What is a ransomware response playbook? It is a pre-documented sequence of decisions and actions – covering containment, authority, communications, and regulatory notification – that an organisation executes in the hours immediately following a ransomware detection.
Sophos reports that average recovery costs from ransomware in 2024, excluding the ransom itself, reached USD 2.73 million, while average downtime was 22 days and only 56% of organisations that paid recovered all their data (Sophos State of Ransomware 2024). The playbook is not paperwork – it is the difference between a contained crisis and a month of operational improvisation.
Ransomware response – at a glance:
- Sophos 2024: only 56% of organisations that paid a ransom recovered all their data – payment is not a reliable recovery strategy
- IBM 2024: average breach lifecycle is 194 days to identify and 64 days to contain – the first hour’s decisions determine how bad the next three months will be
- UK GDPR / GDPR Article 33: if personal data is affected, the supervisory authority must be notified without undue delay and, where feasible, within 72 hours of becoming aware
- NIS2 Article 23: early warning within 24 hours; full incident notification within 72 hours; final report within one month – for covered entities
- PCI DSS Requirement 12.10: incident response plans must be documented and tested before the incident, not improvised during it
- Do not reboot, wipe, restore from backup, or pay in the first hour – these actions destroy forensic evidence and can worsen the incident
- The recommended restoration sequence: identity and admin access first, then core communications, then revenue-critical platforms, then regulated data platforms, then general productivity systems
Table of Contents
| Time window | Primary objective | Key decisions | What not to do |
|---|---|---|---|
| H+0–1 | Detect and contain | Isolate affected endpoints and accounts; preserve evidence; assess whether spread is active | Do not reboot, wipe, restore, or pay |
| H+1–4 | Activate and assess | Stand up the incident team; engage legal, IR firm, insurer; assess scope and exfiltration risk | Do not speculate publicly; do not let each team invent its own process |
| H+4–24 | Communicate and decide | Prepare regulatory, board, customer, and insurer communications; decide on negotiation posture | Do not make payment decisions without legal and sanctions review |
| H+24–72 | Recover and notify | Restore in sequence; notify regulators where required; preserve forensic artefacts | Do not reconnect restored systems without validation |
What should you do in the first hour after detecting ransomware?
The first hour is the highest-leverage window in the entire incident. The goal is not to understand everything – it is to stop the infection spreading, preserve evidence, and avoid destructive mistakes. Most organisations lose critical time trying to diagnose before they contain.
Immediate action sequence:
- Confirm the signal. Establish whether you are looking at ransomware execution, pre-encryption lateral movement, or a false positive.
- Contain affected systems. Isolate workstations, servers, privileged accounts, and remote access paths that appear involved. If you have EDR, use the containment function.
- Preserve logs and artefacts. Capture volatile evidence. Preserve SIEM, EDR, authentication, VPN, and firewall logs.
- Protect backups. Verify that backup repositories are isolated from the production estate.
- Open an incident record. Timestamp every action, decision, and evidence source from the first confirmed alert onward.
Do not reboot encrypted systems. Do not wipe endpoints. Do not start restoring from backup. Do not pay. FBI and other law-enforcement guidance remains clear: organisations should not pay before consulting law enforcement, legal counsel, and specialist responders – because payment does not guarantee recovery and may create sanctions exposure if the recipient is a designated actor.
How should you activate your incident response team in hours one to four?
Once containment is underway, the company needs a command structure. A ransomware incident now touches legal, regulatory, customer, operational, insurance, and reputational risk simultaneously. Activate the incident response team formally – it should include the incident commander, technical lead, legal counsel, executive sponsor, communications owner, business continuity lead, and a single note-taker. If you have a pre-agreed external IR partner, engage them now. Pre-negotiated retainers reduce the time lost in procurement and contracting during the worst possible hour.
Notify your cyber insurer at this stage. Many policies require prompt notification and use of panel firms for legal or forensic support. If you leave this until day two, you risk claims friction or disputes about covered costs.
This is also when you assess scope: which business units, systems, identities, and regions are affected? Is this commodity ransomware with immediate encryption, or a double-extortion event where data theft happened before detonation? If there is evidence of exfiltration, your regulatory and contractual obligations widen immediately.
When must you notify regulators after a ransomware attack affecting personal data?
In the UK and EU context, UK GDPR / GDPR Article 33 requires notification to the supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of a personal data breach. NIS2 adds a faster staged model for covered entities: an early warning within 24 hours, a full incident notification within 72 hours, and later follow-up reporting under Article 23.
The most important practical point: the 72-hour period starts when the organisation becomes aware that a personal data breach has occurred – not when the forensic story is complete. EDPB guidance is clear that notification can be phased if not all information is immediately available. Waiting for perfect certainty is one of the easiest ways to drift into late notification.
Should you pay the ransom? What does the evidence say?
Boards ask this question early because it feels like a shortcut. It usually is not. Sophos reported that only 56% of organisations that paid in 2024 recovered all their data (Sophos State of Ransomware 2024). Even when decryption keys work, recovery is often slow, incomplete, and operationally messy.
There is also a legal layer. Ransom payment can create sanctions risk if the recipient is linked to a designated actor. In the UK, legal counsel needs to review whether payment creates money-laundering implications. In the EU, sanctions exposure also requires legal review. The right operating rule: never decide on payment without legal counsel, forensic advice, executive sign-off, and a documented alternatives analysis.
In what sequence should you restore systems after a ransomware attack?
| Priority | Restore first | Why |
|---|---|---|
| 1 | Identity and admin access | Without trusted identity, every other recovery step is fragile |
| 2 | Core communications and emergency channels | Leadership, IT, legal, and operations need reliable out-of-band coordination |
| 3 | Revenue-critical platforms | ERP, payment gateways, customer support, or manufacturing control systems often drive existential business impact |
| 4 | Regulated data platforms | Personal data and cardholder data environments require controlled, auditable restoration |
| 5 | General productivity systems | E-mail, collaboration, and shared storage return once the core estate is trustworthy |
Preserve forensic images and key logs before large-scale rebuilds where possible. That matters for prosecution, insurer recovery, regulator engagement, and lessons learned. Learn more about PCI DSS incident response requirements and DORA ICT risk obligations.
FAQ
What should you do immediately when ransomware is detected?
Isolate affected systems, preserve evidence, activate the incident commander, and stop the spread before attempting to explain the incident. Do not reboot or wipe machines in the first hour – those actions destroy forensic evidence that affects insurance claims, regulatory engagement, and any potential prosecution.
Should you pay a ransomware demand?
Not until legal counsel, forensic responders, and leadership have reviewed the alternatives, sanctions exposure, and whether clean backups exist. Sophos found that only 56% of organisations that paid in 2024 recovered all their data – payment is not a reliable recovery strategy (Sophos State of Ransomware 2024).
How long does ransomware recovery take?
Sophos reported average downtime of 22 days in 2024. Organisations with clean tested backups, a pre-planned incident structure, and pre-engaged external support recover materially faster than those improvising under pressure.
What are your legal obligations after a ransomware attack in the UK and EU?
If personal data is affected, UK GDPR / GDPR Article 33 may require notification to the supervisory authority within 72 hours of awareness. NIS2-covered entities face a staged reporting model: a 24-hour early warning and a 72-hour full incident notification.
How do you report a ransomware attack to the authorities?
Use your national supervisory authority or ICO process for personal-data impacts, your national CSIRT or competent authority where NIS2 applies, and law-enforcement channels where serious criminal activity or national-security implications exist. Preserve timestamps and keep your written record aligned across all reports.
Does cyber insurance cover ransomware payments?
Sometimes, but never assume it. Policies differ on extortion coverage, business interruption, legal support, panel providers, and sanctioned actors. Always review the policy wording and notify the insurer early — many policies require prompt notification as a condition of coverage.
Ransomware preparedness – free tabletop or playbook review
Patronusec can help you stress-test your ransomware response foundations before an attacker does: IR retainer arrangements, regulatory notification templates, backup testing, and executive decision design.
Book a no-commitment call with our team.