Refer to the following best practices to help you manage the risk posed by ransomware and support your organization’s coordinated and efficient response to a ransomware incident.

Refer to the following best practices to help you manage the risk posed by ransomware and support your organization’s coordinated and efficient response to a ransomware incident. Apply these practices to the greatest extent possible based on availability of organizational resources.
It is critical to maintain offline, encrypted backups of data and to regularly test your backups. Backup procedures should be conducted on a regular basis. It is important that backups be maintained offline as many ransomware variants attempt to find and delete any accessible backups. Maintaining offline, current backups is most critical because there is no need to pay a ransom for data that is readily accessible to your organization.
Create, maintain, and exercise a basic Cyber Incident Response Plan and associated communications plan that includes response and notification procedures for a ransomware incident. Review available incident response guidance, a resource and guide to:
Phase of a ransomware incident | What to do | Who decides |
|---|---|---|
Detection | Confirm it is ransomware, record the time, capture the ransom note and affected hosts, keep systems powered for forensics | On-call engineer, escalating to the IR lead |
Containment | Isolate affected hosts, disable compromised accounts, block the initial access path (exposed RDP, phished account, MSP connection) | IR lead |
Notification | Engage breach counsel and forensics retainer, notify the cyber insurer, log customer and regulator deadlines | Executive sponsor with counsel |
Ransom decision | Weigh backup integrity and restore time, whether data was exfiltrated, sanctions exposure, insurer position, and that payment guarantees neither working keys nor deleted data | CEO or Board, advised by counsel and forensics, never IT alone |
Eradication | Find the precursor malware and persistence, reset credentials, rebuild from gold images rather than cleaning in place | IR team with forensics firm |
Recovery | Restore from offline backups in critical asset order, verify before reconnecting, monitor for re-entry | IR lead with system owners |
Review | Document timeline, root cause, cost and control gaps, update the plan, schedule the next tabletop | Executive sponsor |
Ensure antivirus and anti-malware software and signatures are up to date. Additionally, turn on automatic updates for both solutions. We recommend using a centrally managed antivirus solution. This enables detection of both “precursor” malware and ransomware.
Not every control in this post applies to every SaaS company. Much of the hardening guidance targets Windows domains: SMB, RDP, PowerShell logging, AppLocker and Active Directory groups.
If your company is cloud-native, runs on managed Linux containers and issues macOS laptops, those sections are not your priority. Your ransomware exposure sits in cloud consoles, CI/CD pipelines, SaaS admin accounts and object storage, and the relevant controls are MFA on every privileged identity, immutable or versioned backups of production data stores, restricted service account permissions and monitoring of API keys. Gold images matter less when infrastructure is rebuilt from code, but only if the code repository is backed up outside the primary cloud account.
If an MSP manages your endpoints, do not duplicate their tooling; get their coverage in writing and test a backup restore yourself. And a small team does not need a 40-page incident response plan. One page naming who isolates systems, who calls counsel and who decides on payment, tested once a year, beats a long document nobody has read.
Our diverse industry experience and expertise in AI, Cybersecurity & Information Risk Management, Data Governance, Privacy and Data Protection Regulatory Compliance is endorsed by leading educational and industry certifications for the quality, value and cost-effective products and services we deliver to our clients.

.png?u=https%3A%2F%2Fimages.ctfassets.net%2Fbicx998lc6bb%2Fh6BIYQP7ZmOkVaY0NvVgJ%2F8ce3033e0a6855577f61bc35b19a38f1%2Fblog4-4__1_.png&a=w%3D152%26h%3D107%26fm%3Dpng%26q%3D100&cd=2024-03-05T22%3A38%3A25.353Z)