Skip to content
CIM-182 Cyber Incidents & Offender Methods

What should be preserved immediately in a ransomware incident?

The practical answer

Immediate preservation should focus on volatile evidence, short-retention records and material likely to be altered by containment or recovery.

The key evidential caution

The dangerous assumption is that encrypted files and the ransom note are the only important evidence.

Evidence to preserve

Preserve:

Key points

  • ransom notes and communications
  • representative encrypted files
  • malware and scripts
  • active sessions
  • memory and running processes
  • endpoint telemetry
  • authentication and cloud logs
  • remote-access records
  • network, DNS and proxy data
  • archive and staging evidence
  • backup-console records
  • payment instructions
  • incident-response decisions

Record the first known event, first detection, first visible impact and every containment action separately.

Evidential limits

Do not restart, rebuild or decrypt systems before considering evidential consequences and operational risk.

Where immediate recovery is necessary, document what was changed and preserve representative systems or images where proportionate.

Provider-held records may require urgent preservation because retention can be limited.

Also preserve internal communications, support tickets and decision logs. They may be essential to reconstruct what was known and why actions were taken.

Where payment or negotiation begins, preserve every message, portal identifier, cryptocurrency address, deadline and file supplied by the offender. Keep negotiation activity separate from technical containment, and record who was authorised to communicate and what information was disclosed.

Preserve any decryptor or proof file supplied by the offender without executing it on production systems. Specialist examination may reveal identifiers, configuration or malware behaviour, but testing should be controlled and documented.

Operational takeaway

Preserve live access, logs, malware, encrypted data, extortion material, backup activity and the full response timeline before recovery changes the evidence.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.