Skip to content
Skip to main content
Cyber Incidents & Offender Methods Operational Explainer

What should be preserved immediately in a ransomware incident?

Prioritise volatile evidence, short-retention provider records and material that containment or recovery will alter. Encrypted files and the note are only part of the record.

Capture high-loss evidence first

Preserve active sessions, memory, processes, malware, scripts, endpoint telemetry, authentication, cloud and remote-access logs, network data, staging, backup-console events, communications and payment instructions. Retain representative encrypted originals and notes with metadata.

Record first known activity, detection, impact and each response action separately. Restarts, rebuilds and decryption may be necessary, but their evidential effects should be considered and documented.

Preserve extortion and decision records

Retain portal IDs, messages, cryptocurrency addresses, deadlines and files supplied by the offender. Record authorised communicators and information disclosed. Test decryptors or proof files only in a controlled environment, not production.

Internal communications, tickets and decision logs explain what was known and why action was taken. If urgent recovery limits preservation, document lost evidence and alternative sources rather than concealing the gap.

Key takeaway

Preserve volatile access, short-lived logs, malware, encrypted samples, extortion material, backup activity and the complete response timeline before recovery changes them.

Reference: CIM-182Cyber Incidents & Offender Methods