Incident Playbook
Ransomware & Malware
Summary
Malicious software has infected organisational devices, encrypting files, stealing data or disrupting work.
- Category
- Devices and malware
- Typical severity
- Critical
- Response led by
- Incident lead, with technical support and leadership
First 15 minutes
- Disconnect affected devices from the network and Wi-Fi, but leave them switched on to preserve evidence.
- Photograph the ransom note and any messages on screen.
- Don't connect backup drives to any device until it's confirmed clean.
1. Overview
Malware is malicious software that spies on you, steals data or damages your systems. Ransomware is a kind of malware that locks your files and demands payment to unlock them. Many ransomware groups also steal data first and threaten to publish it.
2. How it happens
- Opening an infected attachment, or clicking "Enable content" in a document.
- Installing cracked or pirated software, or fake updates.
- Attackers getting in through unpatched systems or remote access tools with weak passwords.
- Infected USB drives shared between computers.
- Once inside, it spreads to shared drives and other devices on the same network.
3. Indicators
Signs that this incident may be happening:
- Files with strange extensions that won't open.
- A ransom note on the screen or in folders.
- Devices suddenly slow, with fans running hard or unknown programs starting.
- Security software switched off without anyone doing it.
- Unusual network activity or large uploads.
4. Triage questions
Answer these first to understand scope and severity:
- Which devices, shared drives and accounts are affected?
- Is the infection still spreading?
- Is there a ransom note, and does it claim data was stolen?
- Are backups intact, offline and unaffected?
- Which work and services are disrupted, and for how long can you cope?
5. Severity guide
Use your plan's severity levels. As a guide for this incident:
| Level | Typical situation |
|---|---|
| Low | A single device infected with adware or a potentially unwanted program, removed. |
| Medium | One device infected with malware; no spread or data theft found. |
| High | Several devices or a shared drive affected; operations disrupted. |
| Critical | Files encrypted across the organisation, backups affected, or data stolen and threatened with publication. |
6. Response steps
Work through these in order. Record every action, with the time and who did it, in your incident log.
- Disconnect affected devices from the network and Wi-Fi, but leave them switched on to preserve evidence.
- Photograph the ransom note and any messages on screen.
- Don't connect backup drives to any device until it's confirmed clean.
- Check which other devices and shared drives are affected.
- Get expert help to identify the malware and check for a known fix.
- Don't rush to pay. Payment doesn't guarantee your files back, and may mark you as a willing payer.
7. Communication
Who to inform, and when:
- Incident lead, technical support and leadership, immediately.
- All staff: what to do and not do with their devices.
- Partners and funders, if work or deadlines are affected.
- Affected people and your data protection authority, if personal data was stolen and the law requires it.
- Don't contact the attackers without expert advice.
8. Evidence to preserve
Keep these before making changes, wherever it's safe to do so:
- Photographs of ransom notes and on-screen messages.
- Samples of encrypted file names and extensions.
- Affected devices, kept powered on and isolated until examined.
- System and security logs, and the time each device was found affected.
- How the infection is thought to have entered: email, download, remote access.
9. Recovery and review
- Clean or rebuild infected systems before restoring from backup.
- Restore from the most recent clean backup, and check restored files.
- Change passwords, especially for admin and remote access accounts.
- Check whether personal data was taken, and whether the law requires you to report it.
- Find out how the malware got in, and close that gap.
- Record the incident and update your plan.
10. Prevention checklist
- Turn on automatic updates for operating systems and software.
- Use licensed software only, and keep security protection switched on.
- Back up regularly with the 3-2-1 rule: three copies, two types of storage, one offline or separate.
- Test that you can actually restore from backup.
- Give admin rights only to people who need them, and protect remote access with 2-step verification.
- Separate sensitive systems and limit access to shared drives.