Ransomware response checklist: how to stop it from getting in, slow it down if it does, and recover if you get hit — straight from a security pro's own Reddit series.

This encore episode is back because so many of you didn't just download it — you listened all the way through, some of you more than once. That's the kind of engagement that tells us it was worth bringing back.

In this episode, Curtis Preston and Prasanna Malaiyandi walk through a three-part Reddit series from a security specialist who goes by snorkel42, breaking ransomware defense into three phases: prevention, containment, and recovery. It's a genuinely useful ransomware response checklist, built from someone who's clearly seen this play out for real.

You'll hear Curtis and Prasanna cover phishing and dropper prevention, why application whitelisting is one of the highest-friction but highest-payoff defenses out there, and how blocking lateral movement between servers (and locking down RDP and SSH) can stop an attacker cold even after they're already in.

They also dig into detection — honeypot files designed to catch intruders in the act, behavioral analytics for spotting data exfiltration before it's too late, and why "it's time to kill monolithic file servers" is more nuanced advice than it sounds.

And then there's the part nobody wants to think about: what happens after you've been hit. Curtis and Prasanna talk through incident response planning, why a ransomware attack is nothing like a normal disaster recovery scenario, the messy reality of decryption keys and ransom payments, and why getting your data back is never actually the end of the story.

If you want a real, practical ransomware response checklist — not just theory, but the actual steps — this episode is for you.

Chapter Markers:
00:00 – Encore intro & episode setup
00:01:37 – Show intro and banter
00:06:21 – Preventing the breach: phishing, droppers, and whitelisting
00:14:46 – Blocking lateral movement, RDP/SSH lockdown
00:20:28 – Detecting exfiltration and honeypot files
00:24:19 – What to do once you've been hit
00:25:58 – Building your incident response plan
00:30:43 – Decryption, ransom payments, and why it's not over yet
Listen to the full episode and check out more from the show: https://www.backupwrapup.com/ransomware-response-checklist
Did you use any of the banned words? Checked — clean, nothing from the list appears.