[email protected]
Information Security

After a Malware Attack: A Security Assessment to Protect Your Business

September 26, 20267 min read

When malware damages or destroys business data, the first instinct is to restore systems and get back to work. Restoring without understanding what happened risks reinfection, missed legal obligations, and the same attack succeeding again. A post-breach security assessment gives you the facts to protect the business.

First Priorities

  • Contain: isolate affected systems to stop the spread.
  • Preserve evidence: keep logs, affected devices, and records of what was observed. Evidence is needed for root cause, insurance, and possible law enforcement involvement.
  • Notify: inform leadership, your cyber insurer if you have one, and legal counsel.

What the Assessment Covers

  • Timeline: how the attacker got in, what they touched, and when.
  • Root cause: phishing, stolen credentials, an unpatched vulnerability, remote access, or a third party.
  • Impact: which data and systems were damaged, encrypted, or taken, and whether personal or customer data was involved.
  • Exposure: what weaknesses remain, such as backups, access rights, network segmentation, and monitoring.
  • Recovery readiness: whether backups are clean and restorable.

Reporting Obligations

Depending on your business, you may have legal or contractual reporting duties. Examples include state data breach notification laws when personal information is affected, the 72-hour cyber incident reporting requirement for defense contractors under DFARS 252.204-7012, and SEC disclosure rules for public companies. Victims can also report to the FBI's Internet Crime Complaint Center (IC3) and to CISA. Confirm your obligations with counsel.

Using ISO 27001 to Rebuild

ISO/IEC 27001 provides a structured way to turn assessment findings into lasting controls: a risk assessment, a risk treatment plan, and controls selected from Annex A such as malware protection, backups, access control, and incident management. It also gives customers and auditors a recognized framework for your response.

Compliance Fortress includes a qualified ISO 27001 lead auditor who can assess your situation and your controls against the standard.

Related reading: Ransomware and ISO 27001: Annex A Controls.

How Compliance Fortress Solves This: The Exceleor Path

  1. Discovery: understand the problem, measure where things stand today, and agree on what success looks like.
  2. Define the engagement path: most organizations don't know the path. We do. A proven method, tailored to your situation.
  3. Training: bring your people to a clear understanding of the requirements.
  4. Implement and engage: carry out the work jointly, with your people involved from day one.
  5. Verify: confirm the work was done and meets the requirement.
  6. Validate: confirm the original problem is actually solved, measured against the success measures from Discovery.
  7. Transfer ownership: we collaborate throughout, so your team can run it without us.
  8. Sustain and grow: we stay close, check in, and catch the next need early. We're here to make sure you succeed.

Is this your situation? See how we approach it on the Malware Sabotaged Our Data page, or request a Situation Review. You can also email [email protected].

Need an EHS Audit?

Veteran-led, certified lead auditors covering ISO 14001, ISO 45001, RC14001, CFATS and more. Get a tailored proposal within 24 hours.

Request Your Assessment

Free EHS Compliance Checklist

Download our 50-point EHS Audit Readiness Checklist — the same framework our auditors use.

Download Free Checklist

Fortify Your Compliance Today

Don't wait for an audit finding to reveal your gaps. Partner with the Southeast's most comprehensive EHS and security audit team.