Many companies have already implemented ransomware countermeasures. However, what is critical now is not only preventing incidents but also preparing for when they occur. Key considerations include investigation and analysis, forensic response, decisions regarding ransom demands, consulting with experts, reporting obligations, public disclosure, and measures to prevent recurrence. In this session, we will explain these key points and work with participants to explore the most effective responses.