What problem does it solve?
Standard incident response playbooks do not cover ransomware-specific decision points including OFAC and cross-jurisdiction sanctions screening, decryptor availability lookup, cyber-insurance carrier notification requirements, immutable backup viability testing, and exfil-before-encrypt breach classification, leaving organizations vulnerable to legal penalties, insurance denial, and incomplete recovery during ransomware incidents.
Core Features & Use Cases
- Cross-Jurisdiction Sanctions Screening: Automate checks against OFAC SDN, EU Reg 2014/833, UK OFSI, AU DFAT, and JP MOF sanctions lists to block illegal ransom payments and avoid federal-law violations.
- Decryptor Availability Lookup: Integrate No More Ransom Project and vendor-specific decryptor catalogs to identify free decryption options before considering ransom payment.
- Cyber-Insurance Workflow Integration: Enforce 24h carrier notification and pre-approval requirements to prevent policy voiding and ensure coverage for incident response costs.
- Immutable Backup Viability Testing: Validate that backup snapshots are truly immutable and recoverable before relying on them for restoration.
- Parallel Breach Notification: Classify exfil-before-encrypt as a distinct breach trigger to meet overlapping regulatory clocks (NIS2 24h, GDPR 72h, HIPAA 60d, SEC 8-K 4 days, etc.) independent of the encryption event.
- Use Case: A healthcare organization hit by ALPHV/BlackCat ransomware with PHI exfiltrated before encryption uses this skill to screen the threat actor against sanctions, confirm no decryptor is available, notify its cyber insurer within the 24h window, test immutable backup restore, and trigger HIPAA and GDPR breach notifications on the exfiltration event separately from the encryption event.
Quick Start
Use the ransomware-response skill to guide your incident response team through the full ransomware decision workflow, from encryption confirmation and sanctions screening to decryptor lookup, insurance notification, and regulatory breach reporting, for any active ransomware incident.