24/7 Support Available
Skip to main content
Advanced
Act immediately

Ransomware Incident Response

What to do in the first hours of a ransomware attack: contain the spread, preserve evidence, tell the right people, and recover in a way that does not reinfect you.

Prerequisites

  • Your incident response contacts to hand: internal leads, your IT provider, and a specialist responder.
  • Access to backups, and knowledge of whether they are offline or otherwise out of the attacker's reach.
  • Cyber insurance details, since many policies require you to call their hotline before you act.
  • A way to communicate that does not rely on the affected network, such as mobiles or a separate email.

Step-by-Step Instructions

Contain before you do anything else

Ransomware spreads across a network in minutes, so isolation is the priority. Disconnect affected machines from the network by pulling the cable or disabling wireless, and isolate or shut down shared storage and backup systems the malware could reach. Do not power infected machines off if you can avoid it, because that can destroy evidence held in memory.

Tip

Isolate, do not wipe. Rebuilding a machine straight away feels productive, but it removes the evidence you need to understand how the attackers got in and whether they are still inside.

Call for help and start the clock

Ring your incident response contact and, if you have cyber insurance, their hotline, because acting first can void a claim. Get the right people in one place: someone senior who can make decisions, IT, and legal. If personal data may be involved, the 72 hour clock for reporting to the ICO may already be running, so flag that early.

Preserve evidence

Before anything is changed, capture what you can: photograph ransom notes, note the exact time you first saw the problem, and preserve logs from firewalls, servers and cloud services before they roll over. Keep at least one infected disk image untouched. This evidence guides recovery, supports any insurance claim, and helps if the police become involved.

Work out what happened and what was taken

Establish how the attackers got in, how far they reached, and whether they copied data before encrypting it. Modern ransomware groups usually steal data and threaten to publish it, so treat the incident as a possible data breach as well as an outage. This assessment decides your legal obligations and your recovery plan.

Recover from clean backups

Do not pay first and think later. Paying does not guarantee your data back, funds criminals, and marks you as willing to pay again. Rebuild from backups you have confirmed are clean, and only reconnect systems once you have closed the way in and reset credentials. Restore in a controlled order, starting with the systems the business needs most.

Tip

Reset every credential the attacker could have seen, including service accounts and any shared passwords, before you reconnect. Restoring onto the same compromised accounts is how organisations get hit twice.

Notify and learn

Meet your reporting duties: the ICO within 72 hours if personal data is at risk, affected people if the risk to them is high, and Action Fraud for the crime itself. Once the dust settles, hold a review. The controls that would have blocked this attack are almost always cheaper than the recovery you have just been through.

Every organisation is different, and a playbook can only take you so far. If you would like a second pair of eyes, or you would rather we handled the work, our incident response team is here to help. Talk to us about your requirements.