If this is happening right now, start here: isolate affected systems from the network but leave them powered on. Protect your backups immediately — attackers target them first. Call your cyber insurer before you engage any vendor, because most policies require their consent. Then work down this page.
If you're reading this in advance, good. Most of what determines the outcome is decided before the incident.
The first hour
Start a timestamped log. Every action, every decision, who made it, when. You will need this for the insurer, for regulators, and for the post-mortem. Start it now, not later.
Get the core team onto an out-of-band channel. Assume email and chat are compromised. A phone tree and a messaging app on personal devices is fine. Do this before you discuss anything sensitive on the network you think is breached.
Isolate, don't power off. Network containment through your endpoint tool preserves memory, which preserves evidence. Pulling the plug destroys it.
Protect the backups. Disconnect them, verify they exist, verify they're intact. Modern ransomware crews deliberately attack recovery capability — backup infrastructure, identity systems, virtualization management — before encrypting anything. Assume they tried.
Disable suspected-compromised privileged accounts and revoke their sessions and tokens. A password reset alone doesn't log an attacker out.
Identify the variant from the ransom note and file extensions. It informs whether a free decryptor exists.
Activate your incident response retainer, your insurer, and legal counsel. In that call, ask counsel to direct the investigation — it's how privilege is preserved, and doing it afterwards usually doesn't work.
Assume the data is already gone
Double extortion has been standard since 2019. Data is stolen before encryption, so "we restored from backup" doesn't end the incident — it just ends the outage.
Treat data theft as confirmed until forensics says otherwise, and start the notification analysis in parallel rather than after recovery. This matters for the clock: GDPR gives you 72 hours to notify a supervisory authority, several US states now require notification within 30 days, HIPAA gives 60, and public companies have four business days after determining an incident is material.
Notification is a parallel workstream from hour one, run by counsel. Not a post-recovery afterthought.
Who to call, in order
- Your cyber insurer's hotline. First, because engaging vendors without consent can void coverage. Most policies also designate a breach coach — a privacy attorney who coordinates the response.
- Legal counsel, to establish privilege over the investigation.
- Your incident response firm, ideally one already on retainer and on your insurer's panel.
- Law enforcement. In the US, the FBI via IC3 or your local field office, and CISA. Elsewhere, your national CERT. This is genuinely useful — and it's a mitigating factor if a payment decision ever arises.
- Executives and the board, with a factual briefing and no speculation about scope.
The payment decision
This never gets made quickly, and never alone. It runs through counsel, your insurer, and a sanctions screen conducted by an experienced negotiation firm.
The US government position is that payment is discouraged: it doesn't guarantee recovery and it funds further crime. The data supports the scepticism — most payers recover some data, only a small minority recover all of it, and a substantial share are attacked again within a year. Verizon's 2026 DBIR found around 69% of victims in its dataset didn't pay; Chainalysis and Coveware, measuring different populations, put the non-payment share higher still, above 70%.
The legal risk is the decisive part. Paying an entity under sanctions can violate US law on a strict-liability basis — meaning it doesn't matter whether you knew who you were paying. Mitigating factors that regulators weigh include strong pre-incident security, prompt reporting to law enforcement, and full cooperation.
Also check No More Ransom before assuming payment is the only path. A meaningful share of newer strains are poorly built and have free decryptors, and law enforcement has released keys for several major families.
Eradication and recovery
Find everything before you remove anything. Eradicating one foothold while an attacker retains others just tells them you've noticed, and prolongs the incident.
Rebuild rather than clean. For anything beyond trivial infections, reimage.
Restore in the right order. Identity infrastructure first, then backups, then core applications. Modern attacks compromise Active Directory or Entra, so if you restore applications onto a compromised identity plane you're restoring into the attacker's hands. Document this order before you need it — deriving it mid-incident costs days.
Verify backup integrity before restoring, and validate restored systems before returning them to production.
Rotate all credentials, privileged accounts first, then service accounts, then users. Where domain infrastructure was compromised, rotate the relevant secrets twice.
Close the way in, and keep heightened monitoring running for at least 30 days. Attackers return through the same door — access resold from a prior compromise is now the single most common ransomware entry vector.
Preserve this evidence
- One encrypted file sample and the ransom note
- Forensic images of representative affected systems
- Logs exported before retention windows roll over — this is urgent and frequently missed
- All extortion communications, including anything on a leak site
- Your incident timeline
The eight mistakes that make it worse
Wiping systems before imaging them. You lose the ability to determine scope, which you need for notification.
Restoring onto a network that's still compromised. The most common cause of a second encryption event.
Saying "no data was taken" before forensics concludes. Roughly half of first-year SEC incident filings had to be amended with later detail, according to an NYU review of the rule's first year. Say "no evidence of X at this time" instead.
Negotiating without counsel and your insurer. It can void coverage and create sanctions exposure.
Discovering the backups were compromised weeks ago. This is what restore testing prevents.
Powering machines off, destroying memory evidence.
Treating the notification clock as a later problem. It starts now.
Letting IT "just fix it" before logs are preserved. Well-intentioned, and it destroys the record you need.
Preventing the next one
The controls that actually change ransomware outcomes, in order:
Phishing-resistant multi-factor authentication — passkeys or hardware keys, administrators first.
Immutable, offline backups that you have actually restored from, timed against your recovery target. Only 54% of victims successfully restored in 2025 in Sophos's survey, usually because nobody had tried.
Treat identity, backup and virtualization infrastructure as Tier 0 — separate credentials, separate admin workstations, no internet-exposed management interfaces.
Patch internet-facing systems in days, not weeks, prioritised by evidence of active exploitation.
Harden help-desk identity verification. Several of the largest incidents of the last three years began with a phone call requesting a password reset.
Treat infostealer detections as ransomware precursors. Mandiant measured the handoff from an access broker to a ransomware crew averaging 22 seconds. There is no such thing as a low-priority credential-theft alert.
All of these are in minimum viable security, with the evidence for each.
What to do next: If you're not currently in an incident, print this page and put a copy somewhere that doesn't depend on your network. Then add your insurer's hotline, your IR firm, and your counsel's out-of-hours number to it.
Related: All incident response playbooks · Ransomware: attacks up, payments down · Minimum viable security · Breach notification deadlines (planned reference; not yet available)
Sources: NIST SP 800-61r3, Incident Response Recommendations (Apr 2025). CISA #StopRansomware Guide. US Treasury OFAC — advisory on potential sanctions risks for facilitating ransomware payments. Verizon 2026 DBIR — payment rates. Mandiant M-Trends 2026 — access-broker handoff timing and prior-compromise entry vector. Sophos State of Ransomware 2025 — restoration rates. NYU Program on Corporate Compliance and Enforcement — SEC Item 1.05 first-year review. No More Ransom.