Establishing secure connection…Loading editor…Preparing document…

Ransomware Response Supplement

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

Ransomware Response Supplement

This Ransomware Response Supplement (the Supplement) is entered into between the parties identified below on the Effective Date provided herein and amends or supplements the existing agreement between the parties for cybersecurity incident response services.

Parties and Effective Date

Effective Date:

Recitals

WHEREAS, Client requires immediate and coordinated professional services to respond to a ransomware-related cybersecurity incident, including containment, forensic investigation, remediation, and restoration; and

WHEREAS, Service Provider represents that it has the expertise, personnel, tools and authority necessary to provide emergency incident response and related services as set forth in this Supplement; and

WHEREAS, the parties desire to set forth the scope of work, payment terms, confidentiality protections, and other material terms specific to ransomware response in addition to the existing agreement between the parties.

Scope of Work

The Service Provider shall provide response services as reasonably necessary to address the ransomware incident, which may include emergency containment, eradication of malicious artifacts, forensic investigation, restoration of systems, data recovery efforts, coordination with third-party vendors, and support for client communications with affected stakeholders and regulators.

Response Components (check all that apply):

Containment and isolation of affected systems    Forensic investigation and evidence preservation    Data recovery and system restoration    Communications and stakeholder support    Third-party vendor coordination

Incident Date (if known):

Ransom Payment Authorization

The parties acknowledge that payment of a ransom is a separate, high-risk decision. Provider shall not use client funds to pay any ransom unless expressly authorized in writing by Client pursuant to the procedures below.

Authorization to negotiate or effectuate payment of a ransom: Client authorizes Provider to negotiate ransom    Client authorizes Provider to effectuate ransom payment

If authorization is granted above, Maximum Authorized Payment Amount: $

Approval requirement: Provider must obtain prior written or documented telephonic approval from an authorized Client representative before attempting any payment or final negotiation.

Payment Terms

Retainer (if applicable): $ payable within days of activation of services.

Hourly Rates: Lead technical personnel $ /hr; Other technical staff $ /hr.

Flat incident fee (if applicable): $

Invoice Due: days from invoice date. Late fee: per month on overdue balances.

Third-party costs and disbursements (including but not limited to forensic lab fees, travel, and extraordinary vendor fees) shall be reimbursed by Client upon presentation of reasonable documentation.

Term and Termination

Term Start Date:    Term End Date (if applicable):

Either party may terminate this Supplement for convenience upon days' written notice. Either party may terminate for material breach if the breach is not cured within days following written notice of breach.

Confidentiality and Data Handling

The parties agree that all non-public information disclosed in connection with the response services, including incident artifacts, forensic data, system logs, and personal data, shall be treated as Confidential Information. Service Provider shall use such Confidential Information solely to perform the services under this Supplement and shall not disclose such information except to personnel or approved subcontractors who have a need to know and are bound by confidentiality obligations at least as protective as those herein.

Exceptions: Confidentiality obligations shall not apply to information that is already public through no fault of the receiving party, independently developed by the receiving party without access to the disclosing party's Confidential Information, or required to be disclosed by law or valid subpoena, provided the receiving party provides prompt notice to permit the disclosing party to seek protective relief.

Liability, Indemnification and Disclaimers

Limitation of Liability: Except for willful misconduct or gross negligence, in no event shall either party be liable to the other for consequential, incidental, special or punitive damages, and aggregate liability for claims arising out of this Supplement shall be limited to the total fees paid to Service Provider under this Supplement in the twelve (12) months preceding the claim.

Indemnification: Each party shall indemnify and hold the other harmless from claims arising from its own acts or omissions in connection with this Supplement, subject to the limitations of liability set forth herein.

No Guarantee of Recovery: Client acknowledges that Service Provider does not guarantee recovery of encrypted data or that ransom payment (if any) will result in successful or complete restoration of systems or data.

Governing Law; Entire Agreement

Governing Law: This Supplement shall be governed by and construed in accordance with the laws of the state of without regard to its choice of law rules.

Entire Agreement: This Supplement, together with the underlying agreement between the parties, constitutes the entire agreement with respect to the subject matter hereof and supersedes all prior and contemporaneous agreements and understandings relating to ransomware response services. In the event of any conflict between this Supplement and the underlying agreement, the terms of this Supplement shall control to the extent they specifically address ransomware response.

Notices

All notices required or permitted under this Supplement shall be in writing and delivered to the notice addresses provided above or to such other address as a party may designate in writing from time to time.

Acceptance

By signing below, the authorized representatives of the parties acknowledge and agree to the terms of this Ransomware Response Supplement.

Client Name (Printed):

By:

Date:

Service Provider (Printed):

By:

Date:

Enter text✕

What the Ransomware Response Supplement Is

A Ransomware Response Supplement is a structured addendum to an incident response plan or incident report that documents actions, decisions, and evidence specific to a ransomware event. It standardizes who was notified, what containment and forensic steps occurred, timelines for each action, payments or ransom decisions, communications with insurers and law enforcement, and chain-of-custody details for preserved media. The supplement supports regulatory reporting, insurer claims, legal review, and post-incident remediation planning while preserving an auditable record for internal and external stakeholders.

Why a Supplement Improves Incident Clarity and Compliance

Using a Ransomware Response Supplement centralizes critical facts, preserves forensic evidence, and documents decision points that insurers and regulators may require. It helps demonstrate timely notification, controlled access to affected systems, and an auditable timeline that supports legal and compliance reviews.

Why a Supplement Improves Incident Clarity and Compliance

Who Typically Completes the Supplement

A small cross-functional team usually completes the supplement to ensure accuracy and completeness.

  • IT Incident Response Lead: Coordinates containment and documents technical actions taken, affected hosts, and timestamps.
  • Legal and Compliance Officer: Reviews regulatory reporting obligations and preserves privileged communications as required.
  • Risk/Insurance Manager: Records policy details, claim numbers, and insurer contacts needed for prompt claims handling.

Centralizing responsibility reduces gaps between technical facts and policy obligations when reporting to insurers or regulators.

Core Sections to Include in a Professional Supplement

A well-structured supplement organizes facts so technical, legal, and business reviewers can quickly verify actions and obligations. Consistent sectioning reduces rework during insurer or regulator review.

Incident Summary

Concise incident description, detection time, affected systems, and scope of impact for quick reference by reviewers.

Containment & Mitigation

Actions taken to isolate systems, block malicious C2, and temporary workarounds used to stop further spread.

Forensic Evidence

Lists preserved images, logs, samples, hash values, storage locations, and chain-of-custody steps for legal admissibility.

Communications Log

Chronological record of internal and external notifications, including timestamps, recipients, and message content summaries.

Ransom Decision Ledger

Documented analysis of ransom options, approvals, payment method, and counsel/insurer input tied to authorization records.

Remediation & Lessons

Planned and completed remediation tasks, patching, credential resets, user notifications, and follow-up actions with owners.

Required Data Fields for the Supplement

Incident ID: Unique identifier
Discovery Timestamp: MM/DD/YYYY HH:MM
Affected Systems: Hostnames and asset tags
Primary Contacts: Names and phone/email
Insurer Policy: Carrier and policy number
Evidence Location: Secure storage URI or vault

Sequential Steps to Complete the Supplement

Complete the supplement progressively during the incident to keep the record contemporaneous and defensible.

  • 01
    Identify: Confirm scope and assign an Incident ID immediately.
  • 02
    Contain: Record isolation actions and network segmentation taken to limit spread.
  • 03
    Preserve Evidence: Capture disk images and logs with hash verification for chain-of-custody.
  • 04
    Notify: Log insurer, counsel, law enforcement, and regulatory notifications with timestamps.

How to Configure an Online Supplement Template

Set up a repeatable, secure workflow so responders can complete the supplement quickly and with validated fields.

Field Configuration
Authentication Require SSO + MFA for editors
File Formats Accept PDF/A and CSV export
Conditional Fields Show ransom-related fields only if 'Ransom Requested' checked
Routing Auto-route to legal, insurer, and IR lead

Where to Send Completed Supplements and Who Receives Them

A clear routing path ensures timely insurer and regulatory responses while protecting privileged content.

  • Internal IR Team: Primary repository for the official incident record
  • Cyber Insurer: Send per policy notice requirements with claim reference
  • Legal Counsel: Provide privileged copies and seek litigation hold advice
  • Law Enforcement: Share relevant evidence as requested by investigators

Secure Distribution Options and Technical Requirements

Choose platforms that preserve audit trails, encrypt data, and support controlled access for reviewers.

  • Formats Supported: PDF, PDF/A, DOCX, CSV
  • Integrations: Salesforce, Microsoft 365, NetSuite, Google Workspace
  • Security: TLS 1.2/1.3 in transit; AES-256 at rest

Common Timelines and Notification Expectations

Timeframes vary by insurer, regulation, and the scale of impact; document each deadline and confirm next steps with counsel and claims contacts.

Insurer Notification Window:

Often within 24–72 hours per policy; confirm policy language

Law Enforcement Contact:

Notify investigators as soon as evidence is preserved

Regulatory Notifications:

State breach laws and sector rules set differing deadlines

Internal Reporting:

Complete supplement before closure of containment phase

Evidence Preservation:

Retain original images until legal counsel directs otherwise

Frequent Preparation Mistakes to Avoid

  • Delaying evidence capture until systems are rebuilt, which degrades forensic value and hash verification
  • Failing to record exact timestamps and actor names, causing gaps in the incident timeline
  • Not centralizing approvals for ransom decisions, producing unclear authorization trails
  • Sharing privileged notes widely without segregation, risking waiver of legal privilege

Risks of Incomplete or Incorrect Supplements

Regulatory Fines: Civil penalties under HIPAA or state laws
Claim Denial: Insurer may deny coverage for late or incomplete notice
Evidence Loss: Missing chain-of-custody limits legal options
Litigation Exposure: Incomplete records increase liability risk
Reputational Harm: Poorly documented response impairs stakeholder trust
Operational Disruption: Unclear remediation prolongs downtime

Real-World Examples of Supplement Use

These condensed examples show how organizations used structured supplements to support response, claims, and recovery.

Optica Ventures — COO

Optica documented timelines and preserved disk images during containment

  • Forensic images were hashed and stored in a secure vault
  • The organized supplement enabled faster insurer intake and reduced follow-up requests, shortening claim processing by several weeks.

Martin Properties — Founder

Property manager recorded tenant-notification steps and remediation schedules

  • Used e-signed release forms for affected tenants
  • Clear documentation supported a coordinated recovery and satisfied regulator inquiries with minimal delay.

Practical Tips for Accurate, Efficient Supplement Completion

Adopt these practices to keep the supplement usable, legally sound, and aligned with insurer and regulatory expectations.

Use a Single Source of Truth
Designate one secure repository for the active supplement and require incident handlers to update only that copy; version control avoids divergent records and supports auditability.
Capture Actions Contemporaneously
Enter actions and decisions as they occur with exact timestamps and actor names to preserve timelines and reduce reliance on memory-heavy reconstructions.
Preserve Forensic Integrity
Always capture hash-verified images and record chain-of-custody; store evidence in tamper-evident storage to maintain admissibility.
Coordinate with Insurer and Counsel Early
Engage claims and legal teams quickly to clarify notification windows, privilege protection steps, and whether external counsel should lead communications.

eSignature Pricing and Feature Snapshot for Supplement Workflows

Compare common vendor pricing and capabilities relevant to high-volume supplements and secure evidence-sharing. signNow appears first per platform comparison guidance.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial No No Yes, limited Yes, limited
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No

FAQs: Completing and Sharing a Ransomware Response Supplement

Answers to common questions about evidence preservation, legal validity, notifications, and electronic signing when using a supplement.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users