Incident Response
Ransomware Incident Response Playbook: The First Hour, the Ransom Decision, and the OFAC Risk
Most ransomware content focuses on backup architecture — and that matters, which is why we cover it separately in Disaster Recovery in the Age of Ransomware. This article covers the part that backup strategy does not: what your team actually does in the minutes and hours after someone reports encrypted files, and the decisions — law enforcement, outside counsel, and the ransom payment itself — that determine whether the incident stays contained or becomes a much larger event.
The First Hour: Isolate, Don’t Reflexively Power Off
The instinct when ransomware is discovered is to kill power to the affected machines. CISA’s guidance, developed with the Multi-State Information Sharing and Analysis Center, says that instinct is usually wrong. The priority is isolation, not shutdown.
- If multiple systems or subnets appear affected, take the network offline at the switch level rather than chasing individual machines.
- If a full network takedown is not immediately possible, physically disconnect affected devices — pull the ethernet cable or disable Wi-Fi — to stop lateral spread without touching the machine’s power state.
- Only power off devices as a last resort, when disconnecting from the network is not possible. Powering off destroys the contents of volatile memory (RAM), and RAM is frequently where forensic investigators find the encryption keys, the initial access artifacts, and the process activity that reconstructs how the attacker got in and what they touched.
The reasoning is straightforward once stated: a running, isolated machine can still be imaged for forensics with its memory intact. A powered-off machine cannot. Every hour of ambiguity about what happened and how far it spread is an hour your eventual notification obligations, insurance claim, and remediation plan are less precise (CISA, #StopRansomware Guide).
Alongside isolation: preserve, don’t delete, the ransom note and any attacker communication channel. Identify and disable, but don’t wipe, any scheduled tasks or remote access tools the attacker may have planted for persistence. And resist the urge to reboot systems “to see if it’s better” — a reboot before imaging is one of the most common ways organizations destroy their own forensic evidence.
The Decision Tree: Law Enforcement, Outside Counsel, IR Retainer
Once containment is underway, three parallel calls need to happen — and the order matters less than making sure none of them is skipped or delayed by internal debate.
Law Enforcement
Report to the FBI (via IC3.gov or your local field office) and, for many regulated entities, to sector-specific authorities as well. CISA and the Treasury Department are explicit that early law enforcement engagement is not just a civic obligation — it is a documented mitigating factor if the ransom-payment question later intersects with sanctions exposure, addressed below. Law enforcement may also already hold decryption keys or threat-actor intelligence for the specific ransomware family involved, which has ended incidents faster than a forensic investigation alone.
Outside Counsel — Before, Not After, Key Decisions
Breach counsel should be engaged early enough to direct the forensic investigation under attorney-client privilege, not brought in afterward to review decisions that already happened. Counsel also owns the notification-timeline analysis — HIPAA’s 60-day clock, state breach laws with shorter windows, CMMC and DFARS incident-reporting requirements — which starts running from discovery, not from resolution. Waiting to loop in counsel until the technical response is “done” is one of the most common and most expensive sequencing mistakes in ransomware response.
An Incident Response Retainer, If You Have One
If your organization holds a retainer with a qualified incident response provider, this is the moment it pays for itself: a team that already knows your architecture, your compliance obligations, and your escalation contacts can be actively working the incident within the retainer’s contractual response window — commonly one to four hours — rather than starting with a cold discovery phase. Organizations without a retainer are, at this exact moment, trying to source, vet, and contract an unfamiliar IR firm while the incident is still active. That gap is the entire argument for pre-engagement.
The Ransom Payment Decision: The OFAC Risk Nobody Explains Up Front
Whether to pay a ransom is ultimately a business and legal decision, not a purely technical one — but it carries a specific regulatory risk that is frequently left out of the conversation until it’s too late to plan around: paying certain ransomware operators can violate U.S. sanctions law, independent of whether the payment “worked.”
The Treasury Department’s Office of Foreign Assets Control (OFAC) has designated a growing list of ransomware operators and facilitators as Specially Designated Nationals, including Evil Corp and its members (originally designated in 2019, with additional designations in 2024) and affiliates of the LockBit ransomware-as-a-service operation (sanctioned in 2024). Paying — or facilitating payment to — a sanctioned actor or a comprehensively embargoed jurisdiction can expose the paying organization, and any intermediary that helps arrange the payment, to strict-liability civil penalties. OFAC’s sanctions liability standard does not require that you knew the recipient was sanctioned; it can attach based on the payment itself.
OFAC’s updated advisory on ransomware payments lays out what mitigates that exposure: reporting the incident to law enforcement and cooperating fully, and maintaining a risk-based sanctions compliance program. Organizations — and the payment facilitators, cyber insurers, and IR firms that work with them — are expected to screen a demanded payment against the SDN list and available threat intelligence before it goes out, not after. In practice, this means the ransom-payment decision cannot be made on IT and business-continuity grounds alone. It needs sanctions screening, and that screening needs to happen inside the same first hours as containment, not as an afterthought once a payment has already been wired (OFAC, Updated Advisory on Potential Sanctions Risks for Facilitating Ransomware Payments).
This is also, practically, an argument against ever treating “just pay it” as the default plan. Beyond the sanctions exposure, paying does not guarantee a working decryptor, does not guarantee the attacker didn’t retain a copy of exfiltrated data for future extortion, and — per the NetDiligence Cyber Claims Study — the average SME ransomware incident already costs roughly $432,000 in response, recovery, and related expenses before any ransom is factored in. The payment decision deserves the same structured, counsel-and-forensics-informed process as every other step in the response, not a rushed call made under pressure at 2 a.m.
Retainer vs. Scrambling: How Pre-Engagement Changes the Timeline
Every decision above — isolation without evidence loss, timely law enforcement engagement, counsel-directed forensics, sanctions-screened payment decisions — is faster and more defensible when the response team already knows your environment. That is the operational case for a retainer-based capability like SENTRY’s incident response retainer: pre-negotiated response-time SLAs, a documented environment review completed before any incident, and annual tabletop exercises that mean your internal team has actually rehearsed this decision tree rather than encountering it live for the first time. Organizations without pre-engaged IR capability are, in effect, doing vendor selection and environment discovery simultaneously with active containment — precisely the two things that should already be finished by the time an incident starts.
The documentation this playbook produces — a tested plan, a tabletop record, a retainer contract — is also, not coincidentally, the same evidence set cyber insurance underwriters now require to bind or renew coverage. Response readiness and insurance readiness are the same program, viewed from two different requirements.
Conclusion
The technical playbook is learnable and, with the right pre-engagement, largely rehearsable: isolate without destroying evidence, engage law enforcement and counsel early and in parallel, screen any ransom-payment decision against sanctions risk before money moves, and let a team that already knows your environment run point. None of that works well if it’s improvised for the first time during an active incident.
Get the playbook in place before you need it: start with a SENTRY incident response retainer, or begin with the 90-Day Proof, which includes IR capability as part of the integrated SENTRY MDR program.