Treat this as critical
Immediate actions
- Disconnect affected devices from the network if safe to do so.
- Do not wipe or rebuild the system.
- Do not delete ransom notes or encrypted files.
- Create a critical ticket immediately.
- Wait for OpenTech guidance before attempting recovery actions.
Why this matters
Recovery may depend on preserving evidence, confirming scope, validating clean restore points, and preventing spread before restoring data.