Sign in

Cyber crisis: the first 48 hours

Complete plan

Four modules for leaders, IT, communication and legal teams facing ransomware or a major incident: the first hour (isolate without destroying evidence, open the crisis cell, switch to an out-of-band channel, name who decides and who keeps the log), who to call and when (insurer, police complaint, public help, the CNIL, a lawyer, the NIS2 authority), communicating during the crisis, and the ransom question.

  • 12 min
  • 4 modules
  • 12-question check
  • English · Français
  • Attestation

You will be able to

  • Isolate the affected machines from the network and the internet without switching them off, reinstalling them or wiping evidence (machines, ransom note, logs)
  • Tell the insurer as soon as the attack is known and report the claim within the policy deadline
  • Say only facts: don't play things down or guess the attacker or the scale, and say what you don't know yet
  • Know that paying guarantees neither decryption, nor deletion of stolen data, nor an end to attacks, and that the authorities advise not to pay

Programme

4 modules · 12 min
  1. The first hour of a cyber crisis 3 min
    • Isolate the affected machines from the network and the internet without switching them off, reinstalling them or wiping evidence (machines, ransom note, logs)
    • Open the crisis cell without waiting, with management, IT and security, communication, legal and the affected business teams
    • Move to a backup channel agreed in advance (mobile phones, printed crisis directory), assuming the attacker can read the email
    • Name one person who decides, with a deputy, and one person who keeps the crisis log, starting with the time the attack became known
  2. Cyber crisis: who to call, and when? 3 min
    • Tell the insurer as soon as the attack is known and report the claim within the policy deadline
    • File a police complaint no later than 72 hours after learning of the attack, a condition for insurance compensation in France (Insurance Code, art. L. 12-10-1)
    • Know where to turn: 17Cyber (Cybermalveillance) for companies and associations, CERT-FR for government bodies and regulated operators, the NIS2 authority for in-scope entities
    • Notify the CNIL within 72 hours where feasible for a breach that puts people at risk, completing it later, and prepare a call sheet with one name per call
  3. Crisis communication: one voice, only facts 2 min
    • Say only facts: don't play things down or guess the attacker or the scale, and say what you don't know yet
    • Inform in the right order: staff early, affected customers and partners without delay, the people concerned if a breach puts them at high risk, the press with the same facts
    • Speak with one voice, with a spokesperson and messages prepared before the crisis, and give teams a clear instruction: nothing on social media, questions go to the spokesperson
  4. Pay the ransom? 3 min
    • Know that paying guarantees neither decryption, nor deletion of stolen data, nor an end to attacks, and that the authorities advise not to pay
    • Know the legal risks (international sanctions, duties that remain) and the role of insurance, whose conditions you read before a crisis
    • Leave the decision to the leaders, with their advisers, and favour recovery: evict the attacker, restart from a clean base and checked backups
  5. Knowledge check

    12 questions, pass mark 80 %. Explanations after each answer; you can try again.

  6. Attestation

    One per person, with the date, the score and the frameworks covered — anyone can check it online with its code.

Version 1 · updated October 6, 2026