Ransomware Response Playbook
The worst time to work out your ransomware response is in the middle of one. This playbook covers what to do before, during, and after, calmly and in order.
Ransomware is one of the most disruptive things a business can go through: systems locked, operations at a standstill, and pressure to pay. The outcome depends far less on the malware itself than on what you did before it arrived and how you handle the first few hours. This playbook runs in three phases, before, during, and after, so you can prepare now and act clearly later. Take it as general guidance and build your own plan with your provider, plus legal and insurance counsel where it matters.
Before: preparation that decides the outcome
Everything that makes a ransomware incident survivable is built in advance. The single most important factor is recoverable backups.
- Off-site, immutable, tested backups. Follow 3-2-1, keep at least one copy attackers can’t reach or alter, and prove you can restore by actually doing it.
- Multifactor authentication and patching. Most ransomware walks in through stolen credentials or unpatched systems, so close both doors.
- Network segmentation. Limit how far an infection can spread by separating critical systems.
- 24/7 monitoring and detection. Early detection can stop encryption before it spreads.
- A written incident response plan. Names, phone numbers, decision rights, and order of operations, on paper and reachable even when systems are down.
- Know your insurance and legal contacts. Many policies require you to notify the carrier early and may direct the response.
During: the first hours
- Isolate, don’t power off. Pull affected systems off the network to stop the spread, but avoid shutting them down, since that can wipe forensic evidence. Follow your provider’s guidance.
- Activate your response plan. Call your IT/security provider and the people named in your plan. Don’t improvise the chain of command in the moment.
- Notify insurance early. Your cyber-insurance carrier often has incident-response resources and may require early notification for coverage.
- Don’t rush to pay. Paying doesn’t guarantee recovery, can carry legal and regulatory implications, and may not even be necessary if backups are intact. Make that decision with advisors, not under panic.
- Preserve evidence and communicate carefully. Write down what you see, and keep a tight hand on internal and external messaging, on the assumption that attackers may be reading email.
- Assess scope before restoring. Understand what’s affected and how the attacker got in before you bring systems back, or you may restore straight into the same compromise.
After: recovery and hardening
- Restore from clean backups into a verified-clean environment, in priority order for the business.
- Confirm the attacker is out. Rebuild or reimage where needed and rotate every credential, because restoring before you evict them just invites a second round.
- Meet your notification obligations. Depending on data involved and your industry (HIPAA, PCI, state law), you may be required to notify affected parties and regulators.
- Run a post-incident review. How did they get in, what worked, what didn’t, and which controls would have changed the outcome.
- Close the root cause. Fix the entry point and the gaps the incident exposed, or you’ll see it again.
The honest takeaway
No business is immune, and no single product makes you ransomware-proof. What actually works is layered preparation, tested backups, MFA, patching, segmentation, and monitoring, plus a rehearsed plan and a calm, ordered response. In almost every case, preparing ahead costs a fraction of recovering after the fact.
Frequently asked questions
Should we pay the ransom?
What's the single most important thing to prepare in advance?
Should we shut down infected computers immediately?
Do we have to tell anyone if we're hit?
How do we know the attackers are really gone before we restore?
Related
Build your plan before you need it
Book a free 30-minute conversation. We'll review your backups, detection, and response readiness so a bad day stays a bad day and doesn't become a catastrophe.