← All playbooks

Incident Playbook

Ransomware & Malware

SIIRF-PB-04Devices and malwareTypical severity: CriticalVersion 1.0 · October 2026

Summary

Malicious software has infected organisational devices, encrypting files, stealing data or disrupting work.

Category
Devices and malware
Typical severity
Critical
Response led by
Incident lead, with technical support and leadership

First 15 minutes

  1. Disconnect affected devices from the network and Wi-Fi, but leave them switched on to preserve evidence.
  2. Photograph the ransom note and any messages on screen.
  3. Don't connect backup drives to any device until it's confirmed clean.

1. Overview

Malware is malicious software that spies on you, steals data or damages your systems. Ransomware is a kind of malware that locks your files and demands payment to unlock them. Many ransomware groups also steal data first and threaten to publish it.

2. How it happens

  • Opening an infected attachment, or clicking "Enable content" in a document.
  • Installing cracked or pirated software, or fake updates.
  • Attackers getting in through unpatched systems or remote access tools with weak passwords.
  • Infected USB drives shared between computers.
  • Once inside, it spreads to shared drives and other devices on the same network.

3. Indicators

Signs that this incident may be happening:

  • Files with strange extensions that won't open.
  • A ransom note on the screen or in folders.
  • Devices suddenly slow, with fans running hard or unknown programs starting.
  • Security software switched off without anyone doing it.
  • Unusual network activity or large uploads.

4. Triage questions

Answer these first to understand scope and severity:

  1. Which devices, shared drives and accounts are affected?
  2. Is the infection still spreading?
  3. Is there a ransom note, and does it claim data was stolen?
  4. Are backups intact, offline and unaffected?
  5. Which work and services are disrupted, and for how long can you cope?

5. Severity guide

Use your plan's severity levels. As a guide for this incident:

LevelTypical situation
LowA single device infected with adware or a potentially unwanted program, removed.
MediumOne device infected with malware; no spread or data theft found.
HighSeveral devices or a shared drive affected; operations disrupted.
CriticalFiles encrypted across the organisation, backups affected, or data stolen and threatened with publication.

6. Response steps

Work through these in order. Record every action, with the time and who did it, in your incident log.

  1. Disconnect affected devices from the network and Wi-Fi, but leave them switched on to preserve evidence.
  2. Photograph the ransom note and any messages on screen.
  3. Don't connect backup drives to any device until it's confirmed clean.
  4. Check which other devices and shared drives are affected.
  5. Get expert help to identify the malware and check for a known fix.
  6. Don't rush to pay. Payment doesn't guarantee your files back, and may mark you as a willing payer.

7. Communication

Who to inform, and when:

  • Incident lead, technical support and leadership, immediately.
  • All staff: what to do and not do with their devices.
  • Partners and funders, if work or deadlines are affected.
  • Affected people and your data protection authority, if personal data was stolen and the law requires it.
  • Don't contact the attackers without expert advice.

8. Evidence to preserve

Keep these before making changes, wherever it's safe to do so:

  • Photographs of ransom notes and on-screen messages.
  • Samples of encrypted file names and extensions.
  • Affected devices, kept powered on and isolated until examined.
  • System and security logs, and the time each device was found affected.
  • How the infection is thought to have entered: email, download, remote access.

9. Recovery and review

  • Clean or rebuild infected systems before restoring from backup.
  • Restore from the most recent clean backup, and check restored files.
  • Change passwords, especially for admin and remote access accounts.
  • Check whether personal data was taken, and whether the law requires you to report it.
  • Find out how the malware got in, and close that gap.
  • Record the incident and update your plan.

10. Prevention checklist

  • Turn on automatic updates for operating systems and software.
  • Use licensed software only, and keep security protection switched on.
  • Back up regularly with the 3-2-1 rule: three copies, two types of storage, one offline or separate.
  • Test that you can actually restore from backup.
  • Give admin rights only to people who need them, and protect remote access with 2-step verification.
  • Separate sensitive systems and limit access to shared drives.