AnalysisCritical riskComparison recommended

AI Ransomware Incident Scope Assessment Playbook

A 900-bed hospital system has confirmed a ransomware incident. Three file servers and one domain controller are encrypted. The incident was detected at 2:47 AM; IT believes initial access occurred 11 days earlier based on log artifacts. EHR system is offline. Patient diversion is in effect.

When to use this playbook

  • Use this playbook when the decision looks like the situation above: A 900-bed hospital system has confirmed a ransomware incident.
  • It is a fit when you have source files in hand and need a structured, reviewable analysis — not a generic chat answer about "Ransomware Incident Scope Assessment".
  • Do not use it as a substitute for licensed, legal, clinical, or authorized official judgment in the domain.

What you'll need

  • SIEM log export (14 days, all systems)
  • EDR telemetry from affected and adjacent hosts
  • Network flow data
  • Active Directory event log (4624, 4625, 4648, 4768)
  • Ransomware note and sample hash

Attachments: Spreadsheets (Spreadsheets)

The Prompt

You are a cybersecurity incident responder managing a ransomware incident at a hospital system. I am attaching:

Work only from the attached source files. If a conclusion is not supported, say so.

Produce:
1. Reconstruct the attack timeline: initial access vector, persistence mechanism, lateral movement path, and encryption trigger.
2. Identify all systems that communicated with the initial access host in the 11-day dwell period—these are potentially compromised even if not encrypted.
3. Determine whether the threat actor accessed or exfiltrated PHI before deploying ransomware (this determines HIPAA breach notification scope).
4. Identify the ransomware variant from the note and hash and tell me what decryptors, if any, are publicly available.
5. Tell me the containment sequence: which systems to isolate now, which to preserve for forensics, and what to restore first to resume patient care.

Call out where independent models are likely to disagree, and list follow-up documents a reviewer should request.

What to expect

  • Attack timeline reconstruction
  • Blast radius host list
  • PHI exfiltration assessment
  • Ransomware variant identification and decryptor status
  • Containment and recovery sequencing

Review before you act

  • Validate this output against source files before relying on it: Reconstruct the attack timeline: initial access vector, persistence mechanism, lateral movement path, and encryption trigger.
  • Validate this output against source files before relying on it: Identify all systems that communicated with the initial access host in the 11-day dwell period—these are potentially compromised even if not encrypted.
  • Validate this output against source files before relying on it: Determine whether the threat actor accessed or exfiltrated PHI before deploying ransomware (this determines HIPAA breach notification scope).
  • Validate this output against source files before relying on it: Identify the ransomware variant from the note and hash and tell me what decryptors, if any, are publicly available.
  • Confirm every cited figure, date, counterparty, or requirement against the attached originals — models compress and can drop a qualifier.
  • Treat disagreement between models as a review item, especially on classification, materiality, and recommended next action.
  • Do not authorize an operational, clinical, legal, credit, or enforcement action solely because the models agree.

Why compare models on this

For Ransomware Incident Scope Assessment, running the same attachments across independent models is useful because the hard part is classification and completeness, not fluency. The workflow is already designed to surface attack timeline reconstruction; blast radius host list; phi exfiltration assessment; ransomware variant identification and decryptor status. Those are comparison artifacts — they only exist if more than one model runs. Models disagree on blast radius, attribution confidence, and whether a vendor finding is theoretical or exploitable. Those disagreements mark where an analyst should slow down.

CybersecurityIncident ResponseAnalysisCriticalSpreadsheets

See governed multi-model AI on your own prompt

Compare GPT-5, Claude, and Gemini side by side, with human review and a decision record built in.