Skip to content
CoRISE

Recording Decisions and Recovery in Ransomware Response

Record detection, isolation, evidence preservation and recovery decisions to improve subsequent response.

3 min read
  • Security
  • Operations
  • Reliability
Open table of contents

Conclusion

A ransomware response record should explain who made each containment or recovery decision, what evidence supported it and which services were stopped or resumed. Separate observations, hypotheses and decisions to support handover. This is a design for response records, not a chronology or outcome report for a particular incident.

A minimum response record

FieldWhat to retain
TimeObservation time, recording time, time zone and known clock discrepancies
ObservationAffected subject, confirmed facts, source and unresolved questions
EvidenceStorage location, collector, collection method and transfers; integrity values where applicable
DecisionSelected action, alternatives, reasons for rejecting them and approver
ImpactInterrupted workflows, dependencies, contacts and the next decision conditions

Mark unavailable information as unresolved and assign someone to follow it up. Do not fill gaps with assumptions. Preserve earlier entries when a decision changes and append the correction and its reason.

Handover from detection to containment

Investigate possible effects on administrative access, shared storage, backup administration and integrations, rather than only the first observed device. Assess containment against both the risk of further spread and the workflows it interrupts. Network isolation and powering down a device have different operational and evidentiary effects; response leadership and investigators should coordinate the procedure.

Check whether the communication channels and administrator accounts used for response are themselves affected. Avoid carrying potentially compromised credentials into the recovery environment.

Conditions for approving recovery

  1. Define the systems and workflows to restore, the recovery data point and the possible loss interval.
  2. Prepare the recovery environment, management path and credentials, and decide how entry paths and unresolved problems will be addressed.
  3. Check separately that backup data can be retrieved and that the application can use the restored data correctly.
  4. Establish monitoring, user checks, conditions for renewed isolation and the person authorizing service resumption.
  5. Reconcile the observation timeline with the decision timeline afterward. Use the gaps to improve detection, authorization, backups and communications.

Limitations

Evidence requirements and reporting duties depend on contracts, the activity and jurisdiction. Coordinate with the relevant specialists and manage access to and retention of records. A complete record does not itself establish the full extent of compromise or successful recovery.

Sources and further reading

These cases provide attributed design context. They do not establish that the proposed experiments or configurations were delivered in those engagements.

Contact

Tell us about your engineering challenge.

Talk with CoRISE about the design, implementation and operation of your systems.

Start a Conversation