SESK: Stuff Everyone Should Know · sesk.info/aero-ransomware-isolate-first
During a ransomware attack, what should defenders do first with the infected computers?
Find them and isolate them from the network right away.
- Pay the attackers immediately
- Find them and cut them off from the network ✔
- Keep using them so work is not lost
Why: Ransomware spreads from computer to computer across a network. So the first job is to figure out which systems are hit and cut them off. If many are hit, the whole network can be taken offline.
Huh, didn't know that: CISA says that if many systems or subnets are hit, take the network offline at the switch level.
Why did the infected laptop sit alone at lunch? It was in isolation mode.
Like this card?
References
Answer: Find them and cut them off from the network. Ransomware spreads from computer to computer across a network. So the first job is to figure out which systems are hit and cut them off. If many are hit, the whole network can be taken offline.
- CISA #StopRansomware Guide www.cisa.gov/stopransomware/ransomware-guide
Determine which systems were impacted, and immediately isolate them.
Checked 2026-10-10.
Think this answer is wrong? Tap "Challenge this answer" on the card in the game and tell us why.
More stuff everyone should know
That's stuff everyone should know.