PlaybooksRansomware or destructive malware
Datacritical60 minutes to prepare

Ransomware or destructive malware

Systems or data are encrypted, stolen, deleted, or held for payment by a malicious actor.

01DetectConfirm the signal
02ContainStop more damage
03RecoverRestore control
04VerifyProve it works

Your preparation

0 of 0 safeguards ready
0%
Incident worksheet

Make the next decision with evidence

Stop encryption and lateral movement, preserve evidence, protect clean backups, and rebuild business services without reintroducing the attacker.

EvidenceDecisionActionProof

Capture before evidence disappears

  • Record the first affected host, ransom note, file extensions, processes, accounts, network connections, scheduled tasks, and security alerts.
  • Preserve volatile memory and forensic images where practical, plus identity, endpoint, VPN, email, cloud, firewall, storage, and backup logs.
  • Inventory encrypted, deleted, exfiltrated, and unaffected systems by business service, owner, recovery priority, and backup state.
  • Protect ransom messages, wallet details, contact channels, samples, and attacker claims without opening files on production devices.

Decisions that change the response

QuestionAct whenAction
Disconnect systems?Encryption, destructive commands, command-and-control, or lateral movement is active.Isolate affected network segments and identities; avoid powering off systems needed for volatile evidence unless damage continues.
Restore or investigate first?Critical services are down but the entry path and persistence are unknown.Run investigation and clean recovery in parallel. Never attach clean backups to a hostile environment.
Engage the attacker?Leadership, counsel, insurer, sanctions review, and law enforcement have assessed the decision.Use experienced responders. Do not improvise payment or communication from affected systems.

Proof that recovery worked

  • Known persistence, hostile accounts, command paths, and entry vectors are removed or blocked.
  • Restored services come from verified images and backups in a segmented clean environment.
  • Identity, endpoint, network, backup, and data-access monitoring show no continuing hostile behavior.
  • Business owners validate data completeness and function before systems leave heightened monitoring.

Controls to put in place

  • Keep immutable, offline or isolated backups with separate administration and tested restore objectives.
  • Require phishing-resistant MFA, remove standing admin rights, segment networks, and harden remote access.
  • Deploy managed endpoint detection and central logs that compromised administrators cannot erase.
  • Maintain a clean-room rebuild plan, service priorities, insurer route, legal contacts, and out-of-band communications.
Tabletop drill

Assume identity, endpoints, and primary backups are unavailable. The team must isolate a test segment, invoke outside contacts, choose restore priorities, rebuild one service in a clean environment, and verify data.

Escalate when

Contact specialist responders, insurer, counsel, cloud and security providers, and appropriate law enforcement immediately. Treat claimed or possible data theft as a separate breach investigation.

What this means

Ransomware may include both encryption and data theft. Treat nearby identities, backups, cloud accounts, and connected devices as potentially compromised.

Warning signs

  • Files become unreadable, renamed, or replaced with ransom notes.
  • Security tools, backups, or logs are disabled.
  • Unusual encryption, archiving, or outbound data transfer appears.
  • An attacker claims to possess customer or company data.

Recover now

First 15 minutes

  1. Isolate affected devices and workloads from networks without powering them off unnecessarily.
  2. Protect backups and identity systems from the same attacker.
  3. Preserve ransom notes, logs, alerts, timestamps, and system images.
  4. Activate qualified security, legal, insurance, and law-enforcement contacts.

Today

  1. Determine affected systems, accounts, data, and likely initial access.
  2. Rebuild from known-good images and scan backups before restoration.
  3. Rotate credentials from clean devices after the access path is contained.
  4. Assess data theft and notification duties before making public claims.

Verify recovery

  • Restored systems come from a trusted point before compromise.
  • The initial access path and persistence are removed.
  • Old credentials fail and clean monitoring shows no recurrence.
  • Required customer or authority notifications are tracked.

Prepare now

Access

  • Privileged access uses phishing-resistant MFA and separate admin accounts.

Backups and evidence

  • Critical data has encrypted, offline or immutable backups.
  • Restoration is tested and backup administration is isolated from production.

Contacts and ownership

  • Security, legal, insurer, hosting, and law-enforcement routes are documented.

Practice

  • A clean-environment restoration drill has been completed.

Common mistakes

  • Restoring before removing the attacker. Clean systems can be reinfected.
  • Assuming encryption means no data was stolen.
  • Paying without qualified advice. Payment does not guarantee recovery or deletion.

Sources

Last reviewed July 19, 2026Guidance changes. Confirm provider-specific actions in the linked official sources.