Incident Response KitFree severity check

Malware on a device: incident response playbook

Use it when: Antivirus or endpoint alerts, pop-ups, unknown programs, or a device behaving oddly.

First 15 minutes

  1. Isolate the device from the network using your endpoint tool or by unplugging.
  2. Leave it switched on.
  3. Note the alert name, file and time.
  4. Reset passwords used on the device from another device.

Set the severity and download a first-response checklist

What the full playbook covers

The full playbook is in the Incident Response & Business Continuity Kit with 8 more, the IR plan, a BCP/DR plan and 6 tabletop exercises.

Other playbooks

Incident Response & Business Continuity Kit

More free security and AI governance tools