Use this page to record facts, coordinate containment and evidence work, plan recovery, and identify who must assess notification duties. Adapt it to your environment before an incident.
You can use the checklist without submitting contact details. This web page is the current version; the earlier PDF has been retired.
Working checklist
The order will change with the incident. The incident commander should assign owners, record decisions, and adapt each item to system safety and business impact.
Prepare before an incident
Review this section during planning and tabletop exercises.
Open and triage the incident
Start a reliable record before the team loses track of events.
Contain and preserve
Coordinate risk reduction with evidence work. A single rigid sequence can cause harm.
Scope and remove access
Base remediation on tested evidence, not on a single indicator.
Recover and watch for recurrence
Use documented criteria to return services to normal operation.
Assess notifications and communications
Qualified advisers should apply current rules and contracts to the facts.
Close and improve
Do this after owners agree that active response work has ended.
Ransomware and extortion
Use the approved ransomware plan and current government guidance.
Evidence and containment belong in the same decision log. CISA advises ransomware victims to isolate affected systems promptly. NIST frames incident response as coordinated preparation, detection, response, and recovery. Your responders should choose actions that fit the threat, the system, and the consequences of delay.
Primary sources
Check the current official text before relying on a legal or technical requirement.
Is this checklist a substitute for an incident-response plan or professional advice?
No. Use it as a working prompt and adapt it to your systems, contracts, insurance, jurisdiction, and approved incident-response plan. Your technical responders and legal advisers should make decisions for the incident in front of them.
Does containment have to wait until evidence collection is complete?
No fixed rule works for every incident. The response lead should balance system safety, business impact, evidence needs, and the risk of further harm with technical and legal advisers. CISA's ransomware guidance tells organizations to isolate affected systems promptly, while NIST treats response and recovery as coordinated risk-management work. Record each action and its reason.
Can this checklist set our breach-notification deadlines?
No. Notification duties depend on the organization, affected people, data, location, regulator, contracts, and facts of the incident. Record awareness and discovery times, identify the rules that may apply, and ask qualified counsel to assess them against current official sources.
Does the checklist tell us whether to pay a ransomware demand?
No. A payment decision can involve sanctions, law enforcement, insurance, technical recovery, and business continuity. Bring qualified counsel, the incident lead, the insurer when applicable, and the appropriate authorities into the decision. Use current CISA and OFAC guidance rather than a generic rule.
This checklist provides general operational prompts. It is not legal advice, a certification, or a guarantee that the listed actions fit a specific incident.