Question 1 of 30
\"GlobalTech Industries,\" a manufacturing company, experiences a ransomware attack that encrypts critical production servers. The company\'s IT director, David Lee, immediately initiates the incident response plan. However, the plan lacks clear guidelines for communication with external stakeholders, such as customers and regulatory agencies. The company\'s legal counsel advises that they may be legally obligated to report the breach to certain authorities, depending on the nature of the compromised data.\n\nIn this scenario, which of the following steps should David Lee prioritize to ensure an effective and compliant incident response, considering the lack of communication protocols and potential legal obligations?
Immediately establish a communication protocol with external stakeholders, including customers, regulatory agencies, and law enforcement, and engage legal counsel to determine reporting obligations based on the type of data compromised and applicable laws.
Focus solely on restoring the encrypted servers from backups and defer communication with external stakeholders until the systems are fully operational and the extent of the data breach is determined.
Publicly disclose the ransomware attack to all stakeholders, including customers and the media, to maintain transparency and build trust, regardless of the potential legal implications.
Instruct the IT team to investigate the ransomware attack and identify the source of the breach, while postponing communication with legal counsel and external stakeholders until the investigation is complete.

Preparing for ISO 39001:2012 Lead Implementer? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free