skip to content

Ransomware Playbook

The ransom note is the end of an intrusion that began weeks earlier, so what matters is the playbook that already decided who may pull the network and whether you pay. Asked by name in interviews.

on this pageshow

explore

questions

4

Why does a ransomware playbook pre-decide the ransom position and who may disconnect?

level: juniorimportance: must knowfreq 68%

answer

  1. the clock starts before you notice
  2. decision rights, not commands
  3. the deciders are asleep
  4. insurer notice is a policy condition
  5. pay or refuse is settled in daylight

basics

~20 s

Because the extortion note arrives with a countdown, and the decisions it forces — pay or refuse, disconnect or keep producing, call the insurer and counsel — belong to executives who are asleep. Pre-deciding removes hours of paralysis.

solid answer

~50 s

An extortion event does not start when you notice it. By the time the note appears the data has already been copied out and the encryption has already run, so the first hour is spent on decisions rather than discovery. Those decisions are legal, financial and executive: may the provider disconnect a production estate at 02:00 without waking anyone, what is our standing position on paying, when does the insurer have to be told, when is counsel engaged, who watches the leak site. A playbook that pre-decides them is a set of signed decision rights, not a list of commands. Made in advance they are made calmly, by the people who actually own the consequences; made in the moment they are made under duress by whoever happens to be on the bridge, and the cost of hesitating is measured in encrypted datastores and a running deadline.

go deeper

for a junior

Be ready to say what an extortion playbook contains and why each item must exist before the note appears: disconnect authority, ransom position, insurer and counsel triggers, and who watches the deadline.

for a middle

Explain why the note is late in the attack rather than early, and why decisions rather than discovery dominate the first hour. Know that most cyber policies condition cover on notice and approved vendors.

for a senior

Show that you can run the first hour against pre-agreed authority: who you wake, who you do not, and which actions a co-managing provider may already take without you. Be specific about what the playbook cannot pre-decide.

for a principal

Own the argument for why these are executive decisions with signatures attached, and be able to defend the standing position to a board that has never had to state one in daylight.

## What lands on you An extortion incident announces itself late. In the shape this playbook is written for, an intruder reached the virtualisation management plane of a manufacturing estate, used it to encrypt the datastores holding hundreds of virtual machines, and left a note. Two things follow from that. First, the encryption happened *below* the guest operating systems, so agents inside those virtual machines saw nothing before they stopped existing. Second, the theft happened days earlier — modern extortion is *double extortion*: copy the data out first, encrypt second, and hold both the restore and the publication over the victim. Within hours the organisation's name appears on the actor's leak site with a countdown timer. So the first hour of the response is not an investigation. It is a queue of decisions that a security team is not empowered to make. ## What a playbook actually is here It is tempting to write a ransomware playbook as a technical procedure. It is not one. Its value is that it records, in advance and with signatures, **who may decide what** — decision rights, not commands. The recurring items are: - **Authority to disconnect.** Who may sever the virtualisation management network, or a plant's network, without an executive on the call — and what they may never touch. - **The ransom position.** The organisation's standing answer to the payment question, what it will never pay for, who may override the standing answer, and who signs. - **The insurer trigger.** At what point the cyber insurer is notified, by whom. Policies commonly require prompt notice and the use of approved (panel) vendors and counsel; hiring your favourite forensics firm at 02:00 can leave that spend uncovered, and most policies require the insurer's consent before any extortion payment. - **The counsel trigger.** When outside counsel is engaged, and that the response is run in a way that protects legal position from the start rather than retroactively. - **Deadline ownership.** Who monitors the leak-site listing and its timer, and who is briefed on what the timer does and does not mean. ## Why in advance Three reasons, and they are worth being able to say out loud. **The clock is the adversary's, not yours.** The countdown is set by the party that stole the data. Every hour spent locating a decision-maker is an hour taken off whatever time you actually have. **The decision-makers are not in the room.** A tier-1 analyst cannot authorise stopping a production line, and should never be the person deciding whether the company pays. If the playbook does not name a person, the default is escalation through a phone tree at 03:00 while datastores encrypt. **Duress is not a good decision environment.** The pay-or-refuse question is emotionally loaded, expensive and legally constrained. An organisation that first considers it while a timer runs will consider it badly. The point of pre-deciding is that the hard thinking — sanctions exposure, insurer consent, what a deletion promise is actually worth — was done in daylight. ## What cannot be pre-decided A good playbook is honest about its limits. It cannot decide facts it does not have: whether *this* production line must stop, what *this* stolen data set contains, what to tell *this* named customer. It pre-decides **authority and position**; scope-dependent calls still have to be made live, but by a named person against pre-agreed criteria rather than by improvisation. ## How to tell a real one from a paper one A real playbook names individuals and roles, not committees. It states an action a third party may take without asking. It carries a signature from someone who can spend money and stop production. It says what will never be disconnected. And it says what the organisation will not buy at any price — which is the sentence that saves the most time when the note lands, because it converts the loudest question in the room into a decision that was already made. The failure mode to avoid: treating extortion as a restore exercise. Restoring solves encryption. It does nothing at all about the copy of your data sitting on someone else's infrastructure with a timer attached, and that half of the problem is the half the playbook exists to pre-decide.

  • Which decisions genuinely cannot be pre-decided in a playbook like this?
    Anything that depends on facts you do not yet have: whether a specific production line must stop, what the stolen data set actually contains, what a named customer is told. The playbook pre-decides authority and standing position, and gives criteria for the live calls. Pretending to pre-decide scope produces a document responders quietly ignore.
  • What should the playbook say about the cyber insurer?
    A named trigger, a named caller and a deadline. Most policies condition cover on prompt notice, on using panel counsel and approved vendors, and on the insurer's consent before any extortion payment. A response that engages its own forensics firm and negotiator first can be technically excellent and still uninsured.
  • Why is 'we restore from backup, so extortion does not affect us' an incomplete position?
    Restores answer the encryption half only. The other half is a copy of your data on the actor's infrastructure with a publication deadline, and no restore touches it. An organisation with perfect backups still needs a decided position on publication, notification and what it will refuse to buy.

It is the difference between a fire extinguisher and a signed evacuation authority. Anyone can point a hose; only one named person can decide to stop the factory.

saying these in an interview costs you the question

  • Treats the playbook as a technical restore procedure
  • Assumes the security team decides whether to pay
  • Engages a forensics firm before notifying the insurer
  • Assumes disconnecting a plant is uncontroversial
  • Believes good backups make extortion a non-event
  • Thinks the note is the start of the intrusion

context

open as a page

Executives want to pay an extortion demand to prevent publication — what must the pre-decided ransom position answer?

level: principalimportance: must knowfreq 57%

basics

~20 s

It must separate buying a decryption tool from buying a promise to delete stolen data, and settle in advance who signs, whether sanctions screening and insurer consent allow payment at all, and that engaging a negotiator is not the same as paying.

open as a page

In a ransomware playbook, what must pre-delegated authority to disconnect the virtualisation management network specify?

level: middleimportance: should knowfreq 50%

basics

~20 s

A tight observable trigger, a bounded scope with explicit never-touch systems, an isolation method that preserves evidence, a notify-within deadline, who may reconnect and on what proof, and contractual cover so the delegate actually acts.

open as a page

An extortion leak site lists your company with a 2.1 TB claim and a 72-hour timer — what does that prove?

level: seniorimportance: nice to knowfreq 31%

basics

~20 s

It proves the actor published a claim and, if a sample is posted, possesses at least what is in that sample. The volume figure is unverified, the timer is a negotiating lever they set, and absence from the site would prove nothing.

open as a page