WHAT YOU WILL LEARN
Learning objectives
- Map common entry points and lateral movement
- Prioritise coordinated containment
- Define evidence needed before restoring service
Reduce the paths an attacker can use
Inventory exposed remote access, enforce strong authentication and address vulnerable systems. Separate ordinary accounts from administrative privileges. A single stolen credential should not provide unrestricted access to workstations, servers and backups. Segmentation and monitoring help limit and detect movement, but neither is a substitute for maintained access controls.
Coordinate containment
When encryption or a credible intrusion is detected, use the incident plan and a trusted communication channel. Identify affected and at-risk systems. Isolation should be coordinated with the response team, especially for shared or critical services. Preserve logs, messages and a timeline. Avoid improvised cleanup that destroys evidence or reconnects an attacker to clean systems.
Recover to a defensible state
A backup is a recovery input, not proof that the attacker is gone. Understand the initial access, scope and persistence; remediate affected identities and systems. Restore in an isolated environment, verify data and application dependencies, and monitor before reconnecting users. Decide recovery order from business priorities and measured RPO/RTO objectives.
Learn from the event
Document what was known at each decision, who approved containment and how recovery was validated. Convert gaps into assigned improvements. A tabletop exercise and a measured restore test are more useful than an untested statement that recovery is “covered.”
APPLIED EXAMPLE
Put it in context
A fictional manufacturing team discovers encrypted shares. It isolates affected segments, protects backup administration and restores a priority application in a clean environment after checking identity compromise and dependencies.
Illustrative scenario for learning, not a claim about a verified customer incident.Common mistakes
- Connecting backups to compromised administration
- Equating restored files with complete recovery
- Skipping a decision timeline
Your practical checklist
Checklist ticks are temporary and are not recorded as account progress.
MINI RECAP
Ransomware readiness combines limited access, early reporting, evidence-aware containment and tested recovery.
Put your understanding to the test.
OPTIONAL NEXT STEP · PRO
Practise the first-response decisions.
The released ransomware lab asks you to weigh containment, evidence preservation and recovery priorities, then compare your reasoning with worked reviews.
See the ransomware response lab →
Recurring membership. Both plans include the same available Pro collection. Compare the complete offer.
Already a member? Log in or manage your membership before purchasing again.
Free lessons, quizzes and Simulation A stay free.