Your receptionist has just unlocked the front desk computer. The screen is black with red text asking for money. The first patient is due in sixty-eight minutes. You are fifteen minutes away.
Pulling the plug decrypts nothing, and it destroys what an investigator would have worked from. A photograph costs you nothing and it is the only record of the demand, the deadline and the address you were told to reply to.
Paying is not recovery either. In the year of this attack, 80% of organisations that paid were hit again, and 68% of those inside a month. Handing it to the vendor first does not stop the clock that is already running.
You are on site. Sixteen patients are booked today and one is already in the waiting room. The ransom note is still on the screen behind the desk.
The law does not ask you to declare a breach on the morning you find it. It asks you to assess it quickly, and then not to delay. Under the PDPA that means the Commission within three calendar days of deciding the breach is notifiable, and the affected patients as soon as practicable after that.
Calling it a technical problem is the sentence you have to take back later. In this case the patients were told nineteen days after the attack.
The vendor cannot say how they got in. Your local backup sat on the same network and encrypted with everything else. The cloud copy might be intact. The police report is logged.
What you say in the next eight hours gets written down somewhere, and you do not choose where. The insurer's file, the regulator's file and a peer's recollection are all records. The lawyer is the only call whose job is to get the order and the wording right.
Reporting to the authorities is a separate obligation and it is not optional. In this case the clinic told the police, the Commission, SingCERT, the Cyber Security Agency and the Ministry of Health.
The draft notification runs to two pages. One section is headed "Reasonable security measures in place at the time of the breach." You have antivirus, passwords on the workstations and a vendor on retainer. You do not have a policy, training records, or a plan that pre-dates this morning.
Writing the policy today and dating it last year changes what is being investigated. The question stops being what you lost and becomes what you signed, and that question has a different range of answers.
Reasonable security is judged on what existed on the day. Nothing written afterwards changes that, and everything written afterwards carries the date it was written.
Answer these honestly. Nothing is sent anywhere and nothing is saved.