Research · Explainer

Ransomware Incident Response Basics: What to Do in the First 24 Hours

CISA defines ransomware as malware built to encrypt files and render systems unusable — increasingly paired with data theft. This guide distills the #StopRansomware Guide into what to have ready before an incident and what to do when one lands.

Homeland Security Secretary Alejandro Mayorkas at a CISA Infrastructure Security Division ceremony at DHS headquarters, Washington, D.C., February 2024.
Homeland Security Secretary Alejandro Mayorkas at a CISA Infrastructure Security Division ceremony at DHS headquarters, Washington, D.C., February 2024. CISA’s #StopRansomware Guide is the federal baseline for preparing and responding to ransomware.

Photo: DHSgov, Public domain, via Wikimedia Commons

The worst time to write an incident response plan is during an incident. This guide is grounded in the CISA #StopRansomware Guide — the September 2023 update to the September 2020 CISA/MS-ISAC Ransomware Guide — and covers the two things that matter most: what to prepare now, and what to do in the first 24 hours.

Prepare now: backups and a plan

CISA’s first preparation directive is unambiguous: “Maintain offline, encrypted backups of critical data, and regularly test the availability and integrity of backups.” Offline matters because modern ransomware encrypts everything it can reach, including network-connected backups. Untested backups are hope, not strategy.

The second directive: “Create, maintain, and regularly exercise a basic cyber incident response plan (IRP) and associated communications plan.” A plan that has never been exercised will fail on contact with a real incident — roles, call trees, and out-of-band communications channels need rehearsal.

The first 24 hours: contain and preserve

When ransomware is discovered, the guide’s response checklist centers on a few essentials:

  • Isolate affected systems — take them off the network to stop lateral spread, but do not wipe or reimage them before evidence is collected.
  • Secure backups — verify they are disconnected from the affected environment and intact.
  • Collect and secure logs and evidence — firewall, endpoint, and access logs become the timeline investigators will need.
  • Do not destroy forensic artifacts — wiping machines to “start fresh” destroys the evidence law enforcement and incident responders need.
  • Engage incident response — internal team, retained responders, or both.
A second view of the CISA Infrastructure Security Division ceremony at DHS headquarters, Washington, D.C., February 2024.
A second view of the CISA Infrastructure Security Division ceremony at DHS headquarters, Washington, D.C., February 2024. Federal guidance advises contacting the local FBI field office to establish points of contact before an incident occurs.

Photo: DHSgov, Public domain, via Wikimedia Commons

Who to call

CISA advises contacting the local FBI field office to establish points of contact before an incident — ideally during preparation, not at 3 a.m. with systems down. Breach-notification procedures must follow applicable state laws, and where personal data is involved, affected individuals must be notified with the type of information exposed and the remediation steps being taken. Cyber incidents can also be reported through CISA’s incident-reporting channels and to the FBI’s Internet Crime Complaint Center (IC3).

On paying the ransom

Federal guidance discourages paying the ransom: payment does not guarantee decryption, funds further criminal activity, and does not erase data that was exfiltrated. Organizations should consult the #StopRansomware Guide’s own language on this decision and engage law enforcement rather than treating payment as a recovery strategy.

Stop the next one: initial-access hygiene

The same guide addresses how ransomware most often gets in: do not expose RDP or other remote services directly to the internet, patch internet-facing systems promptly, and require multi-factor authentication on VPN and remote access. Most campaigns still enter through the front door left open.

What you can do today

  • Verify at least one offline, encrypted backup exists and has been restored-tested recently.
  • Review the incident response plan: named roles, out-of-band communications, and a call list that includes the local FBI field office.
  • Confirm MFA is enforced on VPN and all remote-access paths, and that internet-facing systems are patched.
  • Read the CISA #StopRansomware Guide itself — this summary is a starting point, not a substitute.

No corrections have been published for this article.

About the author

Owen Barrett, Editor-in-Chief — beat: threat intelligence & breaking news.