Ransomware first response: a calm containment checklist

When ransomware or destructive encryption is suspected, activate the incident plan, isolate affected systems in a coordinated way, preserve evidence, use known-safe communications, protect identities and backups, and involve qualified responders before rebuilding.

Executive summary

What you need to know

When ransomware or destructive encryption is suspected, activate the incident plan, isolate affected systems in a coordinated way, preserve evidence, use known-safe communications, protect identities and backups, and involve qualified responders before rebuilding.

Potentially affected

Organizations observing ransom notes, rapid file encryption, inaccessible systems, destructive activity, or credible ransomware and data-extortion indicators.

DSE recommendation

Activate the approved incident plan and contact the designated response lead immediately from a known-safe channel; do not begin an improvised cleanup.

Suspected ransomware requires fast action, but improvised action can destroy evidence, interrupt unaffected services, or allow the attacker to observe the response. Use the organization’s approved incident-response plan and a known-safe communication channel.

What the official source says

Source fact: Part 2 of CISA’s #StopRansomware Guide provides a ransomware and data-extortion response checklist. CISA places the initial steps in sequence: determine which systems are impacted and immediately isolate them; power down devices only when they cannot otherwise be disconnected, recognizing that shutdown can remove evidence held in volatile memory; then continue coordinated containment and analysis.

First-response checklist

  1. Activate the plan. Contact the designated incident lead, executive decision-maker, IT/security responder, and other required advisers using verified contact information.
  2. Start an incident record. Note who observed what, the exact time, affected systems, ransom-note details, unusual account activity, and actions taken. Separate confirmed observations from assumptions.
  3. Isolate in a coordinated manner. Follow responder direction to remove affected devices or network segments from wired, wireless, remote-access, and cloud connectivity. Do not connect removable media.
  4. Preserve evidence. Do not delete ransom notes, reimage systems, run cleanup tools, or broadly reset systems before qualified responders determine what evidence is needed.
  5. Use known-safe communications. Assume ordinary email or collaboration tools may be visible to an attacker until evaluated. Use the approved out-of-band method.
  6. Protect identities and remote access. Qualified administrators should evaluate involved accounts, privileged access, active sessions, remote services, cloud identities, and suspicious enrollment or recovery changes.
  7. Protect backups and logs. Restrict access to backup administration, preserve relevant logs, and avoid attaching known-good backup media to a potentially compromised environment.
  8. Engage required parties. Follow organizational procedures for legal counsel, cyber insurance, law enforcement, CISA, regulators, customers, employees, and communications. Applicability and timing require qualified review.

Power and isolation decisions

DSE recommendation: prefer coordinated network isolation when it can be performed safely. CISA notes that powering down may be necessary when a device cannot be disconnected, but it can eliminate volatile evidence. Do not use a universal “always shut down” or “never shut down” rule; follow the approved plan and responder direction.

Do not rush into recovery

Recovery should begin only after the team understands the likely entry path, affected scope, persistence risk, credential exposure, and clean recovery environment. Prioritize services using the approved critical-asset list. Validate backups before restoration and change affected credentials after systems are cleaned and persistence is addressed.

This checklist is operational education, not digital-forensics, legal, regulatory, insurance, or ransom-payment advice. DSE should not be represented as providing those specialized services unless expressly contracted.

Practical next step: print or securely store the incident contacts and isolation authority before an event. During an event, record every action and obtain qualified direction before cleanup or restoration.

Primary reference

Review the official source

CISA #StopRansomware Guide · Published October 19, 2023

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE