This ransomware playbook provides guidance for responding to a ransomware incident in 3 phases: detection, analysis, and remediation. The detection phase involves identifying and reporting the ransomware attack. The analysis phase focuses on analyzing the scope of the attack and compromised data. The remediation phase outlines activities to contain the ransomware, remove it from infected systems, and recover affected services. Key stakeholders for each activity include IT, information security, and incident response teams.