Incident Response

🔒 Ransomware

Files are encrypted, inaccessible, or you're seeing a ransom note.

Right now
  • Disconnect the affected device from the network (unplug ethernet, turn off Wi-Fi) — do not turn it off yet, as that can destroy forensic evidence.
  • Do not pay the ransom, and do not negotiate on your own — involve law enforcement and, if you have one, your cyber insurance carrier first.
  • Identify which systems are affected and isolate them from the rest of the network.
  • Notify your Incident Lead (see your Incident Response Policy) immediately.
First few hours
  • Check whether clean backups exist and are unaffected (verify backups are not also encrypted or connected to the infected network).
  • Contact your cyber insurance carrier, if you have a policy — many require notification before you take remediation steps.
  • Consider engaging outside incident response / forensics help if you don't have in-house expertise.
  • Preserve evidence — do not wipe or reimage systems until you've captured what's needed for investigation and insurance/law enforcement.
  • Report to the FBI's Internet Crime Complaint Center (IC3.gov) or local field office.
Recovery
  • Restore from clean, verified backups rather than paying for a decryption key when possible.
  • Change all credentials that may have been exposed, especially admin/privileged accounts.
  • Patch the vulnerability that allowed the attack before reconnecting systems.
  • Document the timeline and response for your incident report and any required notifications.
Notification obligations

If ransomware may have accessed or exfiltrated personal data (not just encrypted it), this may trigger state breach notification laws and, for healthcare organizations, HIPAA breach notification requirements. Consult legal counsel promptly to determine your specific obligations and deadlines.

Developed and supported by iConsulting — a working vCISO practice.Contact us for vCISO services →