Time Since Ransom
00:00:00
A reconstruction · Singapore · 2021
06 Aug · 19:42
The Morning

The doctor paid 4 Bitcoins. $39 would have been enough.

Tomorrow, that will be you.

A specialist clinic in Singapore. Fourteen years of practice. Eleven thousand patient records on a single locked screen. By the time he reached the office, it was already too late. The breach had happened. The damage was done.
What would you do in his situation?
Scroll to begin
— Rewind —
19:42
end of day
6 August 2021 · 07:52 AM · AYE Expressway
The doctor is on the phone with his receptionist. He is fifteen minutes from the clinic. She has just unlocked the front desk computer.
Doctor — the system. There's a message asking for money. I think we've been hacked.
The next four decisions are yours.
Decision 01 / 04 · In transit · AYE Expressway · 07:52 AM

Your receptionist is on the line. The screen at the front desk is locked. Black background, red text. The first patient is in 68 minutes. You're 15 minutes away.

What do you tell her to do?

Option A
Unplug the computer immediately. Cut the connection.
Option B
Don't touch anything. Take a photo of the screen. I'm coming in.
Option C
Pay the ransom while it's small. Stop it before it spreads.
Option D
Call the IT vendor first. Let them handle it.
The right answer was B

Unplugging destroys forensic evidence and won't reverse the encryption. Paying confirms you're a soft target — most who pay get hit again within 12 months. Calling the vendor first delays the regulatory clock that has already started.

The screen is the crime scene. You photograph it. Then you decide who to call, in what order.

Decision 02 / 04 · Reception · On-site · 08:09 AM

You're on-site. Sixteen patients are scheduled today. One is already in the waiting room. The screen is still showing the ransom note.

What do you tell the patients?

Option A
The truth. We've been hacked. Your data may be compromised.
Option B
Nothing. Reschedule them. "Technical issue with our systems."
Option C
Close the clinic. Send them home. Figure it out later.
Option D
Run the appointments on paper. Worry about systems after hours.
Ethics & the law

Ethically, healthcare depends on trust — delaying disclosure after a data breach can damage that trust more than the breach itself, and patients need timely information to protect themselves.

Legally, under Singapore's Personal Data Protection Act (PDPA), clinics must assess quickly, notify the Personal Data Protection Commission (PDPC) within 3 days if required, and inform affected patients as soon as practicable.

Decision 03 / 04 · Doctor's office · 09:14 AM

The IT vendor cannot diagnose the source of the breach. Your local backup is encrypted along with the live system. The cloud backup might be intact. Police have logged the report. You have 11,000 patient records on this system. Fourteen years of practice.

Who do you call next?

Option A
Another clinic owner. Ask for advice — someone who's been through it.
Option B
Your lawyer. Find out what you're actually required to disclose.
Option C
Your insurer. Check if any of this is covered.
Option D
The ransomware group. Try to negotiate the price down.
Your lawyer should be your first call

Every other call — the regulator, the insurer, the clinic owner two suburbs over — is a conversation you can only have properly after the one with your lawyer.

What you say in the next eight hours will appear in a document somewhere. Your lawyer's job is to make sure it's the right document, in the right order, said the right way.

Decision 04 / 04 · Doctor's office · Draft notification · 16:30 PM
Redacted
Redacted

Your lawyer's draft notification has arrived. Two pages. One section is titled: "Reasonable security measures in place at the time of the breach."

What you have: antivirus software, password-protected workstations, a one-person IT vendor at SGD 600/month.
What you don't have: a documented security policy. Staff training records. An incident response plan that pre-dates today.

What do you put in that section?

Option A
List what you have. Hope it sounds like enough.
Option B
Be honest. State what you didn't have. Take the regulatory hit.
Option C
Ask the lawyer to soften the language. "Industry-standard measures."
Option D
Delay submission. Document something retroactively.
D is the answer that makes everything worse

Documenting security measures retroactively is the single move that turns a breach notification into a fraud investigation. The moment a regulator finds timestamps that don't survive scrutiny, the conversation stops being about what was lost — and starts being about what you signed.

Negligence is recoverable. Falsified records are not.

12hrs
Since the breach was discovered
73,000
Patient records exposed
14yrs
Of clinical history compromised
— What was on that one screen —
— End of the morning —
How did you perform? Did you take the right steps?
He wasn't reckless. He was a doctor running a clinic. Cybersecurity wasn't his job — until it was. He never had time to learn how easily a small business gets compromised, or how cheaply. He thought himself as safe as you think you are now.
Your crisis hasn't happened yet.
Let's keep it that way.
The plan
Cybersecurity for smaller businesses.
Protection that makes sense for organisations that don't hire cyber nerds, don't want to fiddle with tools, and don't have money to waste.
Plans from $39 a month.