1
Senaryo: Ransomware saldırısı tespit edildi, production sistemler şifrelendi. Incident response?
Immediate: 1) Isolate affected systems (network segmentation), 2) Incident declaration (war room), 3) Communication (stakeholders, legal, PR). Containment: Shutdown sharing, disable accounts. Eradication: Malware removal, vulnerability patching. Recovery: Clean backups restoration (verify integrity), business continuity testing. Post-incident: Ransom payment decision (last resort), lessons learned.