Ransomware: incident response playbook
Use it when: Files are encrypted or renamed, a ransom note appears, or many devices fail at once.
First 15 minutes
- Disconnect affected devices from the network (unplug or disable Wi-Fi). Do not switch them off.
- Disable remote access and VPN accounts that may be compromised.
- Protect backups: take them offline or confirm they are immutable.
- Call the incident lead and escalate to SEV1.
Set the severity and download a first-response checklist
What the full playbook covers
- Contain (3 steps)
- Eradicate (2)
- Recover (2)
- Who to notify
- Evidence to keep
The full playbook is in the Incident Response & Business Continuity Kit with 8 more, the IR plan, a BCP/DR plan and 6 tabletop exercises.