Download the Cyber Incident Response Playbook

When a cyber incident happens, your team needs to know who is responsible, what to do first, and which decisions cannot wait. Forthright’s Cyber Incident Playbook gives business leaders and technical teams a practical framework to prepare for an attack, respond under pressure, and recover safely.

What You’ll Learn in the Playbook

The guide follows the full life of a cyber incident, from preparation through response and recovery. It includes a detailed ransomware example, guidance for other common threats, and templates your team can adapt to your business.

  • What to do first when you discover a possible cyber incident.
  • How to respond to ransomware, including containment, backup protection, and recovery decisions.
  • Who should lead the response and when to involve IT, leadership, legal counsel, and your insurer.
  • What obligations to check, including potential notification requirements.
  • How to document decisions and evidence using incident logs and communication templates.
  • How to prepare for other threats, including business email compromise, account takeover, data theft, and insider threats.
  • Bonus: Cybersecurity Self-Assessment 

Has Your Business Been Hit by Ransomware?

If your systems are locked, you have received a ransom demand, or you suspect an attacker is still in your network, you need direct help now. Forthright helps businesses respond to ransomware and other cybersecurity incidents. Call (855) 796-3381 for 24/7 assistance rather than waiting to work through the guide on your own.

What should a business do first after a ransomware attack?

Contact your incident response team and begin documenting what you observe and the actions taken. A qualified responder can help isolate affected systems, protect backups, and preserve evidence while the team determines the scope of the attack.

Should we restore our systems from backup right away?

Restoring too soon can put clean data at risk if an attacker still has access to your environment. The playbook explains why teams should contain the threat, verify backups, and test recovery in an isolated environment before returning systems to service.

Should we call our insurance company after a ransomware attack?

Yes, if you have cyber insurance, notify your insurer promptly and follow the reporting instructions in your policy. Your insurer may have an incident hotline and requirements for using response providers or approving expenses, so involve them before making major response or payment decisions.

Does a ransomware attack mean our data was stolen?

Not necessarily, but some ransomware incidents involve data theft as well as encryption. Your response team should investigate what happened before making decisions about customer communications or potential notification obligations.

Should we pay the ransom?

Do not make a payment decision under pressure or without involving your leadership, legal counsel, incident response team, and insurer. The FBI does not support paying a ransom because payment does not guarantee you will get your data back.

Can the Cyber Incident Playbook replace an incident response team?

No. The playbook helps your team understand the response process and make more informed decisions, but an active attack calls for direct help from qualified professionals. If you are dealing with ransomware now, call Forthright at (855) 796-3381.