BY BUSINESS OBJECTIVE
ASSESS & VALIDATE — FIND WEAKNESSES
Digisecuritas logo
Incident Response

How to Respond to a Ransomware Attack: Step-by-Step Playbook

D

Digisecuritas

Cybersecurity Experts

·8 min read

When ransomware hits, the nine steps your team needs to execute immediately are: isolate affected systems, activate your incident response team, preserve forensic evidence, assess the blast radius, notify legal and your insurer, evaluate the ransom decision with counsel, restore from validated clean backups, conduct a post-incident review, and patch the entry vector. This playbook walks through each step in detail with timing, ownership, and the mistakes that turn a contained event into a business crisis.

If you do not have this process documented before an attack happens, you will improvise it under pressure. That is where the real damage is done.

The Situation. It is 6:47 on a Tuesday morning. Your IT manager gets an alert — dozens of workstations are showing the same error. By the time she opens her laptop, the ransom note is already on screen. Files across three servers are encrypted. The backup server is throwing errors. No one knows how far it has spread. In the next four hours, your team will make decisions that determine whether this is a two-day disruption or a six-week shutdown.

Ransomware is not just a technical incident. It is a simultaneous operational, legal, financial, and reputational crisis — and it unfolds in real time. Organisations that navigate it well have one thing in common: they had a plan before the attack happened.

What Makes Ransomware Different from Other Cyber Incidents?

Most cybersecurity incidents affect one layer of your business. Ransomware hits three at once.

  • Operational shutdown. Systems are encrypted and unavailable. Depending on what is hit, this can mean your entire workforce cannot work, customer-facing services are down, and order fulfilment, billing, and communications all stop.
  • Data exfiltration. Modern ransomware groups do not just encrypt your data. They exfiltrate it first and threaten to publish it if you do not pay — a tactic called double extortion. This means paying the ransom does not guarantee your data stays private.
  • Regulatory exposure. If the encrypted data includes personal data, health records, or payment information, you have breach notification obligations across GDPR, HIPAA, PCI DSS, and sector regulators, with timelines that begin the moment you become aware of the incident.

According to IBM's Cost of a Data Breach Report 2025, the average global cost of a ransomware attack is $5.13 million, and the average downtime is 24 days. For organisations without a tested incident response plan, both figures are significantly higher.

Before the Attack: What You Need in Place

The steps in the next section only work if the foundations exist before an attack. A brief readiness checklist:

  • A documented Incident Response Plan with defined roles — who declares an incident, who leads the response, who handles legal and communications
  • A named external cyber incident response retainer with pre-agreed activation terms and SLAs
  • Offline, tested backups that are isolated from your primary network and verified to actually restore
  • A current asset inventory so you know what exists, what matters, and what is connected to what
  • Network segmentation to limit lateral movement once an attacker is inside

If any of these are missing, the steps below still apply — but your response will be slower, costlier, and more dependent on decisions being made under pressure.

The Ransomware Incident Response Playbook: Step by Step

  1. 01. Detect and Confirm (0 to 15 Minutes). Do not act on assumption. Before triggering a full incident response, confirm that what you are seeing is actually ransomware — not a storage failure, a system update gone wrong, or a false alert from your endpoint agent. Check your EDR and SIEM for correlated alerts. Look for mass file encryption activity, unusual process execution, or lateral movement indicators. Identify which systems are affected and, if possible, the initial point of compromise — without touching the infected systems. This matters because the actions you take in the next 30 minutes are difficult to reverse. Confirm before you escalate.
  2. 02. Activate Your Incident Response Team (15 to 30 Minutes). This is not a job for your IT team alone. Ransomware response requires an incident command structure with clear ownership across technical, legal, and communications functions. Activate immediately: your Incident Response Lead (internal CISO or external retainer provider), Legal Counsel (because every decision from this point is legally consequential), an Executive Sponsor with authority to make decisions on ransom and business continuity, and your external IR retainer provider if you have one. Do not put your IT manager in charge of an incident they were not trained to lead.
  3. 03. Isolate, Do Not Shut Down (30 to 60 Minutes). The instinct when ransomware is discovered is to pull the plug. Resist it. Shutting down infected systems destroys volatile memory — which may contain encryption keys, attacker tooling, and forensic evidence essential for both recovery and investigation. Instead, isolate: disconnect infected systems from the network at the switch level, disable affected user accounts, block the relevant network segments at the firewall, and identify clean systems. The goal is to stop lateral movement and further encryption while preserving everything needed for forensic investigation.
  4. 04. Assess the Blast Radius (Hours 1 to 3). Before you can make any decision about ransom, recovery, or disclosure, you need to understand the scope of what has happened. Map what is encrypted, what has been exfiltrated (check egress logs and firewall telemetry), what is still clean, and what the entry vector was. This assessment drives every subsequent decision. Do not skip it to move faster on recovery.
  5. 05. Preserve Forensic Evidence (Parallel to Steps 3 and 4). This step runs in parallel — not after containment. Before any system is wiped, rebuilt, or restored, your IR team should take forensic disk images of affected systems, capture live memory from systems still running, preserve all available logs (endpoint, firewall, DNS, Active Directory, cloud platform), and document the chain of custody for all evidence collected. Cyber insurance claims require evidence. Regulatory investigations will ask for logs. Wiping before capturing evidence is one of the most costly mistakes in ransomware response.
  6. 06. Notify the Right People (Hours 2 to 6). Legal has been involved since Step 2. Now move on external notifications — in the right order. Notify your cyber insurer as early as possible (most policies have notification windows that affect coverage). Under GDPR, personal data breaches must be reported to the relevant supervisory authority within 72 hours. HIPAA requires notification within 60 days for breaches affecting more than 500 individuals. PCI DSS requires immediate notification to your acquiring bank. Do not post on social media or issue press statements before legal has reviewed everything.
  7. 07. Evaluate the Ransom Decision (Hours 3 to 8). This is one of the most consequential decisions in any ransomware response, and it should never be made by your IT team or made in isolation. Consider: backup availability (if clean tested backups cover affected systems, paying is rarely rational), decryptor reliability, double extortion risk, regulatory risk (paying groups on OFAC sanctions lists may itself be a regulatory violation), insurance coverage, and business continuity costs. This decision must be made by executives with legal and insurance counsel involved.
  8. 08. Recover and Restore (Days 1 to 7+). Recovery is a phased process that must be validated at each stage. Verify backups before restoring — many ransomware groups specifically target backup infrastructure in the days before triggering encryption. Build a clean environment for significant incidents rather than restoring directly onto potentially compromised infrastructure. Prioritise critical business systems first. No system returns to the production network until it has been confirmed clean.
  9. 09. Post-Incident Review (After Recovery). Once the immediate crisis is resolved, the work of actually learning from it begins. A thorough post-incident review covers root cause analysis, timeline reconstruction, what worked and what failed, remediation (patch the entry vector, fix the gaps, update the IR plan), and regulatory closeout. The post-incident review is not a blame exercise — it is the mechanism by which organisations become genuinely more resilient after an attack.

The Biggest Ransomware Response Mistakes Organisations Make

Most of the damage done in ransomware incidents is not caused by the attackers. It is caused by the response.

  • Paying the ransom without legal and insurance consultation. Ransom payments made to sanctioned groups create regulatory liability. Payments made without insurance consultation may void coverage. This decision requires counsel, always.
  • Shutting down systems before capturing forensic evidence. Cold shutdown destroys volatile memory. You may lose encryption keys, attacker tooling, and the only evidence that supports your insurance claim or regulatory notification.
  • Notifying customers before legal review. Premature or inaccurate breach notifications create independent liability. Every external communication must be reviewed by legal before it goes out.
  • Restoring from backups that were already encrypted. Ransomware groups often compromise backup infrastructure weeks before triggering encryption. Verify backup integrity before restoring — or you will restore the problem.
  • Trying to find an IR firm mid-crisis. When you are searching for an incident response provider at 3 AM during a live attack, you are negotiating from the worst possible position. Response times are slower, costs are higher, and the team has no prior familiarity with your environment.

Why a Cyber Incident Response Retainer Changes Everything

The organisations that contain ransomware attacks fastest share one characteristic: they had a relationship with an incident response provider before the attack happened.

  • Pre-agreed SLAs. Guaranteed response times, typically measured in hours, not days.
  • Pre-authorised access. Legal and technical agreements already in place, so your IR team can begin work immediately.
  • Environment familiarity. Your IR provider already knows your environment, critical systems, and contacts before the call comes in.
  • Cost predictability. Retainer fees are predictable and budgetable. Emergency IR engagement fees during a live incident are not.

The cost difference between retainer-based IR and emergency IR is significant. But the more important difference is time — and in ransomware response, time directly determines how many systems get encrypted, how much data gets exfiltrated, and how long your business stays down.

Final Thoughts

Ransomware is not a question of if — it is a question of when, and whether your organisation is ready when it arrives. The nine steps in this playbook are not complicated. What makes them hard is executing them correctly, in sequence, under pressure, without a pre-built plan and a practised team. Every gap in your readiness — no tested backups, no retainer, no documented IR plan — compounds the cost and the downtime when the ransom note appears.

The organisations that recover in days instead of weeks are not lucky. They prepared.

If your organisation does not have a documented incident response plan, a tested backup strategy, or a retained incident response provider, now is the right time to fix that — before it becomes urgent.

Frequently Asked Questions

Incident ResponseRansomware

Related reading