Threat-Specific
Ransomware Response Playbook
Complete guide for responding to ransomware incidents including containment, negotiation considerations, and recovery strategies.
Threat-Specific · advanced · Multiple days
Comprehensive response procedures for ransomware attacks, from detection to recovery.
Steps
6
01
Immediate Containment
Stop the ransomware from spreading while preserving evidence.
- Isolate affected systems at the network level immediately
- Do NOT power off systems - preserve memory for forensics
- Disable shared drives and network shares
- Block known ransomware C2 domains and IPs at firewall
- Preserve at least one encrypted system for analysis
02
Scope Assessment
Determine the full extent of the attack.
- Identify all affected systems and data
- Determine the ransomware variant
- Assess backup integrity and availability
- Identify patient zero and initial access vector
- Check for data exfiltration indicators
03
Executive Notification
Brief leadership on the situation.
- Notify CISO and C-suite immediately
- Engage legal counsel and cyber insurance
- Prepare initial impact assessment
- Establish executive communication cadence
04
Recovery Planning
Develop and execute recovery strategy.
- Assess backup viability and recovery time
- Prioritize systems for recovery by business impact
- Check for decryptors (nomoreransom.org)
- Prepare clean systems for restoration
- Plan parallel recovery tracks
05
Ransom Decision
Evaluate ransom payment considerations.
- Consult with legal, insurance, and executive team
- Understand regulatory implications of payment
- Assess likelihood of recovery without payment
- Evaluate double extortion risk
- Document decision-making process
06
Recovery Execution
Execute the recovery plan.
- Rebuild affected systems from clean images
- Restore data from verified clean backups
- Implement additional security controls
- Monitor closely for re-infection
- Gradually restore business operations
Checklist
- All affected systems identified and isolated
- Ransomware variant identified
- Backup status verified
- Executive team briefed
- Legal and insurance engaged
- Law enforcement notified (if required)
- Recovery plan developed
- Ransom decision documented
- Systems rebuilt and restored
- Post-incident review completed
Evidence
- Ransom note
- Encrypted file samples
- System memory dumps
- Network logs showing lateral movement
- Initial access indicators
- Communication with threat actor (if any)
Communication
- Executive briefing template
- Employee notification
- Customer notification (if required)
- Regulatory notification (if required)