The AP has investigated ransomware incidents involving personal data and has spoken to organisations that had experienced such incidents. Their experiences show that proper preparation, rapid decision-making and clear communication can make a significant difference for both the organisation and the individuals whose personal data have been affected. The report is therefore not only an analysis of ransomware incidents, but above all a practical guide for organisations wishing to enhance their digital resilience.
Preparation makes all the difference
Practical experience shows that organisations that plan their incident response approach in advance can act faster and better if a ransomware attack actually occurs.
The key lessons from the report are:
- ensure that suspicious activities are detected quickly;
- work with a up-to-date incident and crisis response plan;
- engage the right experts on time;
- know which personal data your organisation processes and where they are located;
- inform victims (data subjects) in a timely and clear manner when their personal data are at risk;
- continue to invest in digital resilience and security.
Impact on victims is often underestimated
Ransomware not only affects organisations, but also the people whose personal data they process. The AP has observed that organisations often underestimate the consequences for victims. When personal data have been accessed or stolen, people can become victims of, for example, identity fraud, phishing or other forms of misuse. That is precisely why it is important that organisations quickly gain insight into the scale of an incident. Furthermore, organisations must inform victims in a timely manner about the potential risks and the measures they can take to protect themselves.
Not all organisations need to make the same mistakes
With the ransomware report, the AP aims to prevent organisations from having to learn the same lessons the hard way, over and over again. That is why the ransomware report combines practical experiences with the key lessons for organisations.
Monique Verdier, deputy chair of the AP: “Every ransomware attack is different, but the lessons are often the same. Organisations do not need to make every mistake themselves. By learning from one another, they can significantly limit the damage to people and to their own organisation.”
Digital resilience is a shared responsibility
With this report, the AP aims to support organisations in boosting their digital resilience. By sharing practical experiences and concrete lessons from ransomware incidents, the AP aims to help prevent data breaches. The report also helps organisations to better prepare for cyber incidents. In doing so, organisations not only safeguard the continuity of their services, but also contribute to a better protection of the personal data of citizens.
Further information, practical examples and recommendations can be found in the AP’s ransomware report 2025.
Click Here For The Original Source.
