#StopRansomware Guide
The federal guide to preventing ransomware and to responding when it happens.
Why it matters
The response checklist is worth reading before you need it, not during.
What the first hours look like when CAD, records or email are gone, who decides what comes back first, and how a department keeps answering calls while it happens.
A cyber incident is a continuity problem before it is a technical one. The question on the first morning is not how the attacker got in. It is whether you can still take a call, dispatch a unit, alert a station, document a patient and pay your people, and for how long you can do all of that on paper. Most departments discover their real dependencies during the outage. Station alerting turns out to run through the same network as email. The pre-plans are in a cloud system nobody can reach. The ePCR queues locally but cannot transmit, so the hospital gets nothing. Payroll is a city system, and the city is also down. Restoration is a command decision, not an IT one. Someone has to say what comes back first, and that order should be written before the incident, not argued during it. Dispatch and alerting almost always lead. What follows them depends on your operation, and the useful exercise is to put the list in order now, with the people who would have to live with it. Recovery is also staged rather than instant. Systems come back partially, in a rough order, sometimes into a rebuilt environment, and a department can spend weeks operating in a mixed state where some things work and some do not. Plan for the mixed state, because that is where most of the time is actually spent. For EMS there is an added layer. Patient information is protected health information, and an incident touching an ePCR system brings notification and privacy obligations that run in parallel with the operational response. Know before the day comes who makes that call in your organisation. None of this is an argument for alarm. It is the same reasoning behind a pump failure plan or a mutual aid agreement: decide in advance how you keep working when a thing you rely on is unavailable.
If you read one thing on this subject, read this.
The federal guide to preventing ransomware and to responding when it happens.
Why it matters
The response checklist is worth reading before you need it, not during.
The city's own review of the May 2023 incident that affected police, fire and city systems.
Why it matters
A public-safety continuity case study from the organisation that lived it. Read it for system interdependency, manual operations, the order things were restored in, and how long staged recovery actually took — not as a reason to be frightened.
The federal hub for ransomware guidance, alerts and reporting.
Why it matters
Where to go on the day, including who to report to.
Planning to operate through a loss of systems, and to recover in a defined order.
Why it matters
The structure behind a restoration priority list you can agree before an incident.
Everything above was published by someone else, and is here because it is the clearest treatment of the subject we could find and verify. The Hub’s own guide to this topic is still being written. If you know a better source than the ones listed, that is worth telling us before it is.
Send a note