T The Triage ManualTechnical Guides for IT Emergencies
P1 · Cyber Incident Response

Ransomware in progress — first 4 hours

Active or suspected ransomware. Goal: contain spread, preserve evidence, protect ability to report accurately under UK GDPR / NIS2.

Indicators

Likely causes

Diagnostic steps

  1. CONTAIN before investigating. Disconnect from internet at the firewall — not by shutting servers down (memory evidence). Isolate VLANs as needed. Disable VPN. Block external SMB/RDP
  2. Identify Patient Zero — earliest encrypted file timestamp, EDR alert chain, suspicious account logon
  3. Preserve evidence: do NOT wipe affected hosts. Capture memory (KAPE / Velociraptor / FTK Imager) and system logs before any rebuild
  4. Disable compromised accounts; reset credentials for privileged accounts from a clean station; rotate kerberos krbtgt twice (24h apart) for AD compromise
  5. Engage UK NCSC and ICO — 72-hour clock on personal data breaches under UK GDPR. Insurer cyber response team if covered
  6. Begin recovery from immutable / offline backups only — never decrypt and reuse compromised systems for production

Resolution path

Prevention

Tools

References

ransomwareincident-responsencscicocontainmentforensics