An active ransomware incident is a containment and investigation emergency: isolate affected systems, preserve evidence, activate the response team, and stop further spread or data theft. Do not rush to pay the ransom or restore from backups before the environment has been investigated and contained.

The response has six priorities:

  1. Contain the spread
  2. Preserve forensic evidence
  3. Activate technical, legal and business response teams
  4. Determine the full scope, including possible data theft
  5. Remove the attacker and close the entry point
  6. Recover critical services from verified clean backups

This guidance was checked against CISA, FBI and NIST materials on September 20, 2026. CISA, the FBI and NIST all emphasise containment, coordinated incident response, evidence preservation, reporting and controlled recovery.

Active Ransomware Incident Response Checklist

Priority Action Main Objective
1 Isolate affected devices, servers, subnets and cloud resources Stop encryption, lateral movement and further data theft
2 Switch to out-of-band communication Prevent attackers from monitoring response activity
3 Preserve memory, logs, images and ransom communications Support investigation, recovery and law enforcement
4 Engage incident response specialists, legal counsel and cyber insurance Coordinate technical and business decisions
5 Report the incident to appropriate authorities Obtain assistance and support a potential investigation
6 Rebuild and restore critical services on a clean network Resume operations without reinfecting systems
7 Evaluate ransom demands only after investigation Avoid an uninformed or legally risky payment decision

1. Isolate Affected Systems Immediately

Disconnect compromised workstations, servers and other devices from the network. Remove them from Wi-Fi, unplug Ethernet cables or isolate affected subnets at the switch level. If several systems are affected, taking a network segment offline may be safer than disconnecting devices one at a time.

For cloud environments, take snapshots of affected volumes where possible. Investigators can use these point-in-time copies during the analysis. Prioritise systems that support health, safety, revenue generation or other essential operations.

Use phone calls or another trusted out-of-band channel for incident coordination. Attackers may monitor email, collaboration platforms or internal communications. They may also speed up their activity if they realise the organisation is responding.

Should You Shut Down Infected Computers?

If network isolation is possible, do not power off an affected device as your first action. A shutdown can destroy volatile evidence stored in memory.

If a device cannot be disconnected and remains capable of spreading ransomware, power it down to limit further damage. CISA treats shutdown as a fallback when network isolation is not possible.

2. Activate the Incident Response Team

Declare a formal cybersecurity incident and appoint one incident commander. The response normally includes:

  • Internal IT and security teams
  • A qualified digital forensics and incident response provider
  • Legal counsel experienced in data breaches
  • The cyber insurance carrier and its approved response vendors
  • Executive leadership
  • Communications or public affairs staff
  • Technology and service providers
  • Law enforcement, where appropriate

Do not let multiple teams make uncoordinated changes to systems. Maintain a written incident timeline that records decisions, actions, affected assets and evidence collected.

Legal, regulatory and contractual requirements can affect how the organisation investigates, communicates and reports the incident. NIST recommends identifying these requirements as part of ransomware response and recovery planning.

3. Preserve Evidence Before Wiping or Rebuilding

Do not immediately reimage every encrypted computer or delete the ransom note. Preserve a representative sample of affected systems and collect evidence such as:

  • System images
  • Memory captures
  • Endpoint detection and response alerts
  • Windows Security and authentication logs
  • Firewall, VPN and identity-provider logs
  • Cloud audit logs
  • Ransom notes and attacker communications
  • Suspicious files, scripts and malware samples
  • Known command-and-control addresses
  • File extensions and encryption indicators
  • Evidence of unauthorised account creation or privilege escalation

CISA recommends preserving highly volatile evidence, including system memory, Windows Security logs and firewall log buffers. This evidence may help identify the initial access method, determine whether data was stolen and support recovery or law enforcement activity.

4. Determine the Full Scope of the Compromise

A ransomware event may involve more than encrypted files. Investigators should establish:

  • Which endpoints, servers, applications and cloud resources were affected
  • Whether domain controllers or privileged accounts were compromised
  • Whether attackers accessed email, VPN, remote desktop or single sign-on systems
  • Whether backups were deleted, encrypted or altered
  • Whether data was exfiltrated before encryption
  • How long the attackers had access
  • Which vulnerabilities, credentials or remote services enabled the intrusion
  • Whether persistence mechanisms remain in the environment

Review endpoint, network, identity and cloud telemetry together. CISA warns that ransomware may be the final stage of an earlier compromise. Look for precursor malware, lateral movement and suspicious activity involving privileged accounts.

Treat the incident as a potential data breach until the investigation establishes otherwise. Data extortion can occur before, during or independently of file encryption.

5. Report the Ransomware Incident

In the United States, organisations should consider reporting the incident to:

  • The local FBI field office
  • The FBI Internet Crime Complaint Center, known as IC3
  • CISA
  • The U.S. Secret Service, where appropriate
  • Relevant sector-specific authorities
  • State or local law enforcement, where appropriate

CISA states that organisations should report ransomware incidents and may request federal assistance. The FBI directs ransomware victims to contact a local field office or file a report with IC3.

Notify customers, employees, regulators, partners or other affected parties only through an approved communications process. Legal counsel should help determine whether notification duties apply and what information can be disclosed safely.

6. Contain and Remove the Attacker

After initial isolation and evidence collection, the incident response team should remove the attacker's access and address the weakness that enabled the intrusion. Depending on the investigation, this may include:

  • Disabling compromised VPN and remote-access services
  • Containing affected single sign-on and cloud accounts
  • Removing malicious persistence mechanisms
  • Disabling known ransomware binaries
  • Rotating compromised passwords, tokens, keys and certificates
  • Resetting affected privileged accounts
  • Patching the exploited vulnerability
  • Rebuilding compromised systems from trusted images
  • Improving endpoint and network monitoring
  • Blocking known attacker infrastructure

CISA recommends identifying compromised systems and accounts, containing remote-access and public-facing assets, rebuilding essential services and issuing password resets after the environment has been cleaned and rebuilt.

Do not assume the incident is over because file encryption has stopped. Attackers may still have access, maintain persistence or have left other malware in the environment.

7. Verify Backups Before Restoring

Do not restore from a backup simply because it is available. Confirm that the backup:

  • Predates the attacker's access or destructive activity
  • Has not been encrypted or tampered with
  • Does not contain the original malware or persistence mechanism
  • Can be restored successfully
  • Contains the required business data
  • Has suitable access controls

NIST states that the integrity of backups and other restoration assets should be verified before they are used for recovery. Begin with essential services on a clean, controlled network rather than reconnecting the entire environment at once.

Prioritise systems based on:

  • Health and safety
  • Revenue
  • Legal obligations
  • Operational dependency
  • Customer impact

Monitor restored systems closely for renewed suspicious activity.

Should You Pay the Ransom?

Do not pay the ransom automatically or make the decision without legal, technical and executive review.

The FBI does not support paying a ransom because payment does not guarantee that files will be restored or that stolen data will not be published. CISA also recommends consulting law enforcement about possible decryptors, because tools may exist for some ransomware variants.

Before making a payment decision, assess:

  • Whether clean backups can restore operations
  • Whether a working decryptor exists
  • Whether data was exfiltrated
  • Whether payment could violate sanctions or other legal restrictions
  • Whether the attacker has retained access
  • Whether the ransom demand is credible
  • Whether cyber insurance covers payment or negotiation
  • Whether payment would create further security or reputational risks

A ransom payment does not remove the attacker or resolve the breach. The organisation still needs to remove attacker access, rebuild systems and investigate what happened.

Common Mistakes During an Active Ransomware Incident

Avoid these actions:

  • Wiping every affected system immediately, which can destroy evidence.
  • Using compromised email or chat accounts to coordinate the response.
  • Restoring backups before removing the attacker, which can lead to reinfection.
  • Assuming only encrypted systems are affected, while ignoring identity, cloud and backup systems.
  • Reconnecting systems because encryption appears to have stopped.
  • Paying immediately under pressure without legal, insurance and law enforcement input.
  • Changing systems without documenting what changed, which makes the investigation more difficult.
  • Allowing multiple teams to send conflicting information to employees, customers or the media.

If Your Organisation Lacks Incident Response Expertise

Engage a qualified digital forensics and incident response provider immediately. Your managed service provider or managed security service provider may assist, but general IT support is not always equipped to preserve forensic evidence or determine whether an attacker still has access.

CISA provides ransomware response guidance and federal assistance channels. The FBI can support reporting and criminal investigation.