Writifi

Ransomware Response Checklist

The practical sequence of steps for a suspected ransomware incident, from the first sign of encryption through to recovery.

Immediate (first few minutes)

Determine whether systems are actively encrypting or the ransomware is still spreading. Decide whether to disconnect affected systems from the network or shut them down - don't apply a blanket rule; network isolation can preserve forensic evidence while a shutdown can stop active processes but may lose evidence, so weigh containment against investigation needs. Protect unaffected systems and backups immediately, since ransomware often targets backup systems specifically. Photograph or screenshot ransom notes and preserve evidence where it's safe to do so, and establish trusted communications in case email is compromised.

First hour

Try to identify the likely initial access point and determine the scope - how many systems and what data is affected. Preserve logs and evidence before they're overwritten. Check the state of your backups and whether they're clean and usable. Consider contacting your insurer or an incident response provider at this stage rather than later. It's also worth checking whether a reputable free decryptor exists for the specific ransomware family before assuming none is available - but this should never delay proper containment and shouldn't be relied on as your primary recovery plan.

Recovery

Do not restore systems until you have reasonable confidence the attacker's access has been fully removed - restoring too early is one of the most common ways businesses get hit a second time. Validate recovery sources and backups before use. Restore systems in business-priority order rather than whatever's easiest first, and monitor closely afterwards for signs of persistence. Any decision about paying a ransom should be made with specialist, insurer and legal input - never as a unilateral technical decision under pressure.

Common mistakes that make ransomware incidents worse

Wiping and rebuilding a system before anyone has looked at it for evidence. Restoring from a backup that turns out to be from after the initial compromise, reintroducing the same vulnerability. Assuming the incident is over because encryption has stopped, without confirming the attacker no longer has access. Treating the ransom note's deadline as something you must react to immediately rather than a pressure tactic.

A structured playbook helps under pressure

Ransomware is one of the highest-pressure incidents a business can face, which is exactly when a written checklist earns its keep - it's very easy to skip steps like evidence preservation when systems are down and people are anxious to get back to work. Our Cyber Incident Response Plan & Toolkit includes a full ransomware/malware playbook alongside four other common-scenario playbooks, the severity assessment to help you judge how serious the situation is, and the workbook to keep a clean record throughout.