Malware on a device: incident response playbook
Use it when: Antivirus or endpoint alerts, pop-ups, unknown programs, or a device behaving oddly.
First 15 minutes
- Isolate the device from the network using your endpoint tool or by unplugging.
- Leave it switched on.
- Note the alert name, file and time.
- Reset passwords used on the device from another device.
Set the severity and download a first-response checklist
What the full playbook covers
- Contain (1 steps)
- Eradicate (1)
- Recover (1)
- Who to notify
- Evidence to keep
The full playbook is in the Incident Response & Business Continuity Kit with 8 more, the IR plan, a BCP/DR plan and 6 tabletop exercises.