Ransomware Snapshot and Lockout Response
Scenario
A ransomware attack encrypts critical business data, making it inaccessible.
Implementation
Configure automated snapshot capabilities to take snapshots of your data upon detection. Implement automated user lockout mechanisms to block the user exhibiting suspicious behavior.
Outcome
Upon detection of ransomware activity, the application starts taking snapshots and locks out the affected user account, providing more time for the team to investigate what happened. The storage admin can then restore data from the most recent snapshot, minimizing data loss and reducing downtime.
See also
- Threat Response, Lockout and Snapshots — How lockout is triggered and what it does.
- Snapshot Settings — How snapshots are taken during a security event and how to manage the snapshot budget.