Key takeaways
- Isolate infected devices but don't switch them off
- Protect backups immediately; attackers target them next
- Restoring from backup is usually better than paying
- MFA, patching and immutable backups prevent most attacks
Ransomware encrypts files and demands payment to unlock them. It usually arrives through a phishing email, a compromised password or an unpatched system. If it happens, the first hour decides how much damage is done.
1. Isolate affected devices
Disconnect infected computers from the network, both cable and Wi-Fi, but don't switch them off: memory may contain evidence. Disable VPN and remote access until you know how the attacker got in.
2. Call your IT and security team
Contact your IT provider immediately. The sooner specialists are involved, the more likely they can stop the spread, identify the ransomware and preserve evidence.
3. Protect your backups
Check that backups are intact and disconnected from the affected network. If attackers still have access, they may try to delete backups next.
4. Assess the scope
Identify which systems and data are affected, when the attack started and which accounts were used. This determines whether you restore from backup, rebuild systems or both.
5. Communicate carefully
Tell staff what to do and not to do. Depending on the data involved, you may need to inform clients, insurers or regulators. Avoid sharing details on email if accounts may be compromised.
Should you pay?
Paying doesn't guarantee your data back, funds criminal groups and can mark you as a repeat target. With good backups, restoring is almost always the better path.
Write your plan before you need it
An incident response plan should fit on a few pages and answer: who decides, who to call, how to contact staff if email is down, where backups are and how to restore them, and when to involve insurers or authorities. Print a copy, because it may not be accessible during an attack. Review it yearly and after any major change.
Recovering safely
Restoring too quickly can bring the attacker straight back. A safe recovery includes:
- Finding and closing the original entry point
- Resetting passwords, especially admin accounts
- Rebuilding or cleaning affected systems
- Restoring data from backups taken before the infection
- Monitoring closely for signs of re-entry
- Reviewing what to improve afterwards
How ransomware typically unfolds
Most ransomware attacks follow a pattern. Attackers gain access through a phishing email, stolen password or unpatched system. They then explore the network quietly, often for days, collecting passwords, identifying valuable data and locating backups. Many copy data out before encrypting it, so they can threaten to publish it as well. Finally, they deploy ransomware across as many systems as possible, usually at night or over a weekend. Understanding this pattern shows why early detection, strong authentication and protected backups are so effective: each step gives defenders a chance to stop the attack.
Practise with a tabletop exercise
A tabletop exercise is a short meeting where key people walk through a realistic scenario, such as ransomware encrypting the file server on a Sunday night. Ask who would notice first, who they would call, how staff would be contacted, how long restoring would take and what would be communicated to clients. These discussions reveal gaps, such as missing phone numbers, unclear responsibilities or backups that take longer to restore than expected. Fixing them in a meeting room is far easier than discovering them during a real attack.
Prevention is cheaper
Most ransomware attacks can be prevented with a few basics:
- Multi-factor authentication on email and remote access
- Email filtering and staff phishing awareness
- Endpoint protection with ransomware rollback
- Regular patching of systems and applications
- Immutable, tested backups kept off site
Frequently asked questions
With good backups, critical systems can often be restored within a day or two. Without them, recovery can take weeks.
Many policies do, but they often require controls such as MFA and backups. Check your policy's conditions.
Depending on the data affected and your sector, you may have legal obligations. Seek advice early.
Traditional antivirus is not enough. Modern endpoint detection and response, combined with other controls, gives much better protection.




