Why You Need a Plan Before You Need It

The middle of a ransomware incident is the worst possible time to make decisions about who to call, whether to pay, and how to communicate with customers and regulators. Organizations without a plan make these decisions under panic conditions, with limited information, while trying to manage operational chaos. The result is almost always worse outcomes than organizations with a documented, tested response plan. A ransomware response plan is not a luxury. It is a core operational document for any business that depends on its IT systems.

Core Elements of a Ransomware Response Plan

  • Incident identification and declaration — Who determines that an incident is a ransomware event, and what is the threshold for activating the response plan?
  • Escalation chain — Who is called, in what order, and what are their responsibilities? This must include after-hours contact information that is stored off the potentially-encrypted network.
  • Containment procedures — Step-by-step procedures for isolating systems, documented in a way that non-technical managers can execute if IT staff are unavailable.
  • External contacts — Cyber insurance carrier, legal counsel, IR retainer firm, FBI, state regulators. All contact information stored offline and off-network.
  • Payment decision authority — Who has the authority to authorize a ransom payment? What is the process, including OFAC check and legal review?
  • Communication templates — Pre-drafted communications for employees, customers, regulators, and the board. Reviewed by legal counsel in advance.
  • Recovery procedures — How systems are rebuilt, in what order, and what must be verified before systems are returned to production.

Store Critical Documentation Offline

This cannot be overstated: your response plan, contact lists, and recovery procedures must exist somewhere that is not accessible from your production network. A ransomware attack that encrypts your document management system also encrypts your response plan if it is stored there. Print copies, secure USB drives, or a completely separate cloud environment with separate credentials are all viable options.

Test Your Plan with a Tabletop Exercise

A ransomware response plan that has never been tested is significantly less effective than one that has. A tabletop exercise — a structured scenario walkthrough with your response team — identifies gaps in the plan, clarifies roles and responsibilities, and builds the muscle memory that matters under pressure. Most organizations that conduct tabletop exercises find at least three significant gaps in their plan. Better to find them in a conference room than during an incident.

Combining response planning with penetration testing

Grid32's network penetration tests identify the entry points an attacker would use against your environment, giving your response plan more realistic scenarios to prepare for.

Talk to an Expert →