Critical severityHARDEC6 steps · 5 phases
Ransomware Response
Ransomware incident response based on CISA/FBI StopRansomware + Mandiant + NIST SP 800-184. Isolate first, then investigate.
1
Preparation
1 steps- Offline backup + IR retainer
3-2-1 backup, immutable/air-gapped copy, restoration drill, crisis communication plan, insurance/legal.
2
Detection & Analysis
1 steps- Scope and variant
Encrypted systems, ransom note, ransomware family; look for data exfiltration (double extortion) traces.
3
Containment, Eradication & Recovery
2 steps- Stop the spread
Isolate affected networks, shut down shares, protect AD/backup servers; DO NOT DELETE encrypted systems.
- Remove the threat
Close the initial access vector, clean persistence/tools, reset all credentials (krbtgt 2x).
4