Incident Response KitFree severity check

Ransomware: incident response playbook

Use it when: Files are encrypted or renamed, a ransom note appears, or many devices fail at once.

First 15 minutes

  1. Disconnect affected devices from the network (unplug or disable Wi-Fi). Do not switch them off.
  2. Disable remote access and VPN accounts that may be compromised.
  3. Protect backups: take them offline or confirm they are immutable.
  4. Call the incident lead and escalate to SEV1.

Set the severity and download a first-response checklist

What the full playbook covers

The full playbook is in the Incident Response & Business Continuity Kit with 8 more, the IR plan, a BCP/DR plan and 6 tabletop exercises.

Other playbooks

Incident Response & Business Continuity Kit

More free security and AI governance tools