{
  "node_id": "cisa-ms-isac-ransomware-guide",
  "title": "RANSOMWARE GUIDE",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2020-09-01",
  "bluf": "This guide provides ransomware best practices and recommendations based on operational insight from the Cybersecurity and Infrastructure Security Agency (CISA) and the Multi-State Information Sharing and Analysis Center (MS-ISAC). It is intended for information technology (IT) professionals and others involved in developing or coordinating cyber incident response. Ransomware is a form of malware designed to encrypt files on a device, rendering them and the systems that rely on them unusable, after which malicious actors demand a ransom for decryption. Ransomware incidents have become increasingly prevalent and can severely impact business processes, leaving organizations without the data needed to operate and deliver mission-critical services.\nMalicious actors have adjusted tactics to include threatening to release stolen data and publicly naming victims as secondary forms of extortion. The monetary value of demands has also increased, with some exceeding $1 million. These actors often engage in lateral movement to target critical data, propagate ransomware across entire networks, and use tactics like deleting system backups to make restoration more difficult. This guide is composed of two parts: Ransomware Prevention Best Practices and a Ransomware Response Checklist.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "ai_overlay_2026",
      "industry_mapping"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-sp-800-61r2-incident-handling",
    "nist-sp-800-34-r1",
    "nist-ir-8374-ransomware-risk-management",
    "data-integrity-detecting-responding-ransomware",
    "cis-controls-v8",
    "cisa-cross-sector-cybersecurity-goals"
  ],
  "primary_citations_count": 9
}