Cybersecurity · Cybersecurity · Hard · 35-45 min

Fintech Hit by Ransomware

Fintech Hit by Ransomware is a hard Cybersecurity cybersecurity case interview that runs 35-45 min. A fintech with 2M customers has been hit by ransomware. A strong answer works through 5 phases: Triage now; Work the pay-vs-don't-pay decision; Manage stakeholders; Restore safely; Build the longer-term roadmap.

Last updated 2026-09-05

The brief

A fintech with 2M customers has been hit by ransomware. Core systems are encrypted, the attacker demands $5M in crypto, and customer-facing services are down. The CEO wants an immediate response plan and, once stable, a longer-term security roadmap so this never happens again. Regulators and customers will need to be informed.

How to approach it

  1. Triage now — contain/isolate, assess scope, stand up incident command, preserve evidence
  2. Work the pay-vs-don't-pay decision — backup viability, legal/regulatory constraints, no guarantee of decryption
  3. Manage stakeholders — regulator notification timelines, customer communication, law enforcement
  4. Restore safely — clean recovery from backups, verify no persistence, staged service restoration
  5. Build the longer-term roadmap — backups/segmentation, MFA, EDR, patching, incident readiness

What a strong answer does

  • Leads with containment and incident command before debating the ransom
  • Treats paying as a last resort tied to backup viability, with no guarantee and legal exposure
  • Knows breach notification to regulators and customers is time-bound, not optional
  • Ensures recovery is from clean backups with persistence removed, not just decrypting
  • Separates the immediate response from the structural roadmap that prevents recurrence

Red flags interviewers score down

  • Jumps to paying the ransom as the primary plan
  • Ignores regulatory notification obligations and customer duty of care
  • Restores from potentially compromised systems without verifying clean state
  • Conflates the crisis response with the long-term roadmap and does neither well

Cases are written in each firm's style, written and reviewed by working consultants; they are not the firms' own published cases.

More Cybersecurity cases