Inform the management and legal teams about the data breach: Incident response best practices and legal/regulatory requirements (like GDPR) mandate that management and legal teams are informed promptly following a data breach. This allows the organization to initiate appropriate communication plans, understand legal obligations, and coordinate the overall response. Modify the firewall rules to block the IP addresses and update the ports: This is a critical containment step in the incident response process. Blocking the malicious IP addresses and closing the exploited ports helps to prevent further unauthorized access and stop the spread of the ransomware or data exfiltration, thus limiting the impact of the incident.