Incident Response
Ransomware Response: The First 24 Hours of Containment and Decision-Making
A calm, evidence-led playbook for containing an incident, protecting people, and making defensible decisions.

The first day of a ransomware incident sets the quality of every decision that follows. This guide covers safe containment, evidence preservation, communications, leadership decisions, and the path to recovery.
Table of Contents
- Why ransomware needs a coordinated response
- The first hours: activate, isolate, preserve
- Scope the incident without assumptions
- Contain and communicate
- Risk rating
- Eradicate and recover safely
Why Ransomware Needs a Coordinated Response
Ransomware is rarely only an encryption event. It can involve stolen credentials, disrupted services, data theft, extortion, and persistence that existed before the visible impact. Treat the event as a broader security incident until evidence shows otherwise.
The objective is not simply to make affected devices disappear from view. It is to protect people, critical services, recovery options, and reliable evidence while leaders make informed decisions.
The First Hours: Activate, Isolate, Preserve
Activate the approved incident-response process and involve technology, operations, legal, communications, and cyber-insurance stakeholders as appropriate. Isolate confirmed affected systems and prioritize critical services that may be at risk of further disruption.
Preserve volatile evidence and relevant logs under the direction of the response team. Avoid broad rebuilding, indiscriminate deletion, or unsupported cleanup before the organization has captured enough information to understand the incident.
Alert -> activate response -> isolate priority systems -> preserve evidence -> scope and contain -> recover safely
Scope the Incident Without Assumptions
A visible ransom note does not define the full scope. Investigate affected devices, identities, remote access paths, privileged accounts, cloud services, backups, and business systems that depend on them.
Build a working view of what happened, what is still exposed, what information may have been accessed, and which services must be restored first. Update this view as evidence improves rather than treating early assumptions as facts.
- Identify affected systems, accounts, networks, cloud resources, and business services.
- Review endpoint, identity, network, application, and backup-management telemetry.
- Determine whether the initial access path or persistence mechanism may still be active.
- Confirm the condition and accessibility of backup and recovery systems.
Contain and Communicate
Containment should reduce further harm while preserving the ability to investigate and recover. It may include restricting compromised identities, disabling exposed access paths, and separating affected systems from healthy operations according to the incident plan.
Use a controlled communication process. Leadership, service owners, legal advisers, insurers, customers, regulators, and law enforcement may each need timely information, but notifications should be accurate, approved, and appropriate to the organization's obligations.
Risk Rating
| Severity | Description |
|---|---|
| Critical | Core identity systems or business-critical services are affected, or material data theft and broad operational disruption are confirmed. |
| High | Multiple systems, privileged identities, sensitive data, or essential business processes are at risk or disrupted. |
| Medium | Impact is contained to a limited environment, with no evidence of broad privilege or critical-service compromise. |
| Low | A suspicious event is contained quickly with limited operational impact and no confirmed compromise. |
Eradicate and Recover Safely
Recovery should begin only after assessing the likely entry path, persistence, affected identities, and condition of recovery sources. Rebuild from trusted images or approved infrastructure templates, apply necessary remediation, and restore in business-led phases.
Reset or rotate compromised credentials, secrets, and keys based on the incident scope. Monitor restored services closely, validate critical workflows, and preserve evidence for post-incident review.
Ransomware Response Checklist
- An incident commander, technical lead, and executive decision path are established.
- Affected systems and identities are isolated according to the response plan.
- Relevant logs, volatile evidence, and recovery information are preserved.
- Critical business services and dependencies are prioritized for recovery.
- Communications, legal, insurance, and notification obligations are coordinated.
- Restored systems are rebuilt, validated, and monitored before normal operation.
