Response Phase (T+2 to T+8 hours)
Response Phase (T+2 to T+8 hours)
- T+2 hours: Helpdesk ticket created
- T+2.5 hours: Identified as ransomware
- T+3 hours: Incident response team activated
- T+4 hours: Containment actions begun
- T+8 hours: All systems isolated
Analysis: 2-hour delay from detection to team activation