During a ransomware incident, the first hour is chaotic. People are asking whether to shut down computers, whether to call the insurer, whether customers should be told, and who has authority to decide. Phone numbers are on a server that is now encrypted. The one person who knows the backup password is on vacation.
A simple contact sheet and roles list, prepared in advance, removes much of that confusion. It is one of the cheapest and most valuable parts of an incident plan.
Why prepare this ahead
Decisions made under stress are worse and slower. A prepared sheet gives everyone a clear sequence and names responsible people. It also makes sure you can reach those people even when email and the network are unavailable.
Roles to assign
For a small or mid-size company, a person may hold more than one role, but each role should have a named owner and a backup.
- Incident lead. Coordinates the response and makes decisions, often an owner or senior executive.
- Technical lead. Directs containment and recovery, usually your IT provider or internal IT lead.
- Communications lead. Handles messages to employees, customers, and partners.
- Finance lead. Works with banks, insurers, and tracks costs.
- Operations lead. Decides how to keep jobs or field operations running manually.
- Legal and compliance contact. Advises on notification obligations and contract duties.
- Scribe. Records what happens and when, which supports insurance, legal, and learning.
Contacts to include
For each, list name, role, direct mobile number, alternate number, and personal email for use if company email is down.
- Internal incident team members and their backups
- Your managed IT or security provider, including the emergency line
- Cyber insurance carrier and policy number, along with the claim reporting instructions
- Your insurance broker
- Outside legal counsel
- Your bank contacts, for payment issues
- Key software vendors, such as accounting and project platforms
- Internet and telecom providers
- Law enforcement contacts, such as your local FBI field office, and CISA's reporting channels
- Major customers or primes with contractual notification clauses
Check your insurance policy before an incident, since some policies require prompt notice and use of approved vendors. Following the terms can affect coverage.
Where to keep it
The sheet must be accessible when systems are down.
- Print copies and keep them in the office, in the incident lead's vehicle, and in a secure place at home
- Store a copy on personal phones of key staff
- Keep an offline digital copy on an encrypted USB drive in a safe
- Update it every quarter and whenever personnel change
Include first-step guidance
Beside the contacts, add a short checklist. Adapt it with your IT provider.
- Isolate affected devices from the network by unplugging network cables or disabling Wi-Fi, rather than powering off, unless advised otherwise.
- Do not delete anything or run random cleanup tools.
- Call the technical lead and the incident lead immediately.
- Notify the insurer as the policy directs.
- Start the incident log with times and actions.
- Do not contact the attackers or pay anything without involving legal counsel and your insurer.
- Keep communications to approved channels, and avoid discussing details on compromised email.
Plan how you will communicate
If email is compromised, decide in advance how you will reach employees, such as a group text, a phone tree, or a messaging service that was set up separately. Prepare brief template messages for employees, customers, and partners, so you only need to fill in details.
Practice it
Run a short tabletop exercise once or twice a year. Consider a hypothetical scenario in which the file server is encrypted on a Monday morning. Ask each person what they would do first, who they would call, and how they would communicate. Note gaps, such as an outdated number or a role nobody has claimed, and fix them.
Keep it current
People change jobs and phone numbers. Add contact review to your quarterly checklist, along with testing the backup restore and reviewing the insurance policy.
Where Ironfield Cyber helps
Ironfield Cyber helps contractors and energy companies prepare for ransomware, including incident response plans, contact sheets, tabletop exercises, and backup recovery testing. If you would like help building a one-page sheet that fits your company, we can work through it with you.