What this guide helps you evaluate
Organizations responding defensively after files or systems have been encrypted by ransomware.
This page is designed to help you compare the moving parts, organize due diligence and ask better questions before you commit money, sign a contract or change an operating process.
What to compare first
- Isolation of affected systems and accounts
- Evidence preservation and incident scoping
- Known-good offline or immutable backups
- Trusted identification and decryptor resources
- Credential reset, rebuild and controlled restoration
Step-by-step process
- 01
Isolate affected systems according to the incident-response plan and prioritize critical services.
- 02
Preserve forensic evidence and identify the ransomware variant with trusted responders.
- 03
Check backup integrity from an environment that is not connected to compromised credentials or systems.
- 04
Use only reputable government, law-enforcement or established security sources to evaluate available decryptors.
- 05
Rebuild or restore in stages, rotate exposed credentials and monitor closely for persistence.
Common mistakes and risk checks
- Connecting clean backups to an environment that is still compromised.
- Running unknown 'decryptor' downloads from untrusted sites.
- Restoring service before the initial access path and credentials are addressed.
Primary and official references
Rules, pricing and requirements can change. Use these sources to verify the latest details that apply to your situation.