Skip to content
Artwork for The Backup Wrap-Up
The Backup Wrap-Up · July 20 · 36 min

Ransomware Response Checklist: Prevent It, Slow It, Survive It

This episode is built around a ransomware response checklist — a three-part Reddit series by a security specialist who goes by snorkel42, breaking down exactly how to prevent, contain, and recover from a ransomware attack. This is an encore episode, and it's back not just because a lot of people downloaded it originally, but because so many of you listened all the way through — some of you more than once. That kind of engagement told us this one was worth bringing back. Curtis Preston and Prasanna Malaiyandi dig into snorkel42's series, which breaks the whole problem into three parts: how to stop ransomware from getting in, how to slow it down if it does, and what to actually do once you've been hit. Curtis and Prasanna go section by section — covering phishing and dropper prevention, application whitelisting, blocking lateral movement between servers, locking down RDP and SSH, honeypot files for catching intruders in the act, and building a real incident response plan before you ever need one. They also get into the messier parts most people don't talk about — what it's actually like to negotiate for a decryption key, why getting your data back isn't the end of the story, and why a ransomware attack is nothing like a normal disaster recovery scenario. Along the way, Curtis makes the case that most organizations already have the gaps this attacker needs — and that fixing them now is a lot cheaper than fixing them after the fact. Whether you're building your first incident response plan or just want to stress-test the one you've already got, this episode gives you a practical, section-by-section framework to work from. Chapter Markers: 00:00 – Encore intro & episode setup 00:01:37 – Show intro and banter 00:06:21 – Preventing the breach: phishing, droppers, and whitelisting 00:14:46 – Blocking lateral movement, RDP/SSH lockdown 00:20:28 – Detecting exfiltration and honeypot files 00:24:19 – What to do once you've been hit 00:25:58 – Building your incident response plan 00:30:43 – Decryption, ransom payments, and why it's not over yet

0:00-36:21

transcript

No transcript — this publisher did not publish one.

show notes

This episode is built around a ransomware response checklist — a three-part Reddit series by a security specialist who goes by snorkel42, breaking down exactly how to prevent, contain, and recover from a ransomware attack.

This is an encore episode, and it's back not just because a lot of people downloaded it originally, but because so many of you listened all the way through — some of you more than once. That kind of engagement told us this one was worth bringing back.

Curtis Preston and Prasanna Malaiyandi dig into snorkel42's series, which breaks the whole problem into three parts: how to stop ransomware from getting in, how to slow it down if it does, and what to actually do once you've been hit. Curtis and Prasanna go section by section — covering phishing and dropper prevention, application whitelisting, blocking lateral movement between servers, locking down RDP and SSH, honeypot files for catching intruders in the act, and building a real incident response plan before you ever need one.

They also get into the messier parts most people don't talk about — what it's actually like to negotiate for a decryption key, why getting your data back isn't the end of the story, and why a ransomware attack is nothing like a normal disaster recovery scenario. Along the way, Curtis makes the case that most organizations already have the gaps this attacker needs — and that fixing them now is a lot cheaper than fixing them after the fact.

Whether you're building your first incident response plan or just want to stress-test the one you've already got, this episode gives you a practical, section-by-section framework to work from.

Chapter Markers:

00:00 – Encore intro & episode setup

00:01:37 – Show intro and banter

00:06:21 – Preventing the breach: phishing, droppers, and whitelisting

00:14:46 – Blocking lateral movement, RDP/SSH lockdown

00:20:28 – Detecting exfiltration and honeypot files

00:24:19 – What to do once you've been hit

00:25:58 – Building your incident response plan

00:30:43 – Decryption, ransom payments, and why it's not over yet