Get in touch
Emergency

I am under attack: what to do now and how we help

If you are facing ransomware, a compromised account or another attack right now, the first minutes count. Follow the steps below and get in touch with us.

The first reaction determines how big the damage becomes. You do not need to know exactly what is happening to start with the right steps.

Below are the basic steps. If you need help, send us a request with the topic "Security incident", write to info@ithaca-tech.gr or call +30 694 877 9999. To help you quickly, tell us what you see and what you have already done.

What is included
  • Assessment of the situation and priorities
  • Containment: isolating devices, changing passwords, closing access
  • Investigation: what happened, from where and what was affected
  • Recovery from backup and restoring operations
  • Advice on communicating with customers, the insurer and the authorities
  • Support in notifying the competent authority, if you fall under NIS2
  • A report and measures so it does not happen again

What to do in the first minutes

Isolate

Disconnect from the network and Wi-Fi the devices that appear affected. Do not wipe them and do not reinstall anything yet.

Do not pay and do not reply

Do not pay a ransom and do not reply to the attackers before talking to someone who knows. Authorities generally advise against paying and there is no guarantee you will get your data back.

Change passwords from a clean device

If you suspect an account has been compromised, change the passwords and enable MFA from a device that is not affected. Tell your Microsoft 365 administrator.

Keep evidence

Note times, the messages you see and what you did. Photograph screens. Do not delete logs or emails.

Talk to us

Send a request with the topic "Security incident" and describe what you see. If you fall under NIS2, remember the Directive provides for an early warning within 24 hours and a notification within 72 hours from the moment you become aware of the incident.

Frequently asked questions

Should I pay the ransom?

The decision is not only technical. Authorities generally advise against paying, and it does not guarantee you will get your data back. Discuss your options first with someone who knows, and with your lawyer and insurer.

Will my backup save me?

If the backups are intact and tested, restoring is usually the fastest route. We check them first, because attackers often try to destroy them.

Whom do I have to notify?

It depends: the competent authority, if you fall under NIS2; the Data Protection Authority, if personal data was breached (in many cases within 72 hours, under the GDPR); your insurer; and, if needed, the cybercrime authority. For a legal opinion consult a lawyer.

Can you help after the incident too?

Yes: a report, measures so it does not happen again, stronger security and, if needed, NIS2 compliance.