What to Do After a Cyber Incident
If an account, computer, phone, payment, or connected farm system may be compromised, act calmly and quickly. Your priorities are to protect people, livestock, crops, and essential operations; limit the spread; document what happened; and get qualified help.
Protect safety and essential operations
- Check for risks to people, livestock, crops, food safety, water, ventilation, feeding, irrigation, refrigeration, access controls, and other time-sensitive systems.
- Follow established emergency and equipment procedures.
- Use a safe manual process or backup system when available.
- Do not let pressure to solve the computer problem override physical safety.
Limit the spread
- Stop using a device or account that appears compromised.
- If it can be done safely, disconnect an affected computer or device from Wi-Fi, a network cable, or other farm systems.
- Do not connect backup drives to a device that may be infected.
- Do not delete messages, wipe devices, reinstall software, or destroy records before speaking with qualified incident-response or law-enforcement personnel. Those actions may remove useful evidence.
- Do not make changes to operational equipment unless you understand the safety and production consequences.
Call the right people
Contact, as appropriate:
- The person responsible for farm decisions
- Your information technology provider or qualified incident-response professional
- The equipment or software vendor
- Your bank or payment provider if money or financial information may be involved
- Your cyber insurance carrier before incurring major response costs or negotiating with an attacker
- Law enforcement or federal cyber-incident reporting services
- Employees, customers, suppliers, or other partners who need accurate operational instructions
Do not negotiate a ransom or make a payment on your own. Contact law enforcement, your insurer, and qualified response help first. Payment does not guarantee that data or systems will be restored.
Record what happened
Write down:
- When the problem was first noticed
- What appeared on the screen or in the message
- Which devices, accounts, locations, or systems may be involved
- What was working and what stopped
- Any names, email addresses, phone numbers, payment instructions, wallet addresses, or web addresses used by the suspected attacker
- Actions already taken
- People and organizations contacted
Take photographs or screenshots when it is safe to do so. Keep original messages and records.
Report the incident
Cyber-enabled crime or fraud
The FBI's Internet Crime Complaint Center is the central federal hub for reporting cyber-enabled crime. File a report even if you are unsure whether the complaint qualifies. Report to the FBI's IC3
Cyber incident or request for technical assistance
The Cybersecurity and Infrastructure Security Agency accepts reports of cyber incidents and can coordinate assistance. Report an incident to CISA
Reporting a cyber incident may not satisfy every legal, contractual, insurance, or regulatory notice requirement. Ask your insurer and appropriate professional advisers what applies to your operation.
Recover carefully
Work with qualified help to:
- Understand which accounts, devices, and systems were affected
- Remove unauthorized access
- Reset passwords from a known-clean device
- Turn on MFA
- Install needed patches and updates
- Restore data from a known-clean backup
- Test systems before returning them to production
- Watch financial accounts, email, and system activity for further misuse
- Record what changed and update the farm's incident plan
Do not reconnect a system just because it turns on. Confirm that the source of the problem has been addressed.
After the immediate problem
Review the incident without blame. Cybercriminals deliberately use pressure, trust, fear, and convincing messages. Focus on what will reduce the chance or impact of another incident:
- Improve payment-verification procedures
- Remove unused accounts
- Replace shared logins
- Expand MFA
- Separate networks
- Improve backups
- Update vendor contacts
- Practice the incident plan