Direct answer
Prioritise safety, isolation and coordinated command. Isolate affected systems using approved procedures, preserve evidence before destructive cleanup where feasible, protect backups and privileged identities, establish an incident commander and clean communications channel, scope the affected environment, and recover only from known-good systems and data after the intrusion path is understood.
When to activate this playbook
Files become unexpectedly encrypted or renamed at scale.
Ransom notes, extortion messages or mass service failures appear.
Backup, hypervisor, identity or remote-management systems show suspicious administrative activity.
Endpoint or network controls report lateral movement, mass execution or destructive behaviour.
First 15 minutes
Declare a major incident and assign incident command, technical, evidence and communications owners.
Isolate affected systems or network segments using approved containment procedures while preserving critical evidence.
Protect backup systems, privileged identities, remote-management tools and recovery infrastructure from further access.
Move incident coordination to a trusted communications channel if normal collaboration systems may be compromised.
First hour
Establish the known affected systems, business services, identity scope and likely intrusion path.
Preserve endpoint, network, identity, backup, hypervisor and security-control evidence.
Review for persistence, lateral movement, data exfiltration and destructive changes.
Engage qualified incident responders, legal counsel, cyber insurer and relevant providers according to the organisation’s response plan.
First day
Build a recovery sequence based on business criticality and known-good dependencies.
Reset or rotate compromised privileged credentials, keys and secrets through a controlled recovery process.
Restore from known-good backups only after containment criteria are met and recovered systems are monitored.
Maintain an executive decision log covering operational impact, data exposure, notification, recovery and external-party decisions.
Evidence to preserve
EvidenceEndpoint, EDR and operating-system logs and forensic artefacts.
EvidenceIdentity, privileged-access and remote-management logs.
EvidenceNetwork, firewall, DNS, VPN and proxy telemetry.
EvidenceBackup, hypervisor, storage and cloud-control-plane logs.
EvidenceRansom notes, extortion communications and incident-command decisions.
Key decision points
Is the attacker still active in the environment?
Are backups and recovery systems trustworthy?
Was data exfiltrated before encryption?
Which services must be recovered first and what dependencies must be validated?
Communication discipline
Use an incident commander and a single source of truth for confirmed facts.
Separate operational updates, executive decisions, legal advice and external communications.
Do not make payment, notification or attribution decisions from unverified technical assumptions.
Where Cybatar fits
Major-incident coordination, severity, tasks, evidence and timeline records.
Asset, exposure, event and threat context attached to the same incident.
Forensic-case and chain-of-custody workflows.
Executive and governance reporting for recovery and follow-up actions.
Claim boundary
Cybatar can structure response coordination and evidence, but it does not decrypt ransomware, guarantee recovery, guarantee attribution, negotiate ransoms or replace specialist incident-response, legal, insurer, law-enforcement or recovery expertise.
Related evidence and guidance
Incident-response operating modelhttps://cybatar.co/research/incident-response-operating-model
Digital Forensics capabilityhttps://cybatar.co/platform/digital-forensics
Resilience & Vendor Assurancehttps://cybatar.co/platform/resilience-vendor-assurance
Evidence preservation checklisthttps://cybatar.co/incident-evidence-preservation-checklist
Incident Response Checklisthttps://cybatar.co/incident-response-checklist
Evidence Preservation Checklisthttps://cybatar.co/incident-evidence-preservation-checklist