Ransomware Frontline Report
Supplement D: Decision-Support Material — Breaking Down Common Hard Questions
This supplement organizes issues on which judgment tends to diverge in the field, in the order of facts, decision criteria, and shortcuts to avoid. It does not substitute for an individual organization’s legal, insurance, contractual, or regulatory judgment.
D.1 “Should the Entire Corporate Network Be Shut Down?”
Information to Gather as Fact
- Is the anomaly on a single endpoint, or across multiple segments?
- Which management planes and business systems can an identity suspected of compromise access, and what can it operate or change there?
- Are anomalous authentication, privilege changes, external communication, data access, or disabling of protection continuing?
- What immediate impact would a business stoppage have on safety, patients/users, contracts, and social services?
- How far can spread be stopped through partial isolation, suspending a specific identity, shutting down external exposure, or cutting off administrative pathways?
Decision Criteria
A full shutdown can stop the spread, but it can also damage critical operations, evidence, and recovery. Partial isolation can preserve operations, but risks allowing the attacker to keep moving. Rather than fixing a single correct answer in advance, decide in stages based on asset criticality, reachable routes, privilege, fallback operations, and expert advice.
Shortcuts to Avoid
- “It’s just one device, so it’s fine”: Narrowing the scope without checking identity or the management plane.
- “We need evidence, so we won’t stop it”: Leaving the spread of actual damage unaddressed.
- “Stopping it makes us safe”: Failing to look at identities, backups, or the cloud management plane that are already compromised.
D.2 “Which Backup Should Be Restored?”
Information to Gather as Fact
- The time of the first sign of compromise, anomalous authentication, configuration changes, and data manipulation.
- The creation time, retention state, change history, and administrative log for each backup generation.
- Whether the restoration destination environment is isolated from the production compromise.
- The identities, certificates, DNS, keys, licenses, and external integrations needed after restoration.
- The business make-up procedure and acceptable range if data is lost.
Decision Criteria
The newest backup is not necessarily the safest. Choose based on when the compromise or alteration began, whether the backup management plane is suspect, and whether it can be verified after restoration. Do not let the recovery point be chosen by technical staff alone; confirm with the business owner what the lost business data actually means.
Shortcuts to Avoid
- “The job succeeded, so it’s sound”: Not checking restoration, integrity, or deletion history.
- “Older is safer”: Ignoring the impact of losing so much data that the business cannot be restored.
- “Restore to production first and think about it later”: Introducing re-intrusion, alteration, or unverified data.
D.3 “How to Judge Whether Data Was Stolen”
Information to Gather as Fact
- The location, classification, and normal access/sharing routes of critical data.
- Records of anomalous accounts, privileges, searches, compression, sharing settings, and external transfers.
- Audit logs from cloud, SaaS, outsourcing partners, proxies, and the network.
- The authenticity of any sample presented by the attacker, its match against public information, and its timing.
- Log gaps, areas that cannot be investigated, and evidence already preserved.
Decision Criteria
Data theft cannot be judged by the presence or absence of encryption alone. Conversely, the full scope of a leak must not be settled based solely on the attacker’s claim or sample. State explicitly the confirmed scope, the scope reasonably suspected, and the unconfirmed scope, and cross-check against legal, privacy, and contractual requirements.
Shortcuts to Avoid
- “It’s not on the leak site, so it’s safe”: Ignoring extortion that is never posted, a delay before posting, or other channels.
- “There’s no external traffic, so it’s safe”: Ignoring legitimate SaaS, outsourcing partners, and encrypted traffic.
- “There are no logs, so there was no leak”: Conflating an inability to observe with the absence of an event.
D.4 “Is It Acceptable to Announce ‘Recovered’?”
Minimum Confirmation
| Perspective | Example confirmation |
|---|---|
| Availability | Priority operations can be carried out through their specified procedure. |
| Integrity | Data, configuration, integrations, and privileges have been signed off. |
| Confidentiality | The confirmed, under-investigation, and unconfirmed scope can be explained. |
| Security | Remediation of, or residual risk in, the intrusion route, abused identities, and the management plane is understood. |
| Monitoring | Post-recovery anomalies are being observed, and responders are on standby. |
| External explanation | What was recovered, what remains under investigation, and the time of the next update can all be stated. |
“Full recovery” is a strong phrase. In practice, limited resumption, recovery of critical operations, return to normal operations, completion of the investigation, and completion of recurrence prevention can each be separate milestones. Choose wording that matches the facts.
D.5 “Whether to Contact the Attacker”
Contact with the attacker is not a purely technical matter. It relates to evidence preservation, legal/sanctions considerations, insurance, investigative authorities, the safety of the victim organization, negotiation expertise, and external explanation. CISA indicates that payment does not guarantee recovery and that coordination with relevant authorities should be considered. [S01]
For this reason, decide during normal operations who holds the authority to make contact, what information may be handed over, how records are preserved, and how to escalate to outside experts, legal counsel, insurers, and investigative authorities. Avoid a structure in which frontline technical staff, acting in good faith, independently initiate contact on their own.