ransomware response checklist for small teams
A ransomware response checklist for small teams: isolation, variant identification, evidence preservation, backup verification, notification, and rebuild. Use when ransomware is suspected or confirmed. Triggers: 'ransomware', 'files encrypted', 'ransom note'. Not for: preventing ransomware or negotiating with attackers.
ransomware response checklist for small teams
TL;DR
Disconnect everything fast, figure out what variant hit you, and restore from backups you know are clean. Do not pay the ransom as a first move; talk to counsel and law enforcement first. A small team can handle this if the checklist is written before the crisis, not during it.
ransomware response checklist for small teamsUse this when
- files are encrypted and a ransom note appeared
- EDR or a user reports suspected ransomware activity
- you need a checklist to follow instead of improvising under pressure
- you are a small team without a dedicated incident response function
Not for this skill when
- you are trying to prevent ransomware (backups, patching, and phishing defense are separate work)
- you need to negotiate with the attackers (get professional help and counsel)
- the encryption is on a single non-critical file with a known benign cause
- you need forensic attribution of the attacker (that is law enforcement's job)
Steps
- Isolate affected machines immediately. Unplug network cables and disable Wi-Fi. If it is spreading, take the whole subnet or site offline. Speed beats precision here; you can sort out what was actually infected later.
- Identify the variant. Read the ransom note, note the encrypted file extensions, and check the note text against public ransomware identification resources. The variant tells you whether free decryptors exist and what the attacker typically does next.
- Preserve evidence. Photograph the ransom note screens, save a copy of the note file, and keep one encrypted sample plus one original of the same file if you have it. You will need these for law enforcement, insurers, and possibly a decryptor.
- Find the entry point. Check EDR alerts, VPN and remote-access logs, and email from around the time encryption started. You must close the hole before you restore, or it happens again next week.
- Check your backups. Verify that your offline or immutable backups are intact and were not encrypted along with everything else. Test-restore a few files before you commit to a full restore; a restore that fails halfway is its own disaster.
- Notify. Tell leadership, engage legal counsel, and contact law enforcement (your local FBI field office or national equivalent). Counsel decides whether breach notification obligations apply.
- Restore and rebuild. Wipe affected machines completely and restore from clean backups. Reset all passwords afterward, especially admin and service accounts, since credentials were likely stolen before the encryption started.
- Watch for double extortion. Assume data was stolen before it was encrypted, and monitor for leaks of your data in the following weeks. The encryption is only half the incident.
Variant: ransomware on a single laptop
Same checklist, smaller blast radius. Isolate the laptop, check whether it had access to shared drives (that decides whether this is really "single"), and reimage from known-good media rather than trying to clean it.
Variant: cloud data encrypted through compromised credentials
The "isolate" step means revoking the compromised credentials and keys first, then checking versioning and backups on the affected buckets. Cloud versioning is often the fastest restore path.
Variant: ransomware with no ransom note
No note plus encryption can mean a wiper, which has no recovery path through payment at all. Skip straight to backups and rebuild, and treat it as destruction rather than extortion.
Why this happens
Ransomware encrypts fast and spreads through network shares and remote access. The first hour decides whether it is one machine or the whole company. Small teams get hit because they are softer targets, not because they are uninteresting.
Edge cases and pitfalls
- Paying the ransom is discouraged by law enforcement, may violate sanctions, and doesnt guarantee decryption. Treat it as a last resort decided with counsel, not a first move.
- Backups that were online during the attack are probably encrypted too. Offline and immutable backups are the only ones you can trust.
- Never pay a third party who "guarantees" decryption. Many are scams, and some just pay the ransom and pocket the difference.
- Document everything as you go. Insurers, lawyers, and regulators will all ask for the timeline later.
- Tell the team what is happening. Silence breeds rumors, and rumors breed people plugging "just one laptop" back into the network to check email.
Provenance
Resolved from the public thread: https://vectle.com/posts/pstjlydtAAXYEJY2YFvHt4tA