Serving North Texas since 2017 817 · 366 · 5829 Contact
Guide · North Texas IT

Ransomware Response Playbook

The worst time to work out your ransomware response is in the middle of one. This playbook covers what to do before, during, and after, calmly and in order.

Ransomware is one of the most disruptive things a business can go through: systems locked, operations at a standstill, and pressure to pay. The outcome depends far less on the malware itself than on what you did before it arrived and how you handle the first few hours. This playbook runs in three phases, before, during, and after, so you can prepare now and act clearly later. Take it as general guidance and build your own plan with your provider, plus legal and insurance counsel where it matters.

Before: preparation that decides the outcome

Everything that makes a ransomware incident survivable is built in advance. The single most important factor is recoverable backups.

  • Off-site, immutable, tested backups. Follow 3-2-1, keep at least one copy attackers can’t reach or alter, and prove you can restore by actually doing it.
  • Multifactor authentication and patching. Most ransomware walks in through stolen credentials or unpatched systems, so close both doors.
  • Network segmentation. Limit how far an infection can spread by separating critical systems.
  • 24/7 monitoring and detection. Early detection can stop encryption before it spreads.
  • A written incident response plan. Names, phone numbers, decision rights, and order of operations, on paper and reachable even when systems are down.
  • Know your insurance and legal contacts. Many policies require you to notify the carrier early and may direct the response.
If one line from this guide sticks, make it this: clean, off-site, immutable backups you have test-restored are what let you recover without paying. They are the difference between a bad week and a crisis that threatens the business.

During: the first hours

  1. Isolate, don’t power off. Pull affected systems off the network to stop the spread, but avoid shutting them down, since that can wipe forensic evidence. Follow your provider’s guidance.
  2. Activate your response plan. Call your IT/security provider and the people named in your plan. Don’t improvise the chain of command in the moment.
  3. Notify insurance early. Your cyber-insurance carrier often has incident-response resources and may require early notification for coverage.
  4. Don’t rush to pay. Paying doesn’t guarantee recovery, can carry legal and regulatory implications, and may not even be necessary if backups are intact. Make that decision with advisors, not under panic.
  5. Preserve evidence and communicate carefully. Write down what you see, and keep a tight hand on internal and external messaging, on the assumption that attackers may be reading email.
  6. Assess scope before restoring. Understand what’s affected and how the attacker got in before you bring systems back, or you may restore straight into the same compromise.

After: recovery and hardening

  • Restore from clean backups into a verified-clean environment, in priority order for the business.
  • Confirm the attacker is out. Rebuild or reimage where needed and rotate every credential, because restoring before you evict them just invites a second round.
  • Meet your notification obligations. Depending on data involved and your industry (HIPAA, PCI, state law), you may be required to notify affected parties and regulators.
  • Run a post-incident review. How did they get in, what worked, what didn’t, and which controls would have changed the outcome.
  • Close the root cause. Fix the entry point and the gaps the incident exposed, or you’ll see it again.

The honest takeaway

No business is immune, and no single product makes you ransomware-proof. What actually works is layered preparation, tested backups, MFA, patching, segmentation, and monitoring, plus a rehearsed plan and a calm, ordered response. In almost every case, preparing ahead costs a fraction of recovering after the fact.

Frequently asked questions

Should we pay the ransom?
Paying is a decision to make with legal, insurance, and security advisors, never in a panic. It does not guarantee you get your data back, can carry legal and regulatory implications, and may be unnecessary if your backups are intact. Strong, tested backups take away most of the attacker's hold over you.
What's the single most important thing to prepare in advance?
Clean, off-site, immutable backups that you have tested by restoring. If you can rebuild your business from backups the attacker couldn't reach or alter, you can usually recover without paying, which changes the entire dynamic of an incident.
Should we shut down infected computers immediately?
Isolate them from the network to stop the spread, but avoid simply powering them off. A hard shutdown can destroy the forensic evidence you need to understand how the attack happened. Follow your incident response plan and your provider's guidance on containment.
Do we have to tell anyone if we're hit?
Often yes. Depending on the data involved and your industry, frameworks like HIPAA and PCI DSS, plus state breach-notification laws, may require you to notify affected individuals and regulators. Your cyber-insurance carrier typically needs early notification too.
How do we know the attackers are really gone before we restore?
You assess the scope and entry point first, then restore into a verified-clean environment, rebuilding or reimaging affected systems and rotating credentials. Restoring without first evicting the attacker risks bringing the compromise right back.

Related

Build your plan before you need it

Book a free 30-minute conversation. We'll review your backups, detection, and response readiness so a bad day stays a bad day and doesn't become a catastrophe.