Ransomware incidents rarely begin with the ransom note. By the time files are encrypted, attackers have usually been inside the network for some time, have obtained privileged credentials and have often copied data. The first hours after discovery are therefore about understanding and controlling a situation that has been developing out of sight.
This is general guidance, not a substitute for professional support tailored to your environment.
Stabilize without destroying evidence
- Isolate affected systems from the network rather than powering them off; memory and running processes may hold valuable evidence.
- Do not wipe, rebuild or restore systems yet. Restoring into a compromised environment can lead to reinfection.
- Preserve logs from firewalls, VPNs, identity providers, endpoint tools and cloud services before retention limits overwrite them.
- Protect backups: disconnect them and verify their integrity before relying on them.
Assume identities are compromised
Most ransomware operations rely on stolen administrative credentials. Plan credential resets from clean devices, prioritize privileged and service accounts, and consider that attackers may be watching internal email and chat. Use out-of-band communication for the response team.
Establish scope before acting broadly
Containment that removes the attacker from one place while leaving other footholds can alert them and trigger further damage. Investigators should quickly identify the entry point, persistence mechanisms, affected systems and whether data was exfiltrated, then contain in a coordinated way.
Bring the right people into the room
- An executive decision-maker with authority over operations and spending.
- Legal counsel, to address notification obligations, privilege and regulatory questions.
- Your cyber insurer, if you have a policy; many policies define required steps and approved providers.
- Communications, to prepare accurate messages for employees, customers and partners.
- Technical leads for IT, security and critical business systems.
Make decisions on facts
Pressure to act immediately is intense. Keep a single incident log and timeline, agree on a regular decision cadence, and separate what is known from what is assumed. Questions such as recovery order, external notification and engagement with the attackers deserve informed, documented decisions.
Prepare before it happens
Almost every point above is easier with preparation: an incident response plan with clear roles, playbooks for ransomware, tested offline backups, centralized logs with adequate retention, and an exercised crisis team. A tabletop exercise is one of the most cost-effective ways to find the gaps.
SecureTech's incident response practice supports both moments: readiness before an incident, including tabletop exercises, and hands-on response when one occurs.