Home · Business · IT, Data & Security · Cybersecurity

PARTLY

As of 13 August 2026, AI can only partly respond to a ransomware attack.

This still needs a person who signs their name to it.

Can you do it?

5 minutesto a draft.

1 hourto something you’d act on.

Cost, all in£0

Skill neededpower-user

Who has to check ita professional

What the alternative costsThe supplied alternatives do not list a price for an incident-response service.

If this goes wrong: you destroy evidence, spread the compromise or restore an infected backup, increasing downtime and the cost of recovery.

What to actually do

  1. Hand it to a person

    The route this page recommends

    Someone with a licence or accountable authority has to sign this before it counts.

  2. Use a tool built for this

    Second choice
  3. Do it yourself

    The distant third

    A chat interface, power-user skill, and roughly 1 hour until you can act on the result.

    How to actually do it

    1. Open your incident log and record when the attack was noticed, what is confirmed, which systems are affected, what has already been disconnected and who is making decisions.
    2. Use a separate trusted device or phone to contact your cyber insurer, managed security provider or incident-response firm, and your IT lead; do not rely on the suspected environment for those contacts.
    3. Preserve the ransom note, alerts, relevant emails and system details in their original form, and do not paste credentials, private keys, personal data or unredacted logs into a chatbot.
    4. Paste the redacted facts and the prompt into a chatbot to produce a fact summary, action checklist, evidence list, handover brief and draft messages.
    5. Have the incident-response lead compare each proposed action with your business continuity plan, insurer instructions and current UK official guidance before anyone changes networks, accounts, backups or devices.
    6. Send only the approved staff, customer or supplier messages, keep the incident log updated, and let the qualified responder and data-protection solicitor decide on containment, restoration, ransom contact and any notifications.

    Prompt

    Act as a planning and documentation assistant during a suspected ransomware incident in a UK business. Do not claim that you have investigated the systems, do not diagnose the intrusion, and do not give destructive commands or instructions to pay a ransom. Do not invent facts, deadlines, legal duties or technical findings. Treat every proposed technical action as requiring approval from our incident-response lead or qualified security professional.
    
    Using only the information below, produce:
    1. A fact-only incident summary, separating confirmed facts, unverified reports and unknowns.
    2. A prioritised checklist for the next actions, with the owner, dependency and risk of each action.
    3. A list of evidence to preserve, without altering affected systems.
    4. Questions to ask our cyber insurer, incident-response provider, IT administrator and data-protection solicitor.
    5. A short internal message telling staff what to do and what not to do.
    6. A short holding message for customers or suppliers only if one is appropriate, clearly marked for professional approval.
    7. A list of decisions that must not be made by the chatbot, including containment, restoration, ransom payment, notification and public statements.
    8. A handover brief that a qualified incident responder can use.
    
    Use plain British English. Do not include credentials, passwords, private keys, personal data or unredacted logs in your answer. Where UK reporting or data-protection obligations may apply, say that the responsible professional must check current GOV.UK and ICO guidance rather than stating an unverified rule.
    
    Business: [business name and sector]
    Incident started or was noticed: [time and date]
    Confirmed symptoms: [symptoms]
    Affected devices, accounts or services: [list]
    Systems still available: [list]
    Backups and recovery information: [known facts only]
    Ransom note or attacker contact: [redacted text or description]
    Actions already taken: [list]
    People and suppliers available: [roles and contact routes]
    Existing incident-response plan: [paste relevant redacted section]
    Known personal or commercially sensitive data involved: [known facts only]

    Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.

What it gets wrong

  • It cannot see which systems are compromised or confirm that an attacker has been removed.
  • It cannot preserve forensic evidence or safely execute containment and recovery actions in your environment.
  • It cannot decide whether a suspected personal-data breach requires notification or represent your business to regulators.
  • It cannot assess whether backups are clean, complete and safe to restore.
  • It cannot carry liability for downtime, disclosure, ransom decisions or inaccurate public statements.

What caps this at PARTLY: stakes of error, verification cost and legal accountability.

How we scored this

Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.

AxisScore (0–2)
Output1
Inputs1
Verification1
Liability0
Effort delta1
Total4 / 10

FAQ

Can AI stop a ransomware attack?
No. AI can organise facts and draft a response checklist, but it cannot reliably identify every compromised system or safely contain the attack without access, authority and an experienced responder.
Can I use ChatGPT to respond to ransomware?
Partly. Use it for a redacted incident summary, evidence checklist, handover brief and draft communications, not for credentials, live commands or unsupervised containment and recovery decisions.
What should I do first in a ransomware attack?
Use a trusted communication route to alert your IT lead, cyber insurer and incident-response provider, then record confirmed facts and preserve evidence without changing affected systems unnecessarily. Follow the approved incident plan rather than instructions generated by a chatbot.
Can AI tell me whether I need to report ransomware to the ICO?
It can list the facts a data-protection professional will need, but it cannot make the decision safely for your business. This is not professional advice; a serious case needs a qualified incident-response specialist and a data-protection solicitor or other competent privacy professional to check the current position.

Nearby answers

Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.

The newsletter

AI news, new answers and product picks, straight to your inbox.