Ransomware Response Checklist (Free Template) for Small Businesses

Cyberlords Editorial Team

Ransomware Response Checklist (Free Template) for Small Businesses

Every 11 seconds, a business is hit by ransomware. If you run a small business, the odds are stacked against you: the Verizon Data Breach Investigations Report (DBIR) 2025 found that 88% of breaches at small and medium-sized businesses involved ransomware, compared to 39% at larger organizations. Having a ransomware response checklist is no longer optional—it is a survival tool.

This guide gives you a free, copy-paste checklist and downloadable template based on guidance from CISA, NIST SP 800-61 Rev 3, and the FBI. It covers every step from the moment you suspect an attack through full recovery and post-incident review.

Quick Summary

  • Ransomware is the #1 breach threat for small businesses — 88% of SMB breaches (Verizon DBIR 2025).
  • The FBI advises against paying the ransom — 64% of victims now refuse to pay (Verizon DBIR 2025).
  • A documented response checklist reduces downtime by giving your team a step-by-step playbook under pressure.
  • This article includes a free, copy-paste ransomware response template you can customize today.
  • The checklist follows the NIST Cybersecurity Framework 2.0 lifecycle: Identify → Protect → Detect → Respond → Recover.

Why Every Small Business Needs a Ransomware Response Checklist

The Numbers Are Clear

Statistic Source
88% of SMB breaches involved ransomware Verizon DBIR 2025
44% of all breaches globally involved ransomware (up 37% YoY) Verizon DBIR 2025
3,156 ransomware complaints filed in 2024 FBI IC3 2024 Report
$16.6 billion in total cybercrime losses reported in 2024 FBI IC3 2024 Report
64% of ransomware victims refused to pay the ransom Verizon DBIR 2025
Median ransom demand dropped to $115,000 Verizon DBIR 2025
NIST SP 800-61 Rev 3 updated in April 2025 NIST 2025

Ransomware is no longer a sophisticated, targeted weapon reserved for enterprise corporations. As we explained in our guide to Ransomware-as-a-Service (RaaS), RaaS has industrialized these attacks, making small businesses the preferred target because they tend to have weaker defenses and fewer resources to resist payment.

What Happens Without a Plan

When ransomware strikes, panic sets in fast. Employees make mistakes: they reboot infected machines (which can trigger encryption on more files), they try to negotiate with attackers without legal guidance, or they wipe machines before evidence can be preserved.

A written, tested checklist prevents all of these errors.


The Complete Ransomware Response Checklist

This checklist follows the NIST Cybersecurity Framework 2.0 structure and CISA's #StopRansomware guidance. Print it, laminate it, and keep a copy next to your server rack—and a second copy offline.

Phase 1: Immediate Containment (First 30 Minutes)

  • Confirm the ransomware incident — Verify it is ransomware and not a false positive. Look for ransom notes, encrypted file extensions (.locky, .ryuk, .encrypted), and locked screens.
  • Alert the incident response lead — Call (do not email) the designated incident response lead. Email may be compromised.
  • Isolate affected systems immediately — Disconnect infected machines from the network (pull Ethernet cables, disable Wi-Fi). Do NOT power them off yet—evidence may reside in memory.
  • Disable Wi-Fi and Bluetooth on affected devices — Prevent lateral spread through wireless connections.
  • Isolate backup systems — Disconnect all backup drives, NAS devices, and cloud sync services immediately to prevent backup encryption.
  • Take screenshots of ransom notes — Photograph or screenshot any ransom messages for evidence and law enforcement reporting.
  • Document the timeline — Start a written log with timestamps: when the attack was discovered, by whom, and what actions have been taken.

Phase 2: Assessment and Communication (First 2 Hours)

  • Determine the scope of the attack — Identify which systems, servers, and data are affected. Check shared drives, databases, email servers, and cloud storage.
  • Identify the ransomware variant — Use free tools like ID Ransomware or No More Ransom to identify the variant. A free decryptor may already exist.
  • Notify your cyber insurance carrier — Call your insurer's incident response hotline. Many policies include access to forensic investigators and legal counsel.
  • Engage legal counsel — Ransomware often involves data exfiltration, which may trigger breach notification laws (GDPR 72-hour rule, US state notification laws, HIPAA).
  • Activate your communications plan — Designate one spokesperson. Draft internal and external communication templates. Do NOT publicly confirm the attack until legal counsel advises.
  • Preserve evidence — Do not wipe or rebuild machines yet. Forensic investigators need disk images, memory dumps, and network logs.

Phase 3: Reporting (First 24 Hours)

  • Report to the FBI IC3 — File a complaint at ic3.gov. Include the ransomware variant, ransom amount, Bitcoin wallet address (if provided), and timeline.
  • Report to CISA — Submit at cisa.gov/report. CISA can provide free technical assistance through its regional teams.
  • Notify affected data subjects — If personal data was exfiltrated, follow your jurisdiction's breach notification requirements. GDPR mandates notification within 72 hours.
  • Notify business partners and vendors — If the attacker accessed shared systems or partner data, notify affected parties promptly.

Phase 4: Recovery (24–72 Hours)

  • Verify backup integrity — Before restoring, confirm that backups are clean and not encrypted. Test restoring a small sample of files first.
  • Rebuild from known-clean images — Do not simply "decrypt" and continue using compromised machines. Wipe and rebuild from trusted OS images and verified backups.
  • Reset all credentials — Change every password in the organization, starting with admin and service accounts. Enforce multi-factor authentication (MFA) across all systems.
  • Patch the entry point — Work with your IT team or a cybersecurity firm to identify how the attacker got in (phishing email, unpatched VPN, exposed RDP) and close that vulnerability immediately.
  • Monitor for re-infection — Attackers often leave backdoors. Implement enhanced monitoring (EDR, network traffic analysis) for at least 30 days post-recovery.
  • Restore operations in phases — Bring critical systems online first (email, finance, customer-facing services), then secondary systems.

Phase 5: Post-Incident Review (Within 2 Weeks)

  • Conduct a formal post-mortem — Document what happened, the timeline of response, what worked, and what failed.
  • Update your incident response plan — Incorporate lessons learned into the checklist and IR plan.
  • Conduct a tabletop exercise — Schedule a team exercise simulating the same scenario to test the updated plan. CISA offers free Tabletop Exercise Packages.
  • Review your backup strategy — Verify you follow the 3-2-1 rule: 3 copies, 2 media types, 1 offline. Consider immutable backups (WORM storage).
  • Schedule a vulnerability assessment — Engage a professional to identify remaining weaknesses across your infrastructure. See our penetration testing cost guide for budgeting.

Common Mistakes During a Ransomware Incident

Avoid these errors—each one is based on real cases our team has encountered:

  • Rebooting infected machines — This can trigger secondary encryption payloads and destroys volatile memory evidence.
  • Paying the ransom without consulting law enforcement — Payment does not guarantee recovery. The FBI IC3 reports that many victims who pay never receive a working decryption key.
  • Communicating via compromised email — If the attacker is inside your email system, they can read your response strategy. Use out-of-band communication (phone calls, personal email, messaging apps).
  • Deleting ransomware artifacts before forensics — Ransom notes, encrypted file samples, and malware executables are evidence. Forensic teams need them to determine scope, identify the variant, and find the entry point.
  • Neglecting to reset ALL credentials — Changing only the admin password is insufficient. Attackers often create hidden accounts or harvest credentials from multiple users.
  • Restoring from the most recent backup — If the attacker was inside your network for days or weeks before detonation, your most recent backup may contain backdoors. Restore from a backup predating the compromise.
  • Ignoring regulatory reporting obligations — Failing to report within required timelines (GDPR's 72 hours, US state laws, HIPAA) can result in fines on top of recovery costs.

Ransomware Response Template (Copy and Customize)

Copy the template below into your own document, fill in the placeholders, and distribute it to your incident response team. Keep printed copies in accessible locations.

====================================================
RANSOMWARE RESPONSE PLAN — [YOUR COMPANY NAME]
====================================================
Version: 1.0
Last Updated: [DATE]
Document Owner: [NAME / TITLE]
Review Frequency: Quarterly

----------------------------------------------------
SECTION 1: INCIDENT RESPONSE TEAM CONTACTS
----------------------------------------------------
Role                    | Name         | Phone         | Email
------------------------|--------------|---------------|------------------
IR Lead                 | [Name]       | [Phone]       | [Email]
IT Administrator        | [Name]       | [Phone]       | [Email]
Legal Counsel           | [Name]       | [Phone]       | [Email]
Cyber Insurance Contact | [Name]       | [Phone]       | [Email]
External IR Firm        | [Name]       | [Phone]       | [Email]
Communications Lead     | [Name]       | [Phone]       | [Email]
CEO / Owner             | [Name]       | [Phone]       | [Email]

----------------------------------------------------
SECTION 2: IMMEDIATE ACTIONS (FIRST 30 MINUTES)
----------------------------------------------------
1. Confirm the incident is ransomware (not a false alarm).
2. CALL (do not email) the IR Lead.
3. Disconnect affected machines from the network.
4. Disconnect all backup drives and cloud sync services.
5. Screenshot ransom notes.
6. Begin written incident log with timestamps.

----------------------------------------------------
SECTION 3: ASSESSMENT AND COMMUNICATION (2 HOURS)
----------------------------------------------------
1. Map the scope: which systems/data are affected?
2. Identify the ransomware variant using ID Ransomware.
3. Call cyber insurance carrier.
4. Engage legal counsel.
5. Brief the CEO / Owner.
6. Preserve all evidence — do NOT wipe machines.

----------------------------------------------------
SECTION 4: REPORTING (24 HOURS)
----------------------------------------------------
1. File report with FBI IC3 (ic3.gov).
2. Report to CISA (cisa.gov/report).
3. Notify affected data subjects (if required).
4. Notify business partners with shared data access.

----------------------------------------------------
SECTION 5: RECOVERY (24–72 HOURS)
----------------------------------------------------
1. Verify backup integrity (test sample restore).
2. Rebuild machines from clean images.
3. Reset ALL credentials. Enable MFA.
4. Patch the confirmed entry point.
5. Deploy enhanced monitoring for 30+ days.
6. Restore operations: critical systems first.

----------------------------------------------------
SECTION 6: POST-INCIDENT REVIEW (WITHIN 2 WEEKS)
----------------------------------------------------
1. Hold a formal post-mortem meeting.
2. Update this plan with lessons learned.
3. Schedule a tabletop exercise.
4. Review and upgrade backup strategy (3-2-1 rule).
5. Commission a vulnerability assessment.

----------------------------------------------------
SECTION 7: KEY EXTERNAL RESOURCES
----------------------------------------------------
FBI IC3 Reporting:          https://www.ic3.gov
CISA Incident Reporting:    https://www.cisa.gov/report
No More Ransom Project:     https://www.nomoreransom.org
ID Ransomware:              https://id-ransomware.malwarehunterteam.com
NIST SP 800-61 Rev 3:       https://csrc.nist.gov/publications/detail/sp/800-61/rev-3/final
CISA Tabletop Exercises:    https://www.cisa.gov/cisa-tabletop-exercises-packages
====================================================

Download: What the Template Includes

The Cyberlords Ransomware Response Template is a ready-to-use document that contains:

  • Incident response team contact sheet — Fill-in-the-blank table for your key contacts (IT, legal, insurance, external responders).
  • Step-by-step response checklist — Organized by phase (containment → assessment → reporting → recovery → review).
  • Communication templates — Draft messages for internal staff, external partners, and regulators.
  • Evidence preservation checklist — What to capture and how to store it before forensic review.
  • Post-incident review form — Structured template for documenting lessons learned.

To receive the downloadable Excel/PDF version of this template, contact us and we will send it to your email within 24 hours — free of charge.


Citations and References

All statistics and recommendations in this article are drawn from the following credible sources:

  1. Verizon Data Breach Investigations Report (DBIR) 2025 — Verizon, 2025. Ransomware involved in 88% of SMB breaches; 44% of all breaches globally; 64% of victims refused to pay; median ransom $115,000.
  2. FBI Internet Crime Complaint Center (IC3) 2024 Internet Crime Report — FBI, April 2025. $16.6 billion in reported cybercrime losses; 3,156 ransomware complaints; 67 new variants identified including Akira, LockBit, RansomHub.
  3. NIST Special Publication 800-61 Revision 3 — NIST, April 2025. Updated incident response guidance aligned with CSF 2.0.
  4. NIST IR 8374 Rev 1: Ransomware Risk Management — NIST, January 2025. Ransomware-specific guidance mapped to CSF 2.0.
  5. CISA #StopRansomware Guide — CISA, updated 2023. Ransomware best practices including the 3-2-1 backup rule, MFA, and incident reporting.
  6. CISA Ransomware Readiness Assessment (RRA) — CISA. Free self-assessment tool for organizations.

How Cyberlords Can Help

Ransomware readiness is not just about having a checklist—it is about testing that checklist before an attack happens.

At Cyberlords, our incident response services help small businesses:

  • Build and test incident response plans tailored to your environment.
  • Run tabletop exercises so your team practices the response before the real thing.
  • Conduct vulnerability assessments to close the entry points attackers exploit.
  • Provide rapid-response forensic investigation if an incident has already occurred.

If you want help implementing this checklist or need a professional assessment of your ransomware readiness, contact the Cyberlords team today.


Frequently Asked Questions

What is a ransomware response checklist?

A ransomware response checklist is a step-by-step document that guides your organization through the critical first hours and days after a ransomware attack. It covers isolation of infected systems, internal and external communications, evidence preservation, recovery from backups, regulatory reporting, and post-incident improvements. Having a pre-written checklist prevents costly mistakes under pressure.

Should a small business pay the ransom?

The FBI and CISA strongly advise against paying ransoms. Payment does not guarantee you will receive a working decryption key, and it directly funds further criminal activity. According to the Verizon DBIR 2025, 64% of ransomware victims now refuse to pay. Focus your budget on offline backups, tested recovery procedures, and professional forensic support instead.

How long does it take to recover from a ransomware attack?

Recovery time depends on the scale of the attack, the quality of your backups, and the availability of professional support. Small businesses with tested, offline backups can often resume essential operations within 48-72 hours. Without backups, recovery may take weeks or months, and costs typically range from tens of thousands to hundreds of thousands of dollars in downtime, legal fees, and remediation.

Who should I report a ransomware attack to?

In the United States, report to the FBI Internet Crime Complaint Center (IC3) at ic3.gov and to CISA at cisa.gov/report. CISA can provide free technical assistance. In the EU, notify your national data protection authority within 72 hours under GDPR. Also notify your cyber insurance carrier immediately, as many policies require prompt notification to maintain coverage.

What is the 3-2-1 backup rule?

The 3-2-1 backup rule is a time-tested strategy recommended by CISA: keep three copies of your data, stored on two different types of media (e.g., local disk and cloud), with one copy stored offsite or completely offline. The offline copy is critical because modern ransomware actively searches for and encrypts network-accessible backups, including cloud storage that is mapped as a network drive.

Do I need an incident response plan if I have cyber insurance?

Yes. Cyber insurance covers financial losses after an incident, but it does not tell your employees what to do during the critical first minutes of an attack. Many cyber insurance carriers now require a documented incident response plan as a policy condition. A tested plan ensures faster containment, lower losses, and smoother interaction with your insurer's response team.

Can ransomware spread to cloud backups?

Yes. If cloud storage is mapped as a network drive or synchronized automatically (e.g., OneDrive, Dropbox, Google Drive sync clients), ransomware can encrypt those files just like local files. Protect yourself by using immutable backup storage (Write Once, Read Many), disabling auto-sync during an incident, and keeping at least one backup completely air-gapped.

What is the average cost of a ransomware attack on a small business?

Direct ransom demands have a median of $115,000 according to the Verizon DBIR 2025, but total costs are significantly higher. When you factor in operational downtime, forensic investigation, legal and compliance costs, customer notification, and reputational damage, the total impact for a small business often reaches several hundred thousand dollars. Investing in prevention and a tested response plan is far more cost-effective.

ransomware response checklist overview

Key decisions, risks, and implementation actions for ransomware response checklist.

WhatsApp