Ransomware Containment
The actions that shorten recovery and reduce blast radius

Field Checklist Free to Use

Encryption is the end of the attack, not the beginning. By the time screens lock, the adversary has usually had days inside your network, and likely took data on the way. Containment is about cutting their access, protecting what's still clean, and keeping your recovery options alive.

Immediate Containment

In order. Each of these either stops active damage or protects your ability to recover.

Action How Why
Isolate, Don't Power Off Disconnect affected systems from the network: pull the cable, disable the NIC, or use EDR network isolation. Leave them running. Powering off destroys memory evidence and can corrupt encrypted volumes mid-write.
Protect the Backups Take backup infrastructure off the domain network NOW. Verify you have an offline or immutable copy before anything else. Modern crews destroy backups first. Your backups are the target, not the fallback.
Cut Remote Access Disable VPN, RDP exposure, RMM tools, and third-party remote access until each is verified clean. The initial access vector is usually still open, and they will come back through it.
Contain the Domain Reset privileged credentials, then rotate the krbtgt account twice. Audit new accounts and GPO changes. Assume domain admin is compromised. Golden tickets survive ordinary password resets.
Preserve Evidence Keep the ransom note, a sample encrypted file, and logs from firewalls, VPN, EDR, and domain controllers. Strain identification and the forensic timeline drive every downstream decision, including legal ones.
Establish Clean Comms Move incident coordination to out-of-band channels. Assume email and chat are monitored. Attackers read response plans in real time and adapt.

Do / Don't

Recovery speed is decided by what you avoid as much as what you do.

Do

  • Engage counsel and your carrier immediately: privilege matters, and consent requirements start early.
  • Identify the strain: the group's known behavior tells you whether data theft, lateral spread, or re-entry is likely.
  • Assume exfiltration until the timeline proves otherwise. Most crews steal before they encrypt.
  • Prioritize recovery order: identity first, then the systems the business actually runs on.

Don't

  • Don't wipe and reimage day one: you destroy the evidence that determines legal obligations and closes the entry point.
  • Don't restore onto a dirty network: recovered systems get re-encrypted, and you burn your backups proving it.
  • Don't contact the threat actor without counsel. Communications strategy, sanctions screening, and negotiation are specialist work.
  • Don't pay before an OFAC check: paying a sanctioned entity is its own federal problem.

The Path Back

Containment buys you the ability to run a structured recovery instead of an improvised one.

1

Contain

Access cut, backups protected, domain stabilized, evidence preserved.

2

Investigate

Entry point, timeline, scope of access, and whether data left the building.

3

Eradicate & Restore

Rebuild identity, restore by business priority onto verified-clean infrastructure.

4

Harden

Close the entry vector, fix what the timeline exposed, and run the after-action review.

Phase 4 is where most organizations stop short. Don't. See After Action Reviews.

When to Call Us

Encryption event, backup uncertainty, or board-level pressure. Olympus Cyber runs ransomware response with rapid triage, containment leadership, recovery structure, and executive-ready reporting for legal, insurance, and the board.
🚨 Emergency IR