Your preparation
0 of 0 safeguards readyMake the next decision with evidence
Stop encryption and lateral movement, preserve evidence, protect clean backups, and rebuild business services without reintroducing the attacker.
Capture before evidence disappears
- Record the first affected host, ransom note, file extensions, processes, accounts, network connections, scheduled tasks, and security alerts.
- Preserve volatile memory and forensic images where practical, plus identity, endpoint, VPN, email, cloud, firewall, storage, and backup logs.
- Inventory encrypted, deleted, exfiltrated, and unaffected systems by business service, owner, recovery priority, and backup state.
- Protect ransom messages, wallet details, contact channels, samples, and attacker claims without opening files on production devices.
Decisions that change the response
| Question | Act when | Action |
|---|---|---|
| Disconnect systems? | Encryption, destructive commands, command-and-control, or lateral movement is active. | Isolate affected network segments and identities; avoid powering off systems needed for volatile evidence unless damage continues. |
| Restore or investigate first? | Critical services are down but the entry path and persistence are unknown. | Run investigation and clean recovery in parallel. Never attach clean backups to a hostile environment. |
| Engage the attacker? | Leadership, counsel, insurer, sanctions review, and law enforcement have assessed the decision. | Use experienced responders. Do not improvise payment or communication from affected systems. |
Proof that recovery worked
- Known persistence, hostile accounts, command paths, and entry vectors are removed or blocked.
- Restored services come from verified images and backups in a segmented clean environment.
- Identity, endpoint, network, backup, and data-access monitoring show no continuing hostile behavior.
- Business owners validate data completeness and function before systems leave heightened monitoring.
Controls to put in place
- Keep immutable, offline or isolated backups with separate administration and tested restore objectives.
- Require phishing-resistant MFA, remove standing admin rights, segment networks, and harden remote access.
- Deploy managed endpoint detection and central logs that compromised administrators cannot erase.
- Maintain a clean-room rebuild plan, service priorities, insurer route, legal contacts, and out-of-band communications.
Assume identity, endpoints, and primary backups are unavailable. The team must isolate a test segment, invoke outside contacts, choose restore priorities, rebuild one service in a clean environment, and verify data.
Contact specialist responders, insurer, counsel, cloud and security providers, and appropriate law enforcement immediately. Treat claimed or possible data theft as a separate breach investigation.
What this means
Ransomware may include both encryption and data theft. Treat nearby identities, backups, cloud accounts, and connected devices as potentially compromised.
Warning signs
- Files become unreadable, renamed, or replaced with ransom notes.
- Security tools, backups, or logs are disabled.
- Unusual encryption, archiving, or outbound data transfer appears.
- An attacker claims to possess customer or company data.
Recover now
First 15 minutes
- Isolate affected devices and workloads from networks without powering them off unnecessarily.
- Protect backups and identity systems from the same attacker.
- Preserve ransom notes, logs, alerts, timestamps, and system images.
- Activate qualified security, legal, insurance, and law-enforcement contacts.
Today
- Determine affected systems, accounts, data, and likely initial access.
- Rebuild from known-good images and scan backups before restoration.
- Rotate credentials from clean devices after the access path is contained.
- Assess data theft and notification duties before making public claims.
Verify recovery
- Restored systems come from a trusted point before compromise.
- The initial access path and persistence are removed.
- Old credentials fail and clean monitoring shows no recurrence.
- Required customer or authority notifications are tracked.
Prepare now
Access
- Privileged access uses phishing-resistant MFA and separate admin accounts.
Backups and evidence
- Critical data has encrypted, offline or immutable backups.
- Restoration is tested and backup administration is isolated from production.
Contacts and ownership
- Security, legal, insurer, hosting, and law-enforcement routes are documented.
Practice
- A clean-environment restoration drill has been completed.
Common mistakes
- Restoring before removing the attacker. Clean systems can be reinfected.
- Assuming encryption means no data was stolen.
- Paying without qualified advice. Payment does not guarantee recovery or deletion.