Ransomware Defense Playbook
Ransomware attacks on companies increased 62% last year. This is the defense playbook your organization needs — before you need it.
Ransomware is no longer a problem that only happens to other people. In 2024, companies became the primary target for ransomware groups — large enough to pay significant ransoms, small enough to lack enterprise-grade defenses.
The average ransom demand for organizations now exceeds $1.5 million. The average total cost of a ransomware incident — including downtime, recovery, legal fees, and reputational damage — is closer to $4.5 million.
This playbook covers what you need to do before, during, and after a ransomware attack.
Before the Attack: Prevention and Preparation
Layer Your Defenses
No single control stops ransomware. Effective defense requires multiple overlapping layers:
Endpoint Detection and Response (EDR)
Deploy EDR on every endpoint — workstations, servers, and laptops. Modern EDR solutions use behavioral analysis to detect ransomware activity before encryption begins. This is your most important preventive control.
Email Security
The majority of ransomware enters through phishing emails. Implement a secure email gateway with sandboxing, anti-phishing, and attachment scanning. Train your users to recognize and report suspicious emails.
Network Segmentation
Ransomware spreads laterally across flat networks. Segment your network so that a compromised workstation cannot directly reach your file servers, backup systems, or critical infrastructure.
Privileged Access Management
Ransomware operators love over-privileged accounts. Implement least-privilege access, disable local administrator accounts where possible, and use privileged access workstations for administrative tasks.
Multi-Factor Authentication
Enable MFA everywhere — email, VPN, remote desktop, cloud services. Credential theft is the primary initial access vector for ransomware groups. MFA stops most credential-based attacks cold.
Build a Resilient Backup Strategy
Your backup strategy is your last line of defense. If your backups are compromised, you're paying the ransom.
The 3-2-1-1-0 Rule
- 3 copies of your data
- 2 different storage media types
- 1 offsite copy
- 1 offline or air-gapped copy
- 0 errors verified through regular restore testing
The critical addition to the classic 3-2-1 rule is the offline copy. Ransomware operators specifically target and encrypt backup systems. An air-gapped or immutable backup that cannot be reached from your network is your recovery lifeline.
Test Your Restores
A backup you've never tested is not a backup — it's a hope. Conduct quarterly restore tests and document your recovery time objectives (RTO) and recovery point objectives (RPO).
Develop Your Incident Response Plan
You cannot write your incident response plan during an incident. Develop it now, test it through tabletop exercises, and make sure everyone knows their role.
Your ransomware IR plan should include:
- Detection and initial triage procedures
- Escalation and notification contacts (internal and external)
- Isolation procedures for affected systems
- Communication templates (internal, customer, regulatory)
- Ransom payment decision framework (legal, insurance, law enforcement)
- Recovery procedures and priorities
During the Attack: Containment and Response
Isolate Immediately
The moment you detect ransomware activity, isolate affected systems from the network. Disconnect from ethernet, disable Wi-Fi, and remove from any VPN connections. Speed matters — every second of connectivity allows the ransomware to spread and encrypt more data.
Do not shut down affected systems unless instructed by your forensics team. Memory forensics can recover encryption keys and provide critical intelligence about the attack.
Activate Your IR Team
Notify your incident response team, legal counsel, and cyber insurance carrier immediately. If you don't have an internal IR capability, engage an external IR firm. Time is critical — most IR firms offer 24/7 emergency response.
Preserve Evidence
Before you start recovery, preserve forensic evidence. This includes:
- Memory dumps from affected systems
- Network traffic logs
- Security tool logs and alerts
- System event logs
This evidence is critical for understanding the attack, identifying the initial access vector, and satisfying regulatory notification requirements.
Assess the Scope
Determine which systems are affected, which data has been encrypted, and whether data has been exfiltrated. Many ransomware groups now operate double-extortion schemes — they encrypt your data and threaten to publish it unless you pay.
Notify Stakeholders
Depending on the data involved and your regulatory obligations, you may have mandatory breach notification requirements. HIPAA requires notification within 60 days. Many state laws require notification within 30 days or less. Engage legal counsel early.
After the Attack: Recovery and Hardening
Recover from Clean Backups
Restore from your most recent clean backup — ideally your offline or air-gapped copy. Before restoring, ensure the ransomware has been fully eradicated from your environment. Restoring into a compromised environment will result in reinfection.
Prioritize recovery based on business criticality. Identify your most critical systems and restore those first.
Conduct a Root Cause Analysis
Understand how the attackers got in. Common initial access vectors include:
- Phishing emails with malicious attachments or links
- Exploitation of unpatched vulnerabilities (especially internet-facing systems)
- Compromised credentials used for RDP or VPN access
- Supply chain compromise through a trusted vendor
Close the initial access vector before declaring recovery complete.
Harden Your Environment
Use the incident as an opportunity to address the security gaps that allowed the attack to succeed. Common post-incident hardening actions include:
- Patching all critical and high vulnerabilities
- Implementing or improving MFA
- Reviewing and restricting privileged access
- Improving network segmentation
- Enhancing monitoring and alerting
Conduct a Post-Incident Review
Document what happened, what worked, what didn't, and what needs to change. Update your IR plan based on lessons learned. Brief your board and executive team.
Building Long-Term Ransomware Resilience
Ransomware defense is not a project — it's an ongoing program. The threat landscape evolves constantly, and your defenses need to evolve with it.
The organizations that successfully defend against ransomware share common characteristics: they have documented security programs, they test their defenses regularly, they train their employees, and they have executive leadership that treats cybersecurity as a business priority.
If you're not sure where your organization stands, start with an assessment. Our team can evaluate your current ransomware defenses, identify your highest-risk gaps, and build a prioritized remediation plan.
Schedule a free security consultation — before you need it.
Explore Topics
Written by
UR Cyber Defense Team
Content creator and writer sharing insights and stories.