Ransomware has hit: what to do in the first 24 hours
The first hour determines how bad the next month is. What to do, in order.
Businesses that provide internet access in Türkiye must retain access records. The law that requires this, No. 5651, is an obligation most business owners are unaware of — until a request arrives.
Broadly: anyone providing internet access to people other than their own staff.
If you are a closed office network used only by employees the position differs — but keeping logs is still worth doing for your own security.
Not content — connection data. Not what someone wrote, but which user connected, when, and to what address.
Three things matter:
Two parts.
The part that produces the record: usually the firewall. FortiGate already generates it; the configuration just has to be correct.
The part that stores it: keeping logs in the appliance's own memory is not enough — that holds a few hours and clears on reboot. A separate collector is needed. On the Fortinet side that is normally FortiAnalyzer.
For the guest network a captive portal is also set up: the user is verified by mobile number, which makes the record attributable to a person.
First establish the simple question: do you give guests internet access? If yes, you are in scope.
The rest is configuration. If you already have a firewall, the right settings plus a collector are usually enough — a rebuild is rarely necessary.
If you are unsure, ask. We will assess whether you fall within scope and design the setup if you do.
Ask us about fortinet firewall installation, or request a free assessment directly.
The first hour determines how bad the next month is. What to do, in order.
Most businesses have backups. Far fewer have a backup that survives ransomware — and that is a different thing.
The data is usually still there. The real loss happens during recovery attempts.