Ransomware Incident Response: Keep UK Services Running During Recovery

On detection of ransomware, your first hour must secure evidence, isolate affected resources, establish incident command, and engage either your assured CIR provider or internal IR team. Every decision from that point forward depends on preserving options: don’t power off systems that hold forensic value, don’t restore before you’ve confirmed eviction, and don’t let panic replace process.


TL;DR:

  • Build a timestamped incident timeline from alerts, identity, network, and backup logs, then map affected systems to business services before setting containment priorities.
  • Keep affected machines powered on, capture disk images or virtual machine snapshots, and export logs outside the compromised environment before remediation erases evidence.
  • If personal data is affected, notify the ICO within 72 hours; phased reports are allowed, so report confirmed facts before the full scope is known.
  • Disable compromised accounts without deleting them, isolate affected hosts, and restore only after monitoring confirms attacker eviction and backups pass isolated integrity checks.
  • Prioritize minimum viable operations, rebuilding identity services first when domain controllers were hit; serious incidents can take weeks to months to resolve.

Zerothrough
Strengthen Your Ransomware Readiness
Zero Through provides security-focused IT support, including SOC and SIEM services, penetration testing, and IT security audits for businesses.

Explore IT security support

Table of Contents

How do you triage alerts and determine the scope?

The first job is building a timeline. You need to know who reported the incident, when symptoms were first noticed, and what those symptoms actually were: a ransom note, encrypted file extensions, disabled backup jobs, or unusual login activity. This timeline becomes the backbone of every later decision, from containment to regulatory reporting.

Once the timeline starts forming, pull telemetry from every system that can confirm or deny the attacker’s footprint:

  • EDR alerts showing process execution, lateral movement, or privilege escalation
  • SIEM events correlating logins, file access, and network anomalies across systems
  • Firewall and VPN logs revealing unusual external connections or data transfers
  • Active Directory logs showing new accounts, group changes, or authentication spikes
  • Backup and restore logs confirming whether backup infrastructure itself was touched

Map each affected system to the business service it supports rather than treating every encrypted server as equally urgent. A finance database and a print server don’t carry the same weight when you’re deciding what to isolate first. This mapping also sets your scope boundary: the point at which you can say with reasonable confidence which systems are clean and which need forensic review before reconnection.

Microsoft’s ransomware incident response guidance outlines a three-step initial approach: assess the current situation, identify affected line-of-business applications, and determine the compromise recovery process. That order matters. Jumping straight to recovery before you understand which applications are affected tends to create more rework later.

Evidence preservation runs in parallel with triage, not after it. Image affected disks where possible, snapshot virtual machines before touching them, and export logs to storage outside the compromised environment. Avoid rebooting or wiping systems that haven’t been imaged: a reboot can clear memory artifacts that would otherwise show how the attacker moved.

Disk, virtual machine, and logs copied to secure storage

Pro Tip: Keep a running, timestamped decision log from the first alert onward. It becomes essential for insurers, regulators, and your own post-incident review.

Who needs to be notified and when?

Reporting obligations run on a different clock than technical recovery, and missing them creates legal exposure on top of operational damage.

  1. Use the governments Where to Report a Cyber Incident portal to identify whether Action Fraud, Police Scotland, or the National Cyber Security Centre is the right contact for your situation.
  2. If personal data is affected, UK GDPR requires notifying the ICO within 72 hours of becoming aware of a breach, with phased reporting permitted when full details aren’t yet available.
  3. Draft your initial report around what you know with confidence: scope, affected data categories, and containment actions taken, rather than waiting for a complete picture.
  4. Loop in sector regulators where your industry requires it, and coordinate the timing of disclosures with legal counsel and your cyber insurer so statements stay consistent.
  5. Document any discussion of ransom payment carefully: law enforcement and sanctions bodies treat payment decisions as a risk area, and a clear paper trail protects the organization regardless of the outcome.

Our data protection laws guide covers the broader regulatory landscape multinational organizations navigate alongside breach notification.

What are the tactical containment and eradication steps?

Containment decisions made in the first few hours shape how fast and how safely you recover. Short-term containment means isolating affected hosts, segmenting network zones that show signs of lateral movement, and disabling compromised accounts without deleting them, since a disabled account still carries forensic value.

Identity infrastructure deserves attention before almost anything else. NCSC guidance on cyber attack disruption points to identity compromise as a common enabler of rapid lateral movement, since an attacker with domain credentials can push ransomware across an entire environment quickly. Practical steps include:

  • Isolating known-good domain controllers from suspect network segments while keeping them powered on for evidence
  • Planning a krbtgt account reset once your incident response team confirms the right timing and sequence
  • Reviewing privileged account activity for new memberships, password resets, or unusual sign-ins
  • Preserving log sources before any remediation action risks overwriting them

Chain-of-custody matters here. Decide early who has access to captured evidence and keep that list short. Rushing recovery before forensic analysis is complete is one of the most common and costly mistakes organizations make, since restoring systems before confirming attacker eviction often leads to reinfection within days.

Pro Tip: Coordinate communications about the incident through phone calls or a separate messaging platform, never through the email or chat systems that may be compromised.

Confirming eviction before restoration isn’t optional. EDR and SIEM tooling should show a sustained absence of attacker activity, typically across multiple monitoring cycles, before any system goes back into production. Our MDR services guide covers how continuous monitoring supports this validation phase.

How do you recover to minimum viable operations?

Minimum Viable Operations, or MVO, is the set of business functions you need running to keep the organization operating, even if that means manual workarounds instead of full digital systems. NCSC guidance recommends structuring recovery around MVO rather than trying to restore everything simultaneously, since a staged approach reduces the risk of reintroducing the attacker through an unverified system.

  1. Identify which services are business-critical and map their technical dependencies, including the systems, accounts, and network paths each one relies on.
  2. Rebuild identity services first where domain controllers were affected, since nearly every other system depends on authentication working correctly.
  3. Test restores in an isolated environment before touching production, checking file integrity and confirming the backup itself predates the compromise.
  4. Reinstate systems in phases, monitoring each one closely for a defined period before moving to the next, rather than flipping everything back on at once.

Premature restoration is one of the costliest mistakes in ransomware recovery. Without confirmed eviction and validated backups, a restored system can become reinfected within hours, undoing days of containment work. NCSC’s annual review notes that recovery from highly disruptive incidents can take weeks to months, which underlines why rushing the final steps rarely saves time overall.

Once operations stabilize, the rebuild phase becomes about resilience rather than just restoration. That means patching the vulnerabilities that enabled initial access, hardening identity and network segmentation, running a tabletop exercise based on what actually happened, and documenting lessons learned in a format the leadership team will actually read. A ransomware response plan that never gets exercised tends to fail in exactly the ways a tabletop would have revealed.

What does a managed CIR engagement look like?

Calling in an NCSC-assured Cyber Incident Response provider early gives your team an objective set of eyes on evidence, containment, and the ransom decision, which matters most in the hours when internal teams are stretched thin and emotionally invested in the outcome.

A practical onboarding checklist for any external responder includes:

  • Scoping the engagement clearly: hours of coverage, deliverables, and evidence handling expectations
  • Signing NDAs and access agreements before any credentials or log access change hands
  • Setting a communication cadence so leadership gets regular updates without pulling responders off the investigation
  • Confirming how collected data will be stored, retained, and eventually destroyed

NCSC’s annual review describes ransomware as a persistent high-threat category, with recovery for serious incidents often stretching into weeks or months. Managed SIEM and MDR coverage shortens that window by catching the early indicators before encryption spreads, and by staying active through the recovery phase to confirm the environment stays clean. Our managed cyber security services guide walks through how SOC and SIEM coverage fits into this picture.

Why calm leadership decides how fast you recover

The organizations that recover fastest aren’t the ones with the biggest budgets. They’re the ones where someone had already decided, before the incident, who makes the ransom call, who talks to the board, and who signs off on restoration. Decision logs and rehearsed plans protect reputations more than any single technical control, because they remove guesswork at the exact moment guesswork is most dangerous.

— Shirish

Readiness and response support from Zero Through

Ransomware incidents move fast, and the gap between detection and containment is where most of the damage happens. We offer incident response capabilities designed to provide scalable support that adapts to your environment, whether you need rapid engagement during an active incident or ongoing coverage to catch threats before they spread.

Zerothrough

Our services most relevant to ransomware readiness and response include:

Executive guidance on crisis governance, including the kind of calm, structured decision-making a ransomware incident demands, is also something boards increasingly plan for in advance; resources like Dr. Rashaan J. Green’s leadership and strategy work address that governance side directly.

If you want a readiness review before an incident happens, or support during one, reach out through our site to scope what your organization needs.

FAQ

What is the first thing to do when ransomware is detected?

Isolate the affected systems from the network without powering them off, since memory and disk artifacts often hold the evidence needed to understand how the attacker got in. At the same time, stand up incident command and begin a timestamped decision log, which both guides your response and supports later regulatory reporting.

Should we pay the ransom?

Law enforcement and the National Cyber Security Centre do not encourage or condone ransom payments, noting that payment offers no guarantee of recovery and may increase future targeting. The decision involves legal, operational, ethical, and reputational factors, and organizations are advised to seek professional advice before deciding.

How quickly do we need to report a ransomware attack to regulators?

If personal data is affected, UK GDPR requires notifying the ICO within 72 hours of becoming aware of the breach, with phased reporting allowed when full details aren’t yet available. Separately, the Where to Report a Cyber Incident portal directs organizations to the right law enforcement contact based on their specific situation.

What is Minimum Viable Operations in ransomware recovery?

Minimum Viable Operations, or MVO, refers to the smallest set of business functions an organization needs running to keep operating, sometimes through manual workarounds rather than full digital systems. NCSC guidance recommends structuring recovery around MVO rather than restoring everything at once, since a staged approach reduces reinfection risk.

How long does ransomware recovery typically take?

Recovery timelines vary widely depending on scope and preparedness, but NCSC’s annual review notes that highly disruptive incidents can take weeks to months to fully resolve. Organizations with tested backups, rehearsed response plans, and assured CIR support tend to move through the staged recovery process faster than those improvising for the first time.

Sources

CASE STUDIES

See More Case Studies

CONTACT US

Robust IT support & Cybersecurity Services

Whether you operate from one location or across multiple countries, we can help you understand your technology and security priorities and identify the areas that require attention.

Speak to our team about your current environment, your challenges and your plans for growth.

Your benefits:
What happens next?
1

Schedule a call or a face to face meeting

2

We’ll review your current setup, requirements and security priorities

3

We provide a tailored proposal with clear and transparent pricing

Book a free security review