Ransomware Frontline Report
Appendix B — Initial Response Record Form
During the initial response, record confirmed facts, supporting evidence, actions taken, decision makers, and unconfirmed matters in chronological order. This form is intended to help keep facts and judgments separate from the beginning of an incident.
The following is an example entry and does not describe an actual incident.
| Time (including time zone) | Confirmed fact | Evidence / location of supporting material | Action taken | Decision maker | Unconfirmed item / next action |
|---|---|---|---|---|---|
| 2026-09-03 09:15 JST | A high-severity EDR detection was confirmed on administrative endpoint A | EDR console / Alert ID: EXAMPLE-001 | Administrative endpoint A was isolated from the network | Incident response lead | Check whether the same identity was used to log in to other endpoints |
This record form is intended for internal fact management and should be kept separate from records of communications or negotiations with the attacker. Preserve original attacker messages, leak-site material, ransom notes, and similar evidence, and do not casually forward, modify, or publish them.