Cyberstudy
Supplementary — not from your PDF Intermediate ~45 min

Tabletop: respond to a ransomware incident

Walk a realistic ransomware scenario through every incident response phase, and produce a timeline, decisions and a lessons-learned report.

Environment

Pen and paper or a document. Works well with a study partner playing the other roles.

Before you start

  • Read Incident Response Processes (p.296) through Lessons Learned (p.304), and Testing and Training (p.306).

You will

  • Apply each IR phase
  • Make containment and communication decisions
  • Write a short lessons-learned report

Steps

  1. 1

    Scenario, 09:10 Monday: staff report that files on the finance share now end in .locked and there's a ransom note. The finance PCs show heavy disk activity.

  2. 2

    Detection and analysis: list the questions you'd ask and the data sources you'd check (EDR alerts, file server logs, sign-in logs). Decide whether this is a declared incident.

  3. 3

    Containment: decide what to isolate first (affected PCs, the share, any accounts) and whether to power off or just disconnect. Write down your reasons.

  4. 4

    Evidence: list what to preserve before cleaning up, in order of volatility.

  5. 5

    Eradication and recovery: plan how to find the entry point, reset credentials, rebuild or restore systems, and verify the backups are clean before restoring.

  6. 6

    Communication: who do you notify internally, and who externally (management, legal, customers, regulators)?

  7. 7

    Lessons learned: write five findings and one owner and date for each improvement.

Check your understanding

  • ?Why disconnect rather than power off an infected machine in many cases?
  • ?What would make you declare the incident closed?
  • ?Which preparation step would have shortened recovery the most?