A ransomware playbook for growing IT teams.
A six-phase walk-through tailored for companies with an in-house IT team, basic EDR / MFA controls, and a part-time CISO or vCISO. Assumes a pre-signed DFIR retainer, MSSP / SOC contract, and a real cyber insurance policy with named breach coach.
Preparation & Prevention
You have an IT team, maybe a part-time CISO, and budget for tools. The question is whether the controls are deployed correctly and tested under pressure — and whether the IR plan exists outside one person's head.
- 013‑2‑1 backups with at least one immutable copy (Veeam Hardened Repo, Datto, Acronis Cyber Backup).
- 02EDR on every endpoint - Defender for Business, SentinelOne, CrowdStrike Falcon Go cover 50–500 seats affordably.
- 03MFA + conditional access: enforce trusted device + risk-based policies for admin tier.
- 04Pre-signed retainer with a DFIR firm and breach coach - paying full price during an incident is 3–5× more.
- 05Annual tabletop with execs, IT, legal and finance - even a half-day one exposes the gaps.
- 01Don't rely on a single "security person" - peer review and external audit are essential.
- 02Don't run privileged service accounts with non-expiring passwords across the estate.
- 03Don't decline the MSSP / SOC offer because it "looks expensive" - average incident cost dwarfs years of SOC fees.
- 04Don't let backup infrastructure share the same hypervisor or domain as production.
- 05Don't allow attestations on insurance / SOC 2 to drift away from reality between audits.
- 01Domain admin sprawl: more than 5 active DAs in a 200-seat company is almost always too many.
- 02Internet-facing services without WAF, rate-limit or geo-fencing.
- 03Untested DR plan - RTO not validated by a real-world drill in the last 6 months.
Initial Intrusion
A phishing payload runs, a VPN credential gets reused, a third-party integration is abused. Your SOC / MSSP sees the first signal — what happens in the next 60 minutes decides whether this is a near-miss or a board-level incident.
- 01Triage to SLA: SOC / MSSP picks up critical alerts within 15 minutes, not "next shift".
- 02EDR-isolate the host (containment policy) instead of physical shutdown - preserves memory and timeline.
- 03Preserve telemetry: memory dumps, EDR timeline, M365 / IdP logs, proxy logs - copy out before retention windows close.
- 04Activate the IR plan: war-room channel, comms cell, decision log, single source of truth.
- 05Hotline insurer + breach coach the same hour - engaging them late risks both cost and coverage.
- 01Don't power off - you lose volatile data and the EDR forensic chain.
- 02Don't mass-reset passwords - it tips off the attacker and shreds the trail.
- 03Don't dismiss "low and slow" alerts as "the SOC is still tuning" - that's how dwell time becomes 60+ days.
- 04Don't engage your usual vendors outside the insurer panel - invoices may not be reimbursed.
- 05Don't publish anything before forensic certainty - partial truths are worse than measured silence.
- 01Anomalous OAuth grants in Microsoft 365 / Workspace - third-party apps with mailbox.read scope.
- 02Service account abuse: NTLM relay, Kerberoasting attempts, AD recon (BloodHound-style queries).
- 03Endpoint → DC pivots in the EDR process tree - classic precursor to lateral movement.
Propagation & Encryption
The attacker pivots through tier‑1 accounts, exfiltrates data and detonates the encryptor — typically on a Friday night. This is the war-room phase: technical defense, business continuity and crisis communication in parallel.
- 01Stand up the crisis cell: exec, IT, legal, PR, insurance, HR - one chair, one decision log.
- 02Cut the perimeter: block all outbound egress except an allowlist for the DFIR firm and MSSP.
- 03Reset tier‑0: domain admins, schema admins, krbtgt twice (with interval), break-glass account verified.
- 04Move coordination off corporate to Signal / WhatsApp / phone - assume Teams / email is read by the attacker.
- 05Engage the retained DFIR firm formally with scope of work and named legal counsel.
- 01Don't make the pay / no-pay call in panic - sleep on it, with counsel, sanctions screen and decryption test in hand.
- 02Don't restore from backup until integrity is proven (IoC + behavioral scan of the backup itself).
- 03Don't talk to the attacker without a vetted negotiator, counsel and sanctions check (OFAC, EU lists).
- 04Don't drift into vague updates - silence is bad, but "we are investigating" for 5 days is worse.
- 05Don't authorise spend outside the insurer-approved vendor scope without a written carve-out.
- 01Mass encryption signals: anomalous I/O on file servers, extension changes, hidden volume snapshots being deleted.
- 02PsExec / WMI / SMB / RDP lateral moves from a small set of pivot hosts.
- 03Exfiltration tooling: MEGA, rclone, FileZilla, AnyDesk - visible in proxy and EDR network logs.
Containment & Eradication
The blast is contained. Now: uproot every trace of the attacker, rotate every secret, and decide between restore, negotiation or a hybrid path. Documentation here pays the insurance claim and survives the regulatory file.
- 01Forensic snapshots of critical systems and the AD database before any wipe or rebuild.
- 02Rotate every secret: passwords, API keys, SSH keys, certs, OAuth client secrets, SAML signing keys.
- 03Negotiator on standby if pay is even a possibility - vetted by insurer, with sanctions clearance.
- 04Parallel comms tracks: staff, customers, partners, regulators - each with their own message and timing.
- 05Track claim costs in real time by coverage head (DFIR, legal, PR, BI, ransom) so the claim assembles itself.
- 01Don't return systems to production without persistence checks (scheduled tasks, services, WMI subs, AD-ACL).
- 02Don't rush to close the incident - secondary access (backdoor accounts, OAuth tokens) is the norm.
- 03Don't pay without a successful decryption test on a sample file first.
- 04Don't claim "no data exfiltrated" until the exfil hunt is complete and signed off.
- 05Don't settle with third parties or vendors outside the panel without insurer sign-off.
- 01Persistence: scheduled tasks, services, WMI event subscriptions, AD-ACL tampering, certificate enrolment.
- 02Domain trust + golden ticket = double krbtgt rotation (10 hours apart minimum).
- 03Backdoor accounts in Entra ID / AD, planted days or weeks before the encryptor.
Operational Recovery
Systems come back in stages. The goal is not "the way it was" but a measurably stronger posture: cleaner identity, fewer privileged accounts, real EDR coverage, and a backup chain you have actually tested.
- 01Stage the return: tier‑0 (AD, DNS, PKI) → core business apps → periphery, with go/no-go gates.
- 02Rebuild from gold image wherever possible - beats restoring a 30-day-old "dirty" backup.
- 03Enhanced monitoring (heightened alert thresholds, threat-hunt sweeps) for 60–90 days post-recovery.
- 04Weekly updates to the board, customers, key partners - even if there is no news.
- 05Business interruption claim: track downtime, lost revenue, extra-expense costs daily with line-item evidence.
- 01Don't bring everything back on the same day - an alert avalanche will hide a second intrusion.
- 02Don't switch off enhanced monitoring as soon as "everything works" - re-entry attempts are common.
- 03Don't claim insurance without aligning the narrative with the broker - uncoordinated statements reduce payouts.
- 04Don't forget backup infra - it needs revalidating and rebuilding too, not just production.
- 05Don't declare victory externally too soon - wait for the post-mortem to publish anything definitive.
- 01Actual RTO vs target - the headline KPI of this phase, and the board will ask about it.
- 02Backup integrity: verify against IoCs and behavioural signatures before restoring anything.
- 03Re-attempts to gain access in the first 30 days after public disclosure - almost guaranteed.
Review & Improvements
Thirty to ninety days after recovery: a blameless review, ideally facilitated by an external party. The output is a board-grade document, a concrete roadmap with owners and budget, and an honest conversation about the insurance policy.
- 01Blameless post-mortem, facilitated externally where possible - focus on system, not people.
- 02Full timeline with timestamps, decisions and costs - no interpretations, no euphemisms.
- 03Action items with named owners, dates and success metrics - not "we should improve detection".
- 04Share findings via ISAC, sector regulator or CERT - the industry learns and your peers reciprocate.
- 05Review the policy against actual cost: limits, sub-limits, exclusions, retentions - renegotiate early with the PIR in hand.
- 01Don't turn the review into a witch hunt - it kills honesty in every future incident.
- 02Don't close the PIR without explicit action items, deadlines and budget allocated.
- 03Don't keep findings inside the security team - involve business, legal, HR and the board.
- 04Don't assume "it won't happen again" - about 38% of victims are re-attacked.
- 05Don't sign renewal attestations without updating them to reflect the new (and verified) controls.
- 01MTTD / MTTR actual vs target - the baseline maturity metric the board will care about.
- 02Cost delta: direct loss, downtime, reputation, regulatory fines, premium increase.
- 03Action items closed on time ≥ 80% - otherwise the next incident walks the same path.