ransomware attempt was detected via EDR. I isolated the affected system, coordinated with SOC to block malicious IPs, engaged IT to restore from backup, and prepared a root cause analysis for management. Communication with stakeholders was structured at every stage.