Tabletop: respond to a ransomware incident
Walk a realistic ransomware scenario through every incident response phase, and produce a timeline, decisions and a lessons-learned report.
Environment
Pen and paper or a document. Works well with a study partner playing the other roles.
Before you start
- Read Incident Response Processes (p.296) through Lessons Learned (p.304), and Testing and Training (p.306).
You will
- Apply each IR phase
- Make containment and communication decisions
- Write a short lessons-learned report
Steps
-
1
Scenario, 09:10 Monday: staff report that files on the finance share now end in
.lockedand there's a ransom note. The finance PCs show heavy disk activity. -
2
Detection and analysis: list the questions you'd ask and the data sources you'd check (EDR alerts, file server logs, sign-in logs). Decide whether this is a declared incident.
-
3
Containment: decide what to isolate first (affected PCs, the share, any accounts) and whether to power off or just disconnect. Write down your reasons.
-
4
Evidence: list what to preserve before cleaning up, in order of volatility.
-
5
Eradication and recovery: plan how to find the entry point, reset credentials, rebuild or restore systems, and verify the backups are clean before restoring.
-
6
Communication: who do you notify internally, and who externally (management, legal, customers, regulators)?
-
7
Lessons learned: write five findings and one owner and date for each improvement.
Check your understanding
- ?Why disconnect rather than power off an infected machine in many cases?
- ?What would make you declare the incident closed?
- ?Which preparation step would have shortened recovery the most?