TecLeads TecLeads Blog
2026-06-30 · 4 min read

Incident Response Runbook: Build It Before Ransomware Hits

Security operations screens with terminal output in a dark room
cybersecurityincident-responseransomwaresoczero-trust

In the first hour of a real incident, almost nobody is doing forensics. People are trying to find out who is allowed to pull the file server off the network, whether legal needs to be on the call, where the cyber insurance policy actually lives, and why the one person with domain admin is on a plane. Meanwhile the attacker, who has done this many times, is the only participant working from a plan.

That gap is the whole argument for a runbook. Not a ninety page policy written for an auditor. A short document that answers, under pressure, the questions that otherwise take a meeting.

A runbook is a set of decisions you made early

The value is not the paper. It is that the arguments happened months ago, in a calm room, and the answers are written down. Who owns the incident the moment it is declared. What containment actions are pre-approved without asking anyone. At what point executives, legal, insurers, and regulators get told. Who speaks to staff and customers, and who explicitly does not.

Every one of those is cheap to decide on a Tuesday afternoon and brutally expensive to negotiate while systems are encrypting.

The five questions a runbook must answer without a meeting:
1. Who owns this incident right now?
2. What can we isolate immediately, without approval?
3. What evidence are we preserving, and who is doing it?
4. Who gets informed, in what order, by whom?
5. How do we communicate if email and chat are compromised?

The first hour is about stopping the bleeding

Ransomware punishes hesitation. The single most valuable pre-approval you can write is isolate-first authority: the on-call engineer may disconnect affected machines, disable accounts, and block traffic without waiting for sign-off, and asking forgiveness is official policy. Wording that sentence and getting an executive signature under it will do more for your response time than any product you could buy.

Two details deserve special attention because they surprise teams every time. First, evidence: the instinct to wipe and rebuild destroys exactly what forensics, insurers, and sometimes law enforcement will ask for, so the runbook should say what gets imaged or preserved before anything is reset. Second, communications: assume the attacker can read your email and your chat. Decide now what the out-of-band channel is, and make sure the phone numbers on the contact sheet are current and printed somewhere that is not on the encrypted file share.

After the bleeding stops

The first day is scoping and eradication: how far did they get, what did they take, which credentials are burned. The first week is recovery order, and this is where an untested plan quietly falls apart, because restoring systems in the wrong order can mean restoring the attacker's access along with the data. Identity infrastructure first, then the systems the business actually bleeds money without, in an order you agreed with the business before anyone was shouting.

Write down the recovery order for your ten most important systems. If you cannot name your ten most important systems, that is finding number one.

Break-glass, tested

Every plan assumes you can log in. Ransomware frequently takes out the identity provider, the password vault, or both. Break-glass means offline copies of critical credentials, a hardware token in a safe, and contact details that survive your infrastructure. It also means testing those credentials quarterly, because a break-glass account whose password expired eight months ago is a prop, not a control.

The tabletop habit

A runbook that has never been exercised is fiction. Once a quarter, ninety minutes, one scenario, the people who would actually be involved. Walk it step by step and write down every moment someone says "I would have to check". Each of those is a gap, and each one found in a conference room is one you will not discover at 2am.

If you only do one thing this week

Put the first tabletop on the calendar. Ninety minutes, one ransomware scenario, the real people. The document can be imperfect; the habit is what compounds.


If this is on your plate, TecLeads does exactly this as part of our Cybersecurity work. If you'd like a second pair of eyes on your setup, book a 30-minute call or explore what we do.

📍 Tech Pulse · today's quick question 🟢 Level: Basic Networking

What does a VPN mainly provide?

Pick an answer to see how other engineers voted.

Want a hand with this?

TecLeads helps engineering teams ship faster and more securely.

Book a 30-minute call

← All posts