ChecklistCONSTRUCTEDUntested
First 15 minutes: a ransom note, or files that suddenly will not open
Encryption is under way or has just finished. Contain without destroying the memory that holds the operator's tools, protect the backups, and start the clocks that legal and your insurer will ask about.
critical severityImpactT1486T1490
The clock starts when
A ransom note appears, files across a share change extension or will not open, or shadow copies and backup catalogues are deleted.
Stop the spread, keep the machines on
Find where it is coming from
Bring in the people who decide
Do not
- Do not reboot or power off encrypted machines.
- Do not restore from backup until you know how they got in, or you will restore into an open door.
- Do not contact the operator, and do not let anybody else, until legal has decided.
- Do not run a decryptor from the internet on the only copy of the data.
Escalate now if
- Domain controllers, hypervisors or backup servers are affected.
- Backups are deleted, encrypted or unreachable.
- More than one site or business unit is affected.
- There is evidence that data left before encryption.
Minute sixteen. The checklist ends here and the response does not.
Open the ransomware response planWhy this order
Two instincts cause most of the lasting damage here. The first is to switch things off, which stops nothing that network isolation would not also stop and destroys the memory evidence. The second is to start restoring, which feels like progress and restores into an estate where the way in is still open.
The CISA guide says to power down only if you cannot disconnect. That is the line this checklist follows.
What this does not cover
Everything after the first fifteen minutes: scoping, eradication, recovery and notification. The response plan linked above takes it from here, and the first-hour playbook covers the rest of the first hour for whoever is at the keyboard.