Guides 7 min read

Ransomware Decision Tree: What to Decide Before the Attack

Kyanite Blue Labs, Threat Intelligence·11 September 2026

The Call You Are Not Ready For

It is a Wednesday morning. Someone on your IT team notices that file names across three servers have changed. Within the hour, a ransom note appears on a dozen screens. The attacker has been inside your network for eleven days. What happens next is not decided in that moment. It was decided — or left undecided — weeks or months earlier. The organisations that respond well to ransomware are not necessarily the ones with the most sophisticated technology. They are the ones that had a documented decision tree sitting in a folder that everyone in the room had actually read. According to Verizon's 2024 Data Breach Investigations Report, the median time for an attacker to begin exfiltrating data after gaining access is under 24 hours. That means by the time most organisations detect a breach, the data has already left the building. Decisions made in the first two hours of a ransomware incident will shape everything that follows — including whether you pay, what you recover, and how much operational damage you absorb. Those decisions cannot be improvised.

What Is a Ransomware Decision Tree and Why Does It Matter?

A ransomware decision tree is a pre-agreed framework that maps out who decides what, under what conditions, and in what order, during a ransomware incident. Think of it as a flowchart for crisis decisions — not a rigid script, but a structure that stops senior leadership from having to think from first principles while their systems are burning. The concept was explored in depth by Kerri Shafer-Page, VP of Incident Response at Arctic Wolf, in a recent Help Net Security interview. She identified four areas where decisions must be settled in advance: containment, extortion response, communication, and recovery sequencing. Each one represents a point in a ransomware incident where delay or confusion directly worsens the outcome. For UK businesses specifically, the stakes extend beyond operational disruption. Under the UK GDPR and the Data Protection Act 2018, organisations have 72 hours to report a personal data breach to the Information Commissioner's Office (ICO). A poorly structured response plan — or no plan at all — makes that deadline nearly impossible to meet while simultaneously managing an active incident.

The Four Decisions That Cannot Wait Until the Incident Starts

Each of the four decision areas has a specific failure mode when left unresolved. Here is what needs to be settled before any attacker gets the chance to force your hand.

  • Containment authority: Who is authorised to take a system offline during an active incident? This question sounds straightforward until you consider that pulling a database server might halt a manufacturing line, break a client-facing portal, or corrupt a payment pipeline. The person making that call needs to understand the network topology and the business impact — not just the security risk. In practice, that means a containment authority matrix: a named individual or role for each critical system, with documented dependencies and pre-approved kill switches.
  • Extortion response: Does your organisation have a defined policy on ransom payment? Who is authorised to approve one? What is the financial threshold above which board sign-off is required? These questions need legal counsel, insurers, and senior leadership involved before an incident — not during one. Note that paying a ransom to a sanctioned entity is illegal under UK law regardless of operational pressure. The Office of Financial Sanctions Implementation (OFSI) maintains a list of sanctioned groups, and some ransomware operators appear on it.
  • Communication ownership: Who speaks to the press? Who notifies affected clients? Who handles the ICO notification? These three channels require different tones, different timelines, and different approvals. Without pre-assigned ownership, organisations routinely send contradictory messages to regulators and customers simultaneously, compounding reputational damage on top of operational damage.
  • Recovery sequencing: When systems are restored, in what order do they come back online? The answer is never 'everything at once.' A recovery sequence based on business criticality — prioritising identity infrastructure, then communications, then core operations — cuts downtime substantially. That sequence needs to be agreed, tested, and stored somewhere that is accessible even when your main systems are down.

Why Most Incident Response Plans Fail Under Pressure

The uncomfortable truth is that most organisations have an incident response plan. They just have not tested it, updated it since the network changed, or shared it with anyone outside the IT team. A 2023 study by the Ponemon Institute found that organisations with a tested incident response plan saved an average of $1.49 million (approximately £1.17 million) compared to those that did not — even when both organisations suffered a breach of similar scope. The savings came not from avoiding the attack but from the speed and coherence of the response. There is a structural problem here too. Incident response plans are often built by security teams and live in security team documentation. But the decisions that matter most in a ransomware event — pay or don't pay, shut down or stay running, tell clients now or wait for more information — are business decisions, not technical ones. They require input from legal, finance, operations, and the board. When those stakeholders have never seen the plan, let alone contributed to it, the plan becomes a document rather than a playbook. The first time most executives engage with a ransomware scenario is during a tabletop exercise — if one ever happens. IBM's 2024 Cost of a Data Breach Report found that organisations that regularly conducted incident response exercises reduced their breach costs by 35% compared to those that did not. That number alone should make tabletop exercises a board agenda item, not an IT department afterthought.

How Technology Should Support the Decision Tree, Not Replace It

A decision tree without detection capability is a plan for a scenario you will never see coming. And a detection capability without a decision tree is an alarm system with no one trained to respond to it. The two need to work together. On the detection side, the gap that allows ransomware to cause maximum damage is the period between initial access and detonation — the eleven-day window referenced earlier. Attackers use this time to map the network, harvest credentials, move laterally, and stage data for exfiltration. A 24/7 managed detection and response (MDR) capability, like Sophos MDR, exists specifically to catch that activity during the dwell period, before the ransom note appears. Sophos MDR analysts monitor for behavioural indicators — unusual lateral movement, credential stuffing, large volumes of encrypted traffic leaving the network — that signature-based tools miss. On the data protection side, even a well-executed containment strategy cannot undo data that has already been exfiltrated. This is where BlackFog's anti data exfiltration (ADX) technology changes the equation. BlackFog works at the device level to block unauthorised data transfers in real time, regardless of the encryption method the attacker uses. In a ransomware scenario, this means the attacker loses their leverage. Without exfiltrated data, the double-extortion model — pay us or we publish your data — collapses. You can read more about how BlackFog works at /products/blackfog. For organisations that want to understand what an attacker sees before they decide to target you, Hadrian's continuous attack surface management platform maps your external exposure automatically, flags unpatched assets, and runs AI-driven attack simulations against your perimeter. If your decision tree assumes your backups are clean and your critical systems are isolated, Hadrian can verify whether that assumption is actually true. See /products/hadrian for more detail.

Building the Decision Tree: A Starting Framework for UK Businesses

Building a ransomware decision tree does not require a specialist consultant, though one helps. It requires a structured meeting with the right people in the room and a commitment to document what gets decided. Start with five questions and work through each one until you have a named owner, a defined threshold, and a written answer: 1. Who is authorised to declare a ransomware incident, and what evidence threshold triggers that declaration? 2. Who is authorised to take systems offline, and what is the approval chain for each critical system? 3. What is the organisation's policy on ransom payment, who approves any deviation, and has legal counsel reviewed this policy? 4. Who notifies the ICO, clients, and the press — and in what order, within what timeframe? 5. What is the recovery sequence, where is it stored, and who is responsible for keeping it current? Once those questions have answers, run a tabletop exercise. Introduce a scenario — a finance system encrypted at 3am on a Friday — and walk through the decision tree out loud. The gaps will surface quickly. Fix them before an attacker finds them first.

How to Protect Your Business Against Ransomware

Ransomware preparedness has two layers: the plan and the technology that supports it. Both need to be in place before an incident starts. For UK businesses, Coro provides unified protection across endpoints, email, and cloud environments — stopping ransomware delivery at the most common entry points, including phishing emails and compromised cloud credentials. Coro's unified platform also means your security posture across all three vectors is visible in one place, which matters enormously when you need to make containment decisions quickly. Learn more at /products/coro. If data exfiltration is your primary concern — and in a double-extortion scenario, it should be — BlackFog stops data leaving your network before it reaches the attacker's infrastructure. It operates independently of encryption status, which means it catches exfiltration attempts that encrypted channels would otherwise hide from traditional tools. Check your current data exfiltration exposure in two minutes at /data-exfiltration-risk. For organisations that want 24/7 eyes on the network to catch attacker activity during the dwell period, Sophos MDR provides human-led threat detection and response around the clock. The Sophos MDR team actively hunts for the behavioural signals that precede a ransomware detonation, giving your incident response team time to act before the ransom note appears rather than after. If you are not sure where your biggest exposure sits, the best starting point is a conversation with our team. We work with businesses across the UK, New Zealand, and Australia to assess their current posture and identify the gaps that matter most. Talk to us at /contact — no obligation, no sales pressure, just a clear picture of where you stand.

Frequently Asked Questions

What is a ransomware decision tree?

A ransomware decision tree is a pre-agreed framework that defines who makes which decisions, under what conditions, during a ransomware incident. It covers containment authority, extortion response policy, communication ownership, and recovery sequencing. Having these decisions documented before an incident reduces response time and limits operational damage significantly.

Do UK businesses have to report ransomware attacks to the ICO?

If a ransomware attack involves a personal data breach, UK organisations must notify the Information Commissioner's Office (ICO) within 72 hours under the UK GDPR and Data Protection Act 2018. Failure to report within that window can result in regulatory action. This reporting obligation makes a pre-planned incident response process essential, not optional.

Should businesses pay a ransomware demand?

There is no universal answer, but UK businesses must check the Office of Financial Sanctions Implementation (OFSI) sanctions list before considering payment — paying a sanctioned group is illegal regardless of the circumstances. Beyond the legal risk, paying does not guarantee data recovery or prevent publication of exfiltrated data. Anti-exfiltration tools like BlackFog remove the attacker's leverage before payment becomes a question.

ransomwareincident responseransomware decision treecyber resiliencebusiness continuity

Want to discuss this with our team?

Book a free 20-minute call with David or Max.

Book a call