AI Ransomware Incident Scope Assessment Playbook
A 900-bed hospital system has confirmed a ransomware incident. Three file servers and one domain controller are encrypted. The incident was detected at 2:47 AM; IT believes initial access occurred 11 days earlier based on log artifacts. EHR system is offline. Patient diversion is in effect.
When to use this playbook
- Use this playbook when the decision looks like the situation above: A 900-bed hospital system has confirmed a ransomware incident.
- It is a fit when you have source files in hand and need a structured, reviewable analysis — not a generic chat answer about "Ransomware Incident Scope Assessment".
- Do not use it as a substitute for licensed, legal, clinical, or authorized official judgment in the domain.
What you'll need
- SIEM log export (14 days, all systems)
- EDR telemetry from affected and adjacent hosts
- Network flow data
- Active Directory event log (4624, 4625, 4648, 4768)
- Ransomware note and sample hash
Attachments: Spreadsheets (Spreadsheets)
The Prompt
You are a cybersecurity incident responder managing a ransomware incident at a hospital system. I am attaching: Work only from the attached source files. If a conclusion is not supported, say so. Produce: 1. Reconstruct the attack timeline: initial access vector, persistence mechanism, lateral movement path, and encryption trigger. 2. Identify all systems that communicated with the initial access host in the 11-day dwell period—these are potentially compromised even if not encrypted. 3. Determine whether the threat actor accessed or exfiltrated PHI before deploying ransomware (this determines HIPAA breach notification scope). 4. Identify the ransomware variant from the note and hash and tell me what decryptors, if any, are publicly available. 5. Tell me the containment sequence: which systems to isolate now, which to preserve for forensics, and what to restore first to resume patient care. Call out where independent models are likely to disagree, and list follow-up documents a reviewer should request.
What to expect
- Attack timeline reconstruction
- Blast radius host list
- PHI exfiltration assessment
- Ransomware variant identification and decryptor status
- Containment and recovery sequencing
Review before you act
- Validate this output against source files before relying on it: Reconstruct the attack timeline: initial access vector, persistence mechanism, lateral movement path, and encryption trigger.
- Validate this output against source files before relying on it: Identify all systems that communicated with the initial access host in the 11-day dwell period—these are potentially compromised even if not encrypted.
- Validate this output against source files before relying on it: Determine whether the threat actor accessed or exfiltrated PHI before deploying ransomware (this determines HIPAA breach notification scope).
- Validate this output against source files before relying on it: Identify the ransomware variant from the note and hash and tell me what decryptors, if any, are publicly available.
- Confirm every cited figure, date, counterparty, or requirement against the attached originals — models compress and can drop a qualifier.
- Treat disagreement between models as a review item, especially on classification, materiality, and recommended next action.
- Do not authorize an operational, clinical, legal, credit, or enforcement action solely because the models agree.
Why compare models on this
For Ransomware Incident Scope Assessment, running the same attachments across independent models is useful because the hard part is classification and completeness, not fluency. The workflow is already designed to surface attack timeline reconstruction; blast radius host list; phi exfiltration assessment; ransomware variant identification and decryptor status. Those are comparison artifacts — they only exist if more than one model runs. Models disagree on blast radius, attribution confidence, and whether a vendor finding is theoretical or exploitable. Those disagreements mark where an analyst should slow down.
Related playbooks
See governed multi-model AI on your own prompt
Compare GPT-5, Claude, and Gemini side by side, with human review and a decision record built in.

