Part IV. Respond
Fighting Through the Crisis When Ransomware Strikes
The NIST Cybersecurity Framework’s Respond function is about taking action when a cybersecurity incident is detected. When ransomware breaches your perimeter, your ability to respond quickly and effectively determines whether you recover in days or struggle for months. This section walks you through the actual fight – hour by hour, decision by decision.
Chapter 9, “The First 12 Hours”, throws you into the fog of war with ransomware actively spreading across your network. You’ll navigate the impossible decisions about containment versus business continuity and ransom payment legality.
Chapter 10, “The Marathon”, tackles the marathon phase after initial containment, balancing technical response with business operations. You’ll learn degraded operations strategies, manage the human toll on your team, and handle the curveballs that no tabletop exercise prepared you for.
Chapter 11, “Analyzing the Breach”, helps you methodically identify ransomware variants, map infection scope, and explore decryption options. You’ll master essential analysis techniques from VirusTotal to sandboxing that work for organizations of any size.
Chapter 12, “Advanced Analysis and Forensics”, covers specialist techniques for when basic analysis isn’t enough—YARA rules, reverse engineering, memory forensics with Volatility, and comprehensive ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access