised cache/session stores.
2. Ghaymah Backup & Recovery Strategy
- 3-2-1 Backup Rule: Maintain 3 copies of data across 2 different storage media types, with 1 immutable offsite copy on Ghaymah Block Storage WORM policies.
- RPO (Recovery Point Objective): < 15 minutes via automated snapshotting.
- RTO (Recovery Time Objective): < 60 minutes for clean environment restoration.
3. Comprehensive Prevention Plan
- Enforce Zero-Trust architecture and Least Privilege IAM policies across storage access points.
- Enable file integrity monitoring (FIM) and automated write-rate anomaly detection on Ghaymah Block Storage.