As soon as the malware was identified, the incident response begins. The steps for incident response are: 1. Preparation - Preparing for an attack and how to respond 2. Identification - Identifying the threat 3. Containment - Containing the threat 4. Eradication - Removing the threat 5. Recovery - Recovering affected systems 6. Lessons Learned - Evaluating the incident response, see where there can be improvements for a future incident. In the scenario, the malware has already been identified, which means that we are past the Identification step. The next step would be to begin containment as to limit the amount of damage the malware can cause, so, quarantining infected hosts would be the best option here.