While investigating a security event, an analyst finds evidence that a user opened an email attachment from an unknown source. Shortly after the user opened the attachment, a group of servers experienced a large amount of network and resource activity. Upon investigating the servers, the analyst discovers the servers were encrypted by ransomware that is demanding payment within 48 hours or all data will be destroyed. The company has no response plans for ransomware.
Which of the following is the NEXT step the analyst should take after reporting the incident to the management team?
patinho777
Highly Voted 7 months agodangerelchulo
2 years, 9 months agoSallySausage
9 months, 3 weeks agoblacksheep6r
Most Recent 2 months, 2 weeks ago[Removed]
10 months, 2 weeks agoSangSang
11 months, 1 week agoAnarckii
1 year, 4 months agojoinedatthehop
1 year, 7 months agojoinedatthehop
1 year, 7 months agoBiteSize
1 year, 9 months agokycugu
2 years, 4 months agoAndre876
2 years, 5 months agotineboy46
2 years, 6 months agoBoats
2 years, 8 months agodangerelchulo
2 years, 8 months agodangerelchulo
2 years, 9 months agodangerelchulo
2 years, 7 months agoBig_Harambe
2 years, 10 months agoRevZig67
2 years, 11 months agodgfhyjfghfgfkfhd
3 years agozapato
3 years, 2 months agoBlackdaRipper
3 years, 2 months agoBlessedChild
3 years, 1 month ago