Get Help! Something Has Happened

What to Do After a Cyber Incident

If an account, computer, phone, payment, or connected farm system may be compromised, act calmly and quickly. Your priorities are to protect people, livestock, crops, and essential operations; limit the spread; document what happened; and get qualified help.

Protect safety and essential operations

  • Check for risks to people, livestock, crops, food safety, water, ventilation, feeding, irrigation, refrigeration, access controls, and other time-sensitive systems.
  • Follow established emergency and equipment procedures.
  • Use a safe manual process or backup system when available.
  • Do not let pressure to solve the computer problem override physical safety.

Limit the spread

  • Stop using a device or account that appears compromised.
  • If it can be done safely, disconnect an affected computer or device from Wi-Fi, a network cable, or other farm systems.
  • Do not connect backup drives to a device that may be infected.
  • Do not delete messages, wipe devices, reinstall software, or destroy records before speaking with qualified incident-response or law-enforcement personnel. Those actions may remove useful evidence.
  • Do not make changes to operational equipment unless you understand the safety and production consequences.

Call the right people

Contact, as appropriate:

  • The person responsible for farm decisions
  • Your information technology provider or qualified incident-response professional
  • The equipment or software vendor
  • Your bank or payment provider if money or financial information may be involved
  • Your cyber insurance carrier before incurring major response costs or negotiating with an attacker
  • Law enforcement or federal cyber-incident reporting services
  • Employees, customers, suppliers, or other partners who need accurate operational instructions

Do not negotiate a ransom or make a payment on your own. Contact law enforcement, your insurer, and qualified response help first. Payment does not guarantee that data or systems will be restored.

Record what happened

Write down:

  • When the problem was first noticed
  • What appeared on the screen or in the message
  • Which devices, accounts, locations, or systems may be involved
  • What was working and what stopped
  • Any names, email addresses, phone numbers, payment instructions, wallet addresses, or web addresses used by the suspected attacker
  • Actions already taken
  • People and organizations contacted

Take photographs or screenshots when it is safe to do so. Keep original messages and records.

Report the incident

Cyber-enabled crime or fraud

The FBI's Internet Crime Complaint Center is the central federal hub for reporting cyber-enabled crime. File a report even if you are unsure whether the complaint qualifies. Report to the FBI's IC3

Cyber incident or request for technical assistance

The Cybersecurity and Infrastructure Security Agency accepts reports of cyber incidents and can coordinate assistance. Report an incident to CISA

Reporting a cyber incident may not satisfy every legal, contractual, insurance, or regulatory notice requirement. Ask your insurer and appropriate professional advisers what applies to your operation.

Recover carefully

Work with qualified help to:

  • Understand which accounts, devices, and systems were affected
  • Remove unauthorized access
  • Reset passwords from a known-clean device
  • Turn on MFA
  • Install needed patches and updates
  • Restore data from a known-clean backup
  • Test systems before returning them to production
  • Watch financial accounts, email, and system activity for further misuse
  • Record what changed and update the farm's incident plan

Do not reconnect a system just because it turns on. Confirm that the source of the problem has been addressed.

After the immediate problem

Review the incident without blame. Cybercriminals deliberately use pressure, trust, fear, and convincing messages. Focus on what will reduce the chance or impact of another incident:

  • Improve payment-verification procedures
  • Remove unused accounts
  • Replace shared logins
  • Expand MFA
  • Separate networks
  • Improve backups
  • Update vendor contacts
  • Practice the incident plan

Extension note