Home · Business · IT, Data & Security · Cybersecurity
As of 13 August 2026, AI can only partly respond to a ransomware attack.
This still needs a person who signs their name to it.
Can you do it?
5 minutesto a draft.
1 hourto something you’d act on.
Cost, all in£0
Skill neededpower-user
Who has to check ita professional
What the alternative costsThe supplied alternatives do not list a price for an incident-response service.
If this goes wrong: you destroy evidence, spread the compromise or restore an infected backup, increasing downtime and the cost of recovery.
What to actually do
Hand it to a person
The route this page recommends
Someone with a licence or accountable authority has to sign this before it counts.
Use a tool built for this
Second choiceDo it yourself
The distant thirdA chat interface, power-user skill, and roughly 1 hour until you can act on the result.
How to actually do it
- Open your incident log and record when the attack was noticed, what is confirmed, which systems are affected, what has already been disconnected and who is making decisions.
- Use a separate trusted device or phone to contact your cyber insurer, managed security provider or incident-response firm, and your IT lead; do not rely on the suspected environment for those contacts.
- Preserve the ransom note, alerts, relevant emails and system details in their original form, and do not paste credentials, private keys, personal data or unredacted logs into a chatbot.
- Paste the redacted facts and the prompt into a chatbot to produce a fact summary, action checklist, evidence list, handover brief and draft messages.
- Have the incident-response lead compare each proposed action with your business continuity plan, insurer instructions and current UK official guidance before anyone changes networks, accounts, backups or devices.
- Send only the approved staff, customer or supplier messages, keep the incident log updated, and let the qualified responder and data-protection solicitor decide on containment, restoration, ransom contact and any notifications.
Prompt
Act as a planning and documentation assistant during a suspected ransomware incident in a UK business. Do not claim that you have investigated the systems, do not diagnose the intrusion, and do not give destructive commands or instructions to pay a ransom. Do not invent facts, deadlines, legal duties or technical findings. Treat every proposed technical action as requiring approval from our incident-response lead or qualified security professional. Using only the information below, produce: 1. A fact-only incident summary, separating confirmed facts, unverified reports and unknowns. 2. A prioritised checklist for the next actions, with the owner, dependency and risk of each action. 3. A list of evidence to preserve, without altering affected systems. 4. Questions to ask our cyber insurer, incident-response provider, IT administrator and data-protection solicitor. 5. A short internal message telling staff what to do and what not to do. 6. A short holding message for customers or suppliers only if one is appropriate, clearly marked for professional approval. 7. A list of decisions that must not be made by the chatbot, including containment, restoration, ransom payment, notification and public statements. 8. A handover brief that a qualified incident responder can use. Use plain British English. Do not include credentials, passwords, private keys, personal data or unredacted logs in your answer. Where UK reporting or data-protection obligations may apply, say that the responsible professional must check current GOV.UK and ICO guidance rather than stating an unverified rule. Business: [business name and sector] Incident started or was noticed: [time and date] Confirmed symptoms: [symptoms] Affected devices, accounts or services: [list] Systems still available: [list] Backups and recovery information: [known facts only] Ransom note or attacker contact: [redacted text or description] Actions already taken: [list] People and suppliers available: [roles and contact routes] Existing incident-response plan: [paste relevant redacted section] Known personal or commercially sensitive data involved: [known facts only]
Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.
What it gets wrong
- It cannot see which systems are compromised or confirm that an attacker has been removed.
- It cannot preserve forensic evidence or safely execute containment and recovery actions in your environment.
- It cannot decide whether a suspected personal-data breach requires notification or represent your business to regulators.
- It cannot assess whether backups are clean, complete and safe to restore.
- It cannot carry liability for downtime, disclosure, ransom decisions or inaccurate public statements.
What caps this at PARTLY: stakes of error, verification cost and legal accountability.
How we scored this
Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.
| Axis | Score (0–2) |
|---|---|
| Output | 1 |
| Inputs | 1 |
| Verification | 1 |
| Liability | 0 |
| Effort delta | 1 |
| Total | 4 / 10 |
The methodology and its thresholds are published in full.
FAQ
- Can AI stop a ransomware attack?
- No. AI can organise facts and draft a response checklist, but it cannot reliably identify every compromised system or safely contain the attack without access, authority and an experienced responder.
- Can I use ChatGPT to respond to ransomware?
- Partly. Use it for a redacted incident summary, evidence checklist, handover brief and draft communications, not for credentials, live commands or unsupervised containment and recovery decisions.
- What should I do first in a ransomware attack?
- Use a trusted communication route to alert your IT lead, cyber insurer and incident-response provider, then record confirmed facts and preserve evidence without changing affected systems unnecessarily. Follow the approved incident plan rather than instructions generated by a chatbot.
- Can AI tell me whether I need to report ransomware to the ICO?
- It can list the facts a data-protection professional will need, but it cannot make the decision safely for your business. This is not professional advice; a serious case needs a qualified incident-response specialist and a data-protection solicitor or other competent privacy professional to check the current position.
Nearby answers
- Can AI help me choose and secure a VPN for my business?PARTLY
- Can AI help me secure Microsoft 365 for my business?PARTLY
- Can AI check whether an email is a phishing attempt?PARTLY
- Can AI compare business antivirus software in the UK?PARTLY
- Can AI detect phishing emails for my business?PARTLY
- Can AI help my business prepare for Cyber Essentials?YES
Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.
The newsletter
AI news, new answers and product picks, straight to your inbox.