The Recovery Orange Book

Global Agencies Contact

i. List of Law Enforcement Agencies, Governmental Bodies, Cybersecurity Organizations (to be notified)

1) United States of America

  1. Federal Bureau of Investigation (FBI): FBI is the primary federal agency for investigating and responding to cybercrime incidents, including ransomware attacks.
  2. US Department of Homeland Security (DHS) - Cybersecurity and Infrastructure Security Agency (CISA): Report CISA in the event of ransomware attack. It plays an important role in coordinating responses to cyber incidents like ransomware and provides technical assistance.
    • Actionable Steps:-Engage CISA for incident response support, including guidance on containment, remediation.
    • Contact Information:-
  3. Industry Specific Regulatory Authorities (eg, HIPAA, SEC, FTC): Depending on the industry, there are additional regulatory bodies that must be notified if the ransomware attack affects specific sectors like healthcare, finance, or consumer protection.
    • Health and Human Service (HHS) - HIPAA Breach Notification Notify HHS and file a breach notification within 60 days for a health related breach.
    • Securities and Exchange Commission (SEC) Notify SEC if ransomware attack impacts public companies.
    • Federal Trade Commission (FTC) Notify FTC if ransomware attack involves consumer data.

2) Europe

  1. European Union Agency for Cybersecurity (ENISA) ENISA is tasked with supporting incident response teams across the EU and coordinating threat intelligence.
  2. Europol (European Cybercrime Center): Report ransomware attack to Europool’s European Cybercrime Center (EC3) to assist with investigation and coordination across EU member states.
  3. National Data Protection Authorities (DPA): Report to the DPA if personal data is compromised during the ransomware attack, in compliance with GDPR.

3) United Kingdom (UK)

  1. National Crime Agency (NCA) The NCA is the UK’s lead agency for tackling serious and organized crime, including cybercrime and ransomware attacks. Contact Information:- NCA: https://www.nca.gov.uk National Cyber Crime Unit: https://www.nca.gov.uk/what-we-do/crime-threats/cyber-crime Email:- ncsc@nca.gov.uk
  2. Information Commissioner’s Office (ICO) Report ICO if the ransomware attack compromised personal data or violates data protection law. Contact Information:- ICO: https://ico.org.uk Email: casework@ico.org.uk Breach Reporting: https://ico.org.uk/for-organisations/report-a-breach/
  1. Australia
    1. Australia Cyber Security Center (ASCS) ASCS is the primary authority for cybersecurity incidents including ransomware attacks in Australia. Contact Information:- ASCS: https://www.cyber.gov.au
  1. Australian Federal Police (AFP) AFP is the national law enforcement agency responsible for a cyber investigation and crimes, including cyber crime, ransomware attacks. Contact Information:- AFP Cybercrime Operations: https://www.afp.gov.au/what-we-do/crime-types/cybercrime Email: cybercrime@afp.gov.au
  1. Canada
    1. Canadian Cyber Incident Response Center (CCIRC) CCIRC is the primary authority for cybersecurity incidents in Canada. Report the incident to CCIRC to receive immediate technical assistance and support in managing the ransomware attack. Contact Information:- CCIRC: https://www.cyber.gc.ca Email: ccric@cyber.gc.ca Incident Reporting: https://www.cyber.gc.ca/en/incident-management
    2. Royal Canadian Mounted Police (RCMP) RCMP is Canada’s national law enforcement agency, responsible for enforcing federal laws, including cybercrime and ransomware. Contact Information:- RCMP National Cybercrime Coordination Center (NC3): https://www.rcmp-grc.gc.ca Email:- cybercrime@rcmp-grc.gc.ca
  2. India
    1. Indian Computer Emergency Response Team (CERT-In) CERT-In serves as the primary government agency for handling cybersecurity incidents and providing technical assistance and coordination. Contact Information: CERT-IN contact page:- https://www.cert-in.org.in/ Helpline:- 1800-11-2424 Email:- incident@cert-in.org.ins
  1. International Cybersecurity Organizations
    1. CERT (Computer Emergency Response Teams) Worldwide
    2. INTERPOL Cybercrime Unit