Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
Ransomware response checklist
Updated
Isolate ransomware hosts without wiping them. Identify the strain, assess backups, and treat payment as a counsel, insurer, and OFAC sanctions-risk question — not a recommendation. Report to CISA and law enforcement. This page is not legal advice.
Operational guidance, last verified 7 September 2026 against the CISA / FBI / NSA / MS-ISAC #StopRansomware Guide (Joint Ransomware Task Force; revision date 19 October 2023 — guidance, not a statute), CISA's I've Been Hit By Ransomware page, FBI Internet Crime Complaint Center (IC3) intake, the U.S. Treasury OFAC Advisory on Potential Sanctions Risks for Facilitating Ransomware Payments (updated 21 September 2021 — an OFAC advisory, not a determination that a payment is lawful or unlawful on YOUR facts), and ENISA's Threat Landscape for Ransomware Attacks (29 July 2022 — agency landscape, not a law). This page does not recommend paying and does not recommend not paying. It does not rank DFIR firms, decryptors, or identification services, does not start a notification clock, and is not a substitute for counsel, your insurer, or a retained DFIR firm. Not legal advice. Not sanctions advice.
Isolate, do not wipe — this is not a statute
Audience: the incident commander facing encryption or a ransom note, and counsel, the insurer, and DFIR on the out-of-band bridge. The we've-been-breached page on this site is the first-moves hub. The first-15-minutes page on this site is the do-not-power-down checklist. The never-delete-after-breach page on this site is the do-not-destroy list. The preserve-evidence page on this site is the capture order. This page is the ransomware scenario runbook: isolate without destroying evidence, identify the strain within limits, assess backups, walk recovery-versus-payment as a counsel + insurer + OFAC risk question, and report. It does not rank vendors, does not name any, and does not start a notification clock.
The #StopRansomware Guide is Joint Ransomware Task Force guidance — CISA, FBI, NSA, and MS-ISAC — last verified still the current guide on 7 September 2026 (landing-page revision date 19 October 2023). CISA's I've Been Hit By Ransomware page is the short operational list: isolate infected systems from the network; do not power off if you can isolate, because volatile memory holds ransomware artifacts. NIST SP 800-61r2 sequences containment, then eradication, then recovery — guidance, not a statute. Reimaging, restoring over the original, or 'just rebuilding' before a forensic image exists is eradication dressed as containment. Last verified 7 September 2026. Not legal advice.
- Isolate first. Network cable, Wi-Fi, VLAN, cloud security group — take the encrypted host and the likely-affected path off the production network. Leave power on.
- Do not wipe, reimage, restore over the original, or run a 'clean and delete' on the evidence copy. Isolate, do not destroy. The never-delete-after-breach page on this site is that prohibition list.
- Power-off is last resort, not first instinct. CISA ransomware guidance allows it only when you cannot isolate from the network, and it states that the step costs you volatile-memory artifacts. Record that exception if you take it.
- Do not tip the actor. No in-band 'we see you', no public status page, no mass password reset from a possibly compromised identity plane. CISA: actors watch the response.
- This page does not rank DFIR firms, does not interpret YOUR policy, does not start a notification clock, and is not legal advice.
What to do now
Walk top to bottom. Unknowns belong on the list. The who-to-call page on this site is the contact order. The contact-cyber-insurance page on this site is notify-before-panel-vendors. Last verified 7 September 2026. Not legal advice.
- Declare the incident. Name one commander. Open an out-of-band bridge the actor cannot see (phone, a clean conference).
- Isolate encrypted and suspected-encrypted hosts from the network. Leave them powered on. Do not wipe.
- Place the evidence hold in writing: no reimage, no log rotation, no mailbox purge, no 'cleanup' of the ransom note or samples. The preserve-evidence page on this site is the capture list.
- Take backup infrastructure further offline so the actor cannot encrypt the copies you still have. Do not connect backup media to an infected host to 'see if it restores'.
- Page counsel and the cyber insurer now if YOUR plan or policy requires prompt notice. Unilateral decryptor shopping can be a coverage and sanctions problem later. This page does not interpret YOUR policy.
- Identify the strain from the ransom note, file extension, and hashes you already have — not by uploading victim files to a random site. CISA #StopRansomware joint CSAs name variants. This product does not identify a strain.
- Assess backups against the table below. Recovery from known-good, isolated, predating-first-access copies is the operational recovery path this checklist walks.
- Walk the recovery-versus-payment tree with counsel and the insurer. This page does not recommend paying and does not recommend not paying. OFAC screening is their question, not this page's.
- Report to CISA (cisa.gov/report) and file an FBI IC3 complaint (ic3.gov). Those are reporting pointers, not a determination that a filing duty has started. Counsel maps YOUR duties.
Identify the strain — limits, not a ranking
A strain name helps responders find the right CISA #StopRansomware advisory and tells DFIR what artifacts to look for. It is not a determination that a decryptor exists, that a payment would work, or that a notification duty has started. This page does not rank identification services and does not name any. Last verified 7 September 2026. Not legal advice.
| What you already have | What it can tell you | Limit |
|---|---|---|
| Ransom note (filename, text, contact method, wallet if shown) | Family-level clues. Keep the note under the evidence hold. Photograph or copy; do not delete it to tidy the desktop. | A note is not proof of who the actor is. Do not contact the address on the note from a production identity. |
| Encrypted-file extension, dropped binaries, hashes | Enough to match a public #StopRansomware joint CSA if one exists for that family. | This product does not identify a strain. Hash lookup is not a forensic exam. Do not upload victim data to an unknown site as your first move. |
| CISA #StopRansomware joint CSAs and StopRansomware.gov | USG technical write-ups of named variants (prevention, detection, response). Guidance, not a statute. | Absence of a CSA for YOUR extension is not a conclusion that the strain is new. DFIR still images. |
| What you do not have yet | Memory image, disk image, C2, initial-access path. Those sit on the preserve-evidence page on this site. | Do not delay isolation to finish identification. Isolate first. Name the strain while the hold is in force. |
Assess backups
Recovery from known-good backups is how most organizations restore without a payment conversation. Assessment is whether the copies you have are actually usable — isolated, predating first access, and restorable — not a feeling that 'we have backups.' CISA's #StopRansomware Guide treats offline, encrypted, tested backups as prevention practice (including the 3-2-1 pattern: three copies, two media types, one offsite). During response, the question is whether those copies survived. ENISA's ransomware landscape likewise treats isolated backups as resilience, not as a filing. This product does not assess YOUR backups. Last verified 7 September 2026. Not legal advice.
| Check | What 'usable' looks like | Do not restore yet if |
|---|---|---|
| Copies exist | Named stores, dates, and owners. Production, a second medium, and an offsite or immutable copy if you had one. | The only copy is on the encrypted volume, or nobody can point at the store. |
| Isolated from the infected network | Offline, object-lock / immutable, or otherwise unreachable from the hosts that are encrypting. You took them further offline in the first moves. | The backup server is still on the same network as the actor, or you are about to mount the tape on an infected host. |
| Predate first access / encryption | The restore point is before the earliest encryption or first-access mark on the timeline. Unknown first-access means you treat the newest backups as suspect until DFIR says otherwise. | The snapshot is from inside the dwell window, or you have not looked. |
| Restore-tested, keys in YOUR control | You can restore a sample to a clean, isolated target. Backup encryption keys are not sitting on the encrypted estate. | You have never restored, the catalog is encrypted, or the keys are in the same vault the actor reached. |
| Originals still held | The compromised hosts stay imaged and under hold. Restoring production is not permission to wipe the exhibit. The document-containment-recovery page on this site is the recovery-validation checklist. | Someone is 'cleaning up' the encrypted volume because a restore is in progress. |
Recovery versus payment — a risk question, not a recommendation
This page does not recommend paying a ransom and does not recommend not paying. Recovery from known-good, isolated backups is the operational path the checklist walks. Whether a payment would be lawful, would violate OFAC sanctions, would affect insurance coverage, or would actually decrypt anything is a question for counsel, your insurer, and OFAC screening on YOUR facts. Not legal advice. Not sanctions advice. Not coverage advice. Last verified 7 September 2026.
OFAC's Advisory on Potential Sanctions Risks for Facilitating Ransomware Payments (updated 21 September 2021; still listed as current on OFAC's cyber-related sanctions page on 7 September 2026) alerts companies that facilitating ransomware payments can carry sanctions risk, including where a sanctioned person is involved. That is an OFAC advisory — risk information — not a determination that YOUR facts are a violation, not a license, and not this page's advice. Counsel screens counterparties, wallets, and facilitators. This page does not.
- This page does not tell you to pay. This page does not tell you not to pay.
- A payment decision is not a containment decision. Isolation and the evidence hold stay in force either way.
- Decryptors, brokers, and 'negotiators' are vendors. This page does not rank them and does not name any.
- CIRCIA will require covered entities to report covered incidents and ransomware payments once the final rule is in effect. Last verified 7 September 2026: the CIRCIA final rule is not in effect; CISA is still in rulemaking. Do not treat a CISA or IC3 report as that future duty.
| Question | If yes | If no or unknown |
|---|---|---|
| Are backups usable (isolated, predating first access, restore-tested, keys in YOUR control)? | Recover from those copies after a forensic image exists. Payment is not required for this operational path. The document-containment-recovery page on this site is the eradicate-before-restore checklist. | Do not mount backup media on an infected host. Stay isolated. Bring counsel and the insurer onto the bridge before anyone talks to the actor. |
| Are counsel and the insurer on the out-of-band bridge? | They own legality, coverage conditions (including panel-vendor rules), and OFAC screening. The contact-cyber-insurance and contact-breach-counsel pages on this site are those checklists. This page does not interpret YOUR policy. | Page them. Unilateral negotiation, a decryptor from a random site, or a payment facilitator you have not screened is how coverage and sanctions risk both get worse. That is risk, not a ruling. |
| Has counsel screened OFAC / sanctions exposure on any proposed payment path? | Counsel's call on YOUR facts. OFAC's advisory is the risk document they will already know. This page is not sanctions advice and does not run a screening. | Do not treat a decryption tool or a wallet from the actor as a clean recovery. Do not assume 'we are the victim' removes sanctions risk. Ask counsel. This page does not recommend a path. |
| Would a payment actually restore the estate? | Even a working decryptor is not a forensic image, not eradication, and not a reason to skip the hold. Actors re-extort. This is not a recommendation to pay. | Paying does not guarantee decryption. That observation is in USG ransomware guidance as a fact about outcomes, not a recommendation from this page. Recover what you can from known-good media; rebuild what you cannot. |
Report — CISA, FBI IC3, law enforcement
Reporting is how USG and law-enforcement channels get the strain, the wallet, and the infrastructure. It is not a GDPR Article 33 notice, not a CRA Article 14 filing, and not a determination that any of those duties apply. Counsel maps YOUR clocks. Last verified 7 September 2026. Not legal advice.
- Report even if you are going to recover from backups. Intake is not a payment decision.
- Do not treat a CISA report or an IC3 complaint as a GDPR, CRA, US-state, or CIRCIA filing. Counsel maps YOUR duties.
- This product does not file with IC3, CISA, OFAC, or a regulator.
| Where | What it is | Kind of source |
|---|---|---|
| CISA — cisa.gov/report (report@cisa.gov, 1-844-Say-CISA) | CISA asks every organization that experiences a cyber incident to report it. #StopRansomware and I've Been Hit By Ransomware point responders here. | Operational ask and voluntary sharing today for most operators. Not a statute that files a notice for you. CIRCIA mandatory reporting is not in effect as of 7 September 2026. |
| FBI IC3 — ic3.gov | The Internet Crime Complaint Center is FBI intake for cyber-enabled crime, including ransomware. File a complaint. IC3 does not guarantee a response to every complaint. | Law-enforcement complaint intake. Not a regulator filing. Not this product filing on your behalf. |
| FBI field office / local law enforcement | The who-to-call page on this site is the contact map. Field offices are listed on fbi.gov. Immediate danger is 911 / local police, not IC3. | Law enforcement. Counsel coordinates. This page does not page them for you. |
| MS-ISAC (US SLTT) | The #StopRansomware Guide is co-authored with MS-ISAC. State, local, tribal, and territorial entities have that channel. | Sharing community for that sector. Not a ranking. Not a duty this page applies to you. |
| EU / other jurisdictions | ENISA's ransomware landscape and Cyber First Aid point to national CSIRTs and police. GDPR Article 33, NIS2, and CRA Article 14 are legal requirements only when they apply. | Agency guidance vs statute. Confirm with counsel. This page does not start a clock. The first-72-hours page on this site walks clocks that may apply. |
Where this shows up in ShipReady Metrics
The signed-in app does not detect ransomware, identify a strain, assess backups, decide whether to pay, screen OFAC, isolate a host, or file with IC3, CISA, or a regulator. It does not rank DFIR firms, decryptors, or identification services. The cyber risk register lives under Security and includes a ransomware library item — a risk you can record, not a detector. Security findings is where open vulnerabilities, remediation, and KEV / EPSS / CVSS ranking live; a CISA KEV 'known ransomware campaign' flag on a finding is a catalog attribute of a CVE, not strain identification and not a detection that you are being encrypted. If you already have a session: signed-in app → Compliance → CRA reporting tracks the 24-hour / 72-hour / 14-day ladder from your recorded awareness for findings the org has classified as CRA-in-scope. That ladder is not a ransomware runbook, it does not start a clock for you, and it is not a determination that CRA applies. A named human still submits. None of those surfaces isolates a host, restores a backup, or files with IC3.
Primary sources (last verified 7 September 2026)
Every operational claim on this page is taken from one of these. If a later revision of a source changes the advice, the date above is how you can see we have not re-checked yet.
CISA, FBI, NSA, and MS-ISAC, #StopRansomware Guide (Joint Ransomware Task Force; landing-page revision date 19 October 2023) remains the current USG one-stop ransomware prevention and response guide this page cites — guidance, not a statute, last verified still current on 7 September 2026. CISA's I've Been Hit By Ransomware page is the short isolate-and-report list; CISA's report path is cisa.gov/report. FBI IC3 (ic3.gov) is complaint intake for cyber-enabled crime. OFAC, Advisory on Potential Sanctions Risks for Facilitating Ransomware Payments (updated 21 September 2021), remains listed as current on OFAC's cyber-related sanctions page on 7 September 2026 — an advisory about sanctions risk, not a determination on YOUR facts, not legal advice, and not sanctions advice from this page. ENISA, Threat Landscape for Ransomware Attacks (29 July 2022), is agency landscape and resilience guidance (including isolated backups), not a law. NIST SP 800-61r2 remains the current final Computer Security Incident Handling Guide this cluster cites for containment then eradication then recovery. CIRCIA ransomware-payment reporting: last verified 7 September 2026, the final rule is not in effect.
Frequently asked questions
What should we do first in a ransomware attack?
Isolate encrypted hosts from the network and leave power on. Place the evidence hold. Take backups further offline. Page counsel and the insurer. Identify the strain from the note, extension, and hashes you already have. Assess whether backups are usable. Report to CISA and FBI IC3. Do not wipe, reimage, or tip the actor. CISA's I've Been Hit By Ransomware page and the #StopRansomware Guide are the primary operational sources. Not legal advice.
Should we pay?
This page does not recommend paying and does not recommend not paying. Recovery from known-good, isolated backups is the operational recovery path the checklist walks. Whether a payment would be lawful, would violate OFAC sanctions, or would affect coverage is a question for counsel, your insurer, and OFAC screening on YOUR facts. OFAC's advisory (updated 21 September 2021, last verified 7 September 2026) warns of potential sanctions risks for facilitating ransomware payments. That is a risk, not legal advice and not sanctions advice.
Is this legal advice?
No. It is operational guidance distilled from the CISA #StopRansomware Guide, CISA's I've Been Hit By Ransomware page, FBI IC3, OFAC's ransomware-payments advisory, ENISA's ransomware landscape, and NIST SP 800-61r2. Whether a payment is lawful, whether sanctions apply, whether coverage responds, and whether a notification duty has started are questions for counsel on YOUR facts. This page is not sanctions advice, not coverage advice, does not rank vendors, and does not start a notification clock.
Does isolating a ransomware host mean we can reimage it?
No. Isolation is containment: take the host off the production network so encryption cannot spread, while the evidence stays. Reimaging before a forensic image exists is eradication dressed as containment. CISA ransomware guidance treats power-off and rebuild as last resorts because they destroy volatile evidence. The never-delete-after-breach page on this site is the do-not-destroy list. Not legal advice.
Does ShipReady Metrics detect ransomware, identify the strain, assess backups, or file with IC3?
No. The signed-in app does not detect ransomware, identify a strain, assess backups, decide whether to pay, screen OFAC, or file with IC3, CISA, or a regulator. It does have a cyber risk register under Security (including a ransomware library item — a recorded risk, not a detector), Security findings with KEV / EPSS / CVSS ranking, and Compliance → CRA reporting (the Article 14 24-hour / 72-hour / 14-day ladder from recorded awareness for CRA-in-scope findings). A KEV 'known ransomware campaign' flag is a CVE catalog attribute, not strain ID. Not legal advice.
Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.