Ransomware Response Guide
Ransomware strikes fast and demands quick decisions. Having a response plan ready helps you minimize damage and recover faster.
Immediate Actions (First Hour)
1. Contain the Spread
- Disconnect affected systems from network
- Don’t power off (preserve evidence)
- Isolate network segments
- Disable shared drives
- Identify ransomware variant if possible
- Determine scope of encryption
- Check backup integrity
- Document what you know
- Incident response team
- Executive leadership
- Legal counsel
- Communications team
- Phishing email?
- Exploited vulnerability?
- Compromised credentials?
- Third-party access?
- Systems affected
- Data encrypted
- Backup status
- Data exfiltrated?
- Recent and complete
- Not encrypted by ransomware
- Tested and functional
- No More Ransom project
- Security vendor tools
- Law enforcement resources
- No guarantee of decryption
- Funds criminal operations
- May be illegal (sanctions)
- Makes you a future target
- Identify and fix root cause
- Improve detection capabilities
- Update backup strategies
- Document lessons learned
- Consider law enforcement report
2. Assess the Situation
3. Activate Response Team
Investigation Phase
Determine Entry Point
Assess Scope
Recovery Options
Restore from Backups
The preferred option if backups are:
Decryption Tools
Check for available decryptors:
Paying Ransom (Not Recommended)
Reasons to avoid:
Post-Incident
Contact our team for incident response.