Ransomware Response Plan
Security & antivirus
ransomware
incident response
backup
security
By Cade · Updated 03/05/26 07:41 AM
Ransomware encrypts your files and demands payment for the decryption key. A fast, practiced response limits damage. Know the plan before an incident occurs.
Immediate response: isolate affected machines immediately — disconnect from the network. Alert IT and management. Identify the ransomware strain by examining the ransom note or using ID Ransomware (id-ransomware.malwarehunterteam.com) — some strains have free decryptors available. Do NOT pay the ransom without consulting legal counsel and your cyber insurance provider.
Recovery: restore from the most recent clean backup. Verify backups are unaffected — ransomware often targets network shares and backup systems. If backups are also encrypted, check for shadow copies (vssadmin list shadows) or file versioning in OneDrive/SharePoint, which may allow recovering previous versions. After recovery, identify the initial infection vector (most commonly phishing email or RDP brute force) and remediate it before restoring connectivity. File a report with the FBI's IC3 (ic3.gov) — this helps track and combat ransomware groups.