WHAT YOU WILL LEARN
Learning objectives
- Map common entry points and lateral movement
- Prioritise coordinated containment
- Define evidence needed before restoring service
Reduce the paths an attacker can use
Inventory exposed remote access, enforce strong authentication and address vulnerable systems. Separate ordinary accounts from administrative privileges. A single stolen credential should not provide unrestricted access to workstations, servers and backups. Segmentation and monitoring help limit and detect movement, but neither is a substitute for maintained access controls.
Coordinate containment
When encryption or a credible intrusion is detected, use the incident plan and a trusted communication channel. Identify affected and at-risk systems. Isolation should be coordinated with the response team, especially for shared or critical services. Preserve logs, messages and a timeline. Avoid improvised cleanup that destroys evidence or reconnects an attacker to clean systems.
Recover to a defensible state
A backup is a recovery input, not proof that the attacker is gone. Understand the initial access, scope and persistence; remediate affected identities and systems. Restore in an isolated environment, verify data and application dependencies, and monitor before reconnecting users. Decide recovery order from business priorities and measured RPO/RTO objectives.
Learn from the event
Document what was known at each decision, who approved containment and how recovery was validated. Convert gaps into assigned improvements. A tabletop exercise and a measured restore test are more useful than an untested statement that recovery is “covered.”
APPLIED EXAMPLE
Put it in context
A fictional manufacturing team discovers encrypted shares. It isolates affected segments, protects backup administration and restores a priority application in a clean environment after checking identity compromise and dependencies.
Illustrative scenario for learning, not a claim about a verified customer incident.Common mistakes
- Connecting backups to compromised administration
- Equating restored files with complete recovery
- Skipping a decision timeline
Your practical checklist
Checklist ticks are temporary and are not recorded as account progress.
MINI RECAP
Ransomware readiness combines limited access, early reporting, evidence-aware containment and tested recovery.
Put your understanding to the test.
Go further in the Incident Response Track
The free base is available now. Applied labs, assessed evidence and authenticated history are planned extensions.
Explore the learning track →