24/7 INCIDENT RESPONSE
(877) 259-0509

RANSOMWARE & CYBER EXTORTION RESPONSE

Ransomware Response
Built on Evidence.

Cyber Centaurs helps organizations respond to ransomware and cyber-extortion incidents by preserving critical evidence, investigating threat-actor activity, determining affected systems and accounts, evaluating potential data exfiltration, and supporting informed containment and recovery decisions.

WHEN TO ENGAGE

When Ransomware
Disrupts the Environment.

Ransomware incidents can involve far more than encrypted systems. Threat actors may obtain credentials, establish persistence, move through the network, access sensitive information, stage data, or maintain access before encryption becomes visible. Early investigation helps preserve the evidence needed to understand the incident.

Encrypted Servers or Workstations

Ransom Note or Extortion Demand

Threat Actor Claims of Data Theft

Suspicious Remote Access Activity

Compromised Administrative Credentials

Uncertain Scope or Initial Access

RESPONSE OBJECTIVES

Stabilize the Incident.
Preserve the Evidence.

The first priorities are to reduce ongoing risk, protect the available evidentiary record, determine the scope of threat-actor access, and support recovery without unnecessarily destroying evidence needed to understand what occurred.

Stabilize

Reduce immediate risk, identify known affected systems, and support containment decisions appropriate to the environment.

Preserve

Protect volatile and persistent evidence, logs, affected systems, cloud records, security telemetry, and other sources relevant to the investigation.

Investigate

Reconstruct initial access, credential use, persistence, lateral movement, execution, data access, and other threat-actor activity where evidence permits.

Support Recovery

Provide evidence-based findings that help inform eradication, restoration, credential resets, system recovery, and other remediation decisions.

INVESTIGATIVE EVIDENCE

Evidence Across the
Compromised Environment.

Ransomware investigations may require evidence from endpoints, servers, identity systems, cloud platforms, security tools, network infrastructure, and data repositories. Correlating those sources can help reconstruct threat-actor activity before, during, and after encryption. Related incident-response work may involve data breach investigation and incident response.

Endpoints & Servers

event logs

execution artifacts

services

scheduled tasks

persistence

file-system evidence

Identity & Authentication

account activity

authentication logs

MFA events

privileged access

credential use

Cloud & Email

Microsoft 365

Entra ID

email

cloud storage

audit records

account activity

Network & Security Telemetry

firewalls

EDR / XDR

DNS

proxy

network logs

security alerts

Data Access & Exfiltration

file access

staging

archive creation

cloud transfer

external sharing

potential exfiltration activity

Remote Access & Administration

VPN

RDP

remote-management tools

MSP access

administrative utilities

INVESTIGATIVE QUESTIONS

What Happened Before
the Encryption?

Encryption is often the final visible stage of a longer intrusion. The investigation should examine the activity that preceded it, determine what systems and accounts were involved, and evaluate what the available evidence supports concerning access, persistence, and data exposure.

How Did the Threat Actor Gain Access?

Evaluate available evidence concerning compromised credentials, exposed services, remote access, vulnerabilities, phishing, third-party access, or other potential entry activity.

Which Systems and Accounts Were Affected?

Determine the endpoints, servers, identities, administrative accounts, cloud resources, and other systems implicated by the available evidence.

How Did the Threat Actor Move Through the Environment?

Reconstruct relevant credential use, remote sessions, administrative tools, lateral movement, privilege changes, and other activity.

Was Persistence Established?

Examine evidence of services, scheduled tasks, accounts, remote tools, malware, configuration changes, or other mechanisms that may have enabled continued access.

Was Sensitive Data Accessed or Removed?

Evaluate evidence of file access, staging, archive creation, cloud transfers, external sharing, or other potential data-exfiltration activity.

What Must Be Addressed Before Recovery?

Identify supported indicators of compromise, affected accounts or systems, persistence concerns, and other findings relevant to eradication and restoration decisions.

RANSOMWARE RESPONSE PROCESS

Controlled Response.
Evidence-Based Recovery.

The response process is structured to establish control, preserve evidence, investigate the intrusion, determine impact, and support recovery decisions according to what the available technical record supports.

01

Triage & Stabilize

Establish immediate priorities, identify known affected systems, understand current containment actions, and assess ongoing risk.

02

Preserve & Collect

Protect and acquire relevant endpoint, server, identity, cloud, network, security, and other evidence before remediation changes the record.

03

Investigate Threat Activity

Analyze initial access, credential use, persistence, execution, lateral movement, administrative activity, data access, and encryption-related events.

04

Determine Scope & Impact

Correlate evidence to establish affected systems and accounts, evaluate potential data exposure, identify unresolved risks, and define the supported scope of the incident.

05

Support Recovery & Report

Provide findings relevant to eradication and restoration, document investigative conclusions and limitations, and communicate results to technical teams, leadership, counsel, and other authorized stakeholders.

BREACH IMPACT

Encryption Is Only
Part of the Question.

Modern ransomware incidents frequently include claims that sensitive information was accessed or removed before encryption. Those claims should be evaluated against the available evidence rather than accepted or dismissed without investigation.

File Access Activity

Evidence concerning access to sensitive folders, shares, repositories, or data sources.

Data Staging

Evidence of files being collected, reorganized, copied, or prepared for potential transfer.

Archive Creation

Creation or use of compressed archives and other mechanisms associated with data preparation.

External Transfers

Cloud uploads, file-transfer utilities, external sharing, remote destinations, or other potential transfer activity.

Threat Actor Claims

Comparison of extortion statements, sample files, leak claims, or other assertions against the available technical record.

Supported Breach Scope

Findings concerning confirmed activity, potential exposure, evidentiary limitations, and questions that remain unresolved.

RECOVERY DECISIONS

Recover With a Clearer
Understanding of the Incident.

Recovery should address more than encrypted files. Organizations need to understand what access the threat actor obtained, whether persistence remains, which credentials or systems require remediation, and what risks may remain when services return to operation.

Eradication Priorities

Identify supported indicators, persistence mechanisms, malicious tooling, compromised accounts, or other findings relevant to removing threat-actor access.

Credential & Identity Actions

Support decisions concerning password resets, privileged accounts, MFA, service accounts, remote-access credentials, and identity remediation.

System Restoration

Provide investigative context to help prioritize restoration, rebuilding, validation, and return-to-service decisions.

Residual Risk

Identify unresolved questions, unavailable evidence, remaining investigative concerns, or other factors decision-makers should understand during recovery.

WHY CYBER CENTAURS

Technical Depth.
Investigative Judgment.

Recovery decisions are stronger when the intrusion is understood.

Cyber Centaurs combines incident response, digital forensics, and cybersecurity expertise to investigate ransomware incidents, establish supported findings, and help organizations and counsel make informed containment, recovery, and breach-impact decisions.

Incident Response & Forensic Expertise

Technical investigation across endpoints, servers, identity, cloud, network, security telemetry, and other evidence sources.

Evidence-Driven Investigation

Findings are developed through collection, preservation, analysis, correlation, and validation rather than assumptions about threat-actor activity.

Breach Impact Analysis

Technical evidence is evaluated to help determine affected systems, account activity, potential data exposure, and the supported scope of the incident.

Support for Leadership & Counsel

Findings are communicated clearly to technical teams, executives, legal counsel, insurers, and other authorized stakeholders.

RANSOMWARE RESPONSE FAQ

Practical Questions
During a Ransomware Incident.

Ransomware incidents require rapid decisions while important facts are still developing. These questions address common considerations at the beginning of a ransomware investigation and recovery effort.

What should we do immediately after discovering ransomware?

Take reasonable steps to reduce ongoing risk and prevent further spread, but avoid unnecessary reimaging, deletion, log clearing, or other changes that may destroy useful evidence. Preserve affected systems and available logs where practical, document actions already taken, and contact an incident-response firm to assess investigative and containment priorities.

Should we shut down encrypted systems?

The appropriate action depends on the circumstances. Powering off a system may reduce some risks but can also eliminate volatile evidence. If immediate containment is necessary, take reasonable steps to protect the environment while considering evidence preservation and the operational consequences of the action.

Can you determine how the ransomware attack started?

We investigate available evidence for potential initial-access activity such as compromised credentials, remote access, exposed services, phishing, vulnerabilities, third-party access, or other intrusion paths. Whether a specific initial-access vector can be conclusively established depends on the evidence retained by the environment.

Can you determine whether data was stolen before encryption?

Cyber Centaurs evaluates evidence of file access, staging, archive creation, cloud transfer, external sharing, file-transfer utilities, and other potential exfiltration activity. Whether data removal can be conclusively established depends on the evidence available from affected systems, security tools, network infrastructure, cloud platforms, and other sources.

Can you help determine which systems are safe to restore?

Forensic findings can help identify affected systems, compromised accounts, persistence mechanisms, malicious tooling, and other indicators relevant to recovery decisions. Restoration decisions should consider the investigative findings together with the organization's remediation and recovery strategy.

Do you assist with ransomware negotiation or ransom payments?

Cyber Centaurs' primary role is incident response, forensic investigation, breach-impact analysis, and recovery decision support. If specialized ransomware negotiation or payment services are required, those services can be coordinated with appropriate authorized providers as part of the broader response where necessary.

Do you work with cyber insurers and legal counsel?

Yes. Cyber Centaurs can coordinate investigative work with internal and outside counsel, cyber-insurance stakeholders, executive leadership, IT teams, managed service providers, and other authorized participants involved in the response.

How quickly can ransomware response begin?

Cyber Centaurs maintains availability for urgent cybersecurity incidents. Initial priorities depend on the current state of the environment, containment actions already taken, affected systems, evidence availability, and the resources required for the response. For an active incident, call (877) 259-0509.

ACTIVE INCIDENT

Speak With an
Incident Response Investigator.

Tell us briefly what occurred, when ransomware or suspicious activity was discovered, which systems are affected, and the assistance you need. A member of the Cyber Centaurs team will review your inquiry and follow up directly.

Confidential inquiry. Please do not submit evidence, credentials, ransom notes containing sensitive information, or other sensitive files through this form.

ACTIVE RANSOMWARE INCIDENT

(877) 259-0509

24/7 Incident Response