guideAug 2026
Ransomware: first 72 hours checklist
Printable procedure: contain, preserve, communicate, recover.
Threat Research · Security Guides
Step-by-step checklists, owners, and verification — not another essay. Download the ransomware 72-hour path and the identity baseline, or read the field notes on the blog.

What you'll find
Security Guides are how-to artifacts: baseline hardening, phishing response drills, access reviews, and recovery checklists. Commentary and strategic framing live under Insights. Keeping those channels separate means an engineer can open a guide and execute without hunting for the actionable part.
Published guides sit below as printable procedures. Blog field notes in the Guide category unpack the same topics when you need the argument, not just the checklist. Commentary lives under Insights.
guideAug 2026
Printable procedure: contain, preserve, communicate, recover.
guideJul 2026
A procedure for IT leads: privileged accounts, MFA, and mailbox controls.
9 Jul 2026
You do not need a greenfield network. You need verified access to the paths that actually matter.
18 Jun 2026
Contain, preserve, communicate, recover. In that order. Print the checklist before you need it.
Capabilities
Lanes for practical content as publications land.
Identity, endpoint, email, and network controls ordered by risk reduction.
Playbooks, contact trees, evidence handling, and tabletop agendas.
Awareness cadences, access reviews, and change control that staff can sustain.
Self-checks before audits, vendor reviews, or board reporting cycles.
Process
Every guide should be usable under pressure — clear steps, clear done criteria.
What outcome the guide produces and who owns it.
Access, tools, and approvals needed before step one.
Numbered actions with expected results — no buried critical detail.
How to confirm the control or process actually works.
When to stop DIY and bring in assessment or response support.
At a glance
Primary readers
What “done” looks like
Capabilities
Pick the channel that matches the job.
Follow steps, verify, close the ticket or control gap.
Understand trade-offs and programme direction before you spend.
Decide with Insights, implement with Guides, validate with assessment.
Threat landscape
Cloud estates, identities, vendors, and employee devices shift every week. A once-a-year assessment is a snapshot. CyberSafe treats the attack surface as a live model — continuously scanned, ranked by business consequence, and tied to the work of closing what actually matters.
Tell us your environment and the control you need to stand up. We can point you to published guides as they ship — or scope a hands-on engagement to build procedures with your team.
Talk about security procedures