If ransomware is suspected now
- Isolate affected systems from the network to limit spread; do not wait for a perfect diagnosis.
- Activate your incident lead and technical responder through a trusted contact channel.
- Preserve the timeline and available evidence; coordinate disruptive changes.
- Protect backups and identity systems, then scope recovery before restoring.
Last updated: September 24, 2026
The first 30 minutes is a decision window, not a guaranteed containment deadline. The actual sequence depends on what is affected and who can respond. CISA's ransomware response checklist starts by identifying and isolating impacted systems, including network-level isolation when many systems are involved. Follow your organization's incident plan and get qualified help when the scope is unclear.
First decision: isolate what you know is affected
Disconnect an affected device from Wi-Fi and Ethernet or ask IT to isolate it centrally. If multiple devices or shared storage are involved, the responder may need to take a segment offline. Tell staff not to reconnect devices or use the same credentials on another system. Avoid wiping, reinstalling or casually powering down affected machines; your responder may need volatile or disk evidence. If isolation is impossible, ask the technical incident lead for the least damaging containment step.
Second decision: activate the right people
Contact the incident lead, IT provider or security responder, operations owner and the person responsible for backups. Use phone numbers or channels already documented outside the affected email tenant. Assign one person to record times, systems, actions and decisions. Notify the bank immediately if payment systems or transfers may be involved. Contact the insurer and legal adviser where relevant; they can help determine contractual and regulatory obligations. The full incident-response guide includes roles and a runbook structure.
Third decision: protect recovery and evidence
The technical lead identifies affected devices, accounts, cloud drives and backup repositories. Check whether backup credentials or consoles might also be compromised, and restrict access before restoring. Save ransom notes, relevant logs, alerts and user reports according to the responder's instructions. Do not assume a backup is safe or complete simply because its dashboard is green. Test the required restore path in a clean environment before reconnecting production.
| Do now | Wait for a scoped response decision |
|---|---|
| Isolate known affected devices and notify responders | Wipe or reimage systems |
| Record the earliest alert and affected services | Restore over possibly compromised production |
| Protect backup and administrator access | Make payment or public statements |
| Use trusted contacts for bank, insurer and specialist help | Promise a recovery time before testing |
Reporting and recovery
The FBI Internet Crime Complaint Center accepts cybercrime reports. Follow the advice of your responder, insurer and legal adviser for any other reporting duties; timing and scope depend on the incident and affected data. After containment, document the entry route, remove persistence, reset affected credentials, restore from validated backups and monitor for recurrence. NIST SP 800-61 Rev. 3 places response and recovery within ongoing risk management, including lessons learned.
A printed copy helps
Keep incident contacts and this first-response sequence available outside the systems that may be unavailable. Practice the decisions before an incident using the 90-day roadmap.
Sources checked September 24, 2026: CISA StopRansomware Guide, NIST SP 800-61r3, and FBI IC3. This page is general incident guidance, not a substitute for a responder's advice on a live event.