Skip to content

Building A Ransomware Decision Tree Before The Call Comes In

cybernoz.com • September 11, 2026

In this Help Net Security video, Kerri Shafer-Page, VP of Incident Response at Arctic Wolf, walks through the ransomware decision tree in this video. She covers four areas where decisions need settling in advance, starting with containment.

Someone has to know the network well enough to judge what pulling a system offline does to client data, a manufacturing line, or a website. Then comes the extortion demand. Who is authorized to negotiate, and what is the ceiling?

Shafer-Page treats paying as a business decision, noting that a demand can cost less than an insurance retention and higher renewal rates. She argues law enforcement belongs in the playbook, since agencies may know the threat actor and can help you avoid sanctions problems.

Communication matters too, from cyber legal counsel on disclosure deadlines to a spokesperson and a prepared help desk. Her advice: make these decisions on a Tuesday afternoon, not at 2 a.m. on a holiday weekend.

Download: 2026 Credential Risk Report

Wireless Broadband Alliance CEO on key drivers for Wi-Fi adoption in enterprise networks

The demand for robust, reliable, and high-speed connectivity is increasing rapidly in the era of relentless digital transformation. This Help Net Security interview with Tiago…

Week in review: Fortinet patches critical FortiManager 0-day, VMware fixes vCenter Server RCE

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Fortinet releases patches for publicly undisclosed critical FortiManager vulnerabilityIn the…

Ivanti Connect Secure zero-days exploited by attackers (CVE-2023-46805, CVE-2024-21887)

Table of Contents the vulnerabilities (CVE-2023-46805 and CVE-2024-21887) the attacks Mitigation and remediation Two zero-day vulnerabilities (CVE-2023-46805, CVE-2024-21887) in Ivanti Connect Secure VPN…

AI cybersecurity needs to be as multi-layered as the system it’s protecting

Table of Contents Design Development Deployment Operation Cybercriminals are beginning to take advantage of the new malicious options that large language models (LLMs) offer them.…

Valeo and C2A Security partner to improve security for customers and modern vehicles

Valeo and C2A Security have unveiled a strategic collaboration to enhance Valeo’s cybersecurity offerings on their products in development and continuous operations. The new partnership…

Why 90% of cyber leaders are feeling the heat

Table of Contents Consequences of cyber risk immaturity Monitoring is a top priority, but still out of reach TPRM monitoring remains inconsistent Communicating risk 90%…