Responding to ransomware safely

A ransom note or files that suddenly will not open is one of the most stressful moments in a small business's life. The choices made in the first hour — what you switch off, what you preserve, who you call — shape how much can realistically be recovered.

This page sets out a calm, ordered response, what to preserve for anyone investigating, and where the decisions genuinely sit outside what any response tool can decide for you.

Signs of a ransomware incident

  • Files renamed with an unfamiliar extension, or that suddenly will not open.
  • A ransom note appearing as a text file, desktop wallpaper change or pop-up window.
  • Shared drives, backups or network folders becoming inaccessible all at once.
  • Security software disabled or reporting it has been tampered with.
  • Unusually high disk or network activity shortly before files became unreadable.
  • Multiple devices affected within a short window, suggesting spread across the network.

Safe immediate actions, in order

  1. Isolate affected devices from the network — disconnect Wi-Fi and network cables, or disable the network adapter — to stop further spread.
  2. Avoid powering devices off where evidence may matter. Shutting down can lose information held only in memory that helps establish what happened. Isolate from the network first and seek advice before powering off, unless it is unavoidable to stop active, visible damage.
  3. Identify how far it has spread by checking other devices, shared drives and servers on the same network for the same signs.
  4. Protect your backups immediately. Disconnect backup drives or pause backup software if there is any risk the backup destination is reachable from an infected device, so it cannot also be encrypted.
  5. Verify a backup is clean and restorable before relying on it — check its date, and if possible test-restore a sample in an isolated environment rather than assuming it works.
  6. Preserve the ransom note and any attacker contact details exactly as they appear, without engaging in conversation.
  7. Change passwords for critical accounts from a device you know is clean, especially where credentials may have been harvested before encryption began.
  8. Bring in a qualified incident-response specialist where the incident affects core systems, multiple devices or customer data — this is often the point where in-house effort alone is not enough.

On paying the ransom

Whether to pay a ransom is a business and legal decision that depends on advice from your insurer, legal counsel and, in some jurisdictions, sanctions or regulatory rules that may apply. It sits outside what Cyber Crisis Desk can decide or recommend for you. We focus on containment, evidence and recovery steps regardless of that decision.

Assessing whether data was taken, not just encrypted

Many modern ransomware incidents also involve data being copied out before encryption, used as extra leverage. This affects your notification obligations even if you can restore from backup without paying anything.

  • Check network and firewall logs for unusual outbound data transfers in the days before the attack was noticed.
  • Check whether the ransom note or attacker communication references specific files or data — a sign they may have accessed content.
  • Review which systems held personal, financial or commercially sensitive data, and whether the affected devices had access to them.
  • Treat exfiltration as possible rather than ruled out unless you have specific evidence to the contrary.

Evidence worth preserving

  • The ransom note, in its original file or format, with timestamps.
  • A list of affected devices, shared drives and the approximate time each was noticed.
  • Security software or endpoint alerts logged around the time of the incident.
  • Firewall, VPN and network logs covering the days before and after detection.
  • A written timeline of what was isolated, when, and by whom.

What to avoid

  • Do not pay, negotiate with or otherwise contact the attacker yourself before taking advice — this is a decision for your insurer and legal counsel, not something to act on alone.
  • Do not attempt to trace, identify or access the attacker's systems. Cyber Crisis Desk is strictly defensive: no hack-back, no tracing.
  • Do not run "decryptor" tools of unknown origin found online — some are themselves malicious.
  • Do not wipe and reinstall affected devices before logs and evidence have been captured, unless actively stopping ongoing damage requires it.
  • Do not reconnect backups to the network until you are confident the source of the infection has been removed.

Regulators, insurers and authorities

  • Your cyber insurer — as early as possible; many policies specify approved incident-response providers and require early notification to remain valid.
  • Your data-protection regulator — if personal data was likely accessed or exfiltrated, most jurisdictions set a notification deadline that starts running from when you became aware, not when the investigation concludes. In the UK that is the ICO.
  • Legal counsel — to advise on notification duties, contractual obligations to customers or partners, and any sanctions considerations around payment.
  • National reporting channels — for example Action Fraud and the NCSC in the UK, and the equivalent body where you operate.

Cyber Crisis Desk is not a law-enforcement, legal or forensic service and does not report on your behalf, negotiate with attackers, or make the pay/not-pay decision. It helps you organise the facts you need to make those calls with proper advice.

How Cyber Crisis Desk helps

A free emergency triage takes a few questions about what is affected, whether it is spreading, and whether backups are available. From that, the platform selects a ransomware playbook and builds an Immediate Rescue Plan grouped by urgency.

  • Client Next Action gives you one clear step at a time instead of a wall of advice.
  • Evidence requests tell you exactly what to capture before systems are rebuilt, and store it in your private case.
  • Recovery tracks record which devices are isolated, which backups are verified and what has been restored.
  • Structured reports assemble the timeline and evidence into a document for your insurer, legal counsel or regulator.
  • Monitoring and closure keeps the case open until follow-up checks actually pass.

See how the guided workflow fits together or compare the plans and the one-time Emergency Pass.

Clear limitations

  • We do not decrypt files, negotiate with attackers or make the decision on whether to pay a ransom.
  • We do not perform deep forensic analysis or malware reverse engineering, and we do not guarantee any outcome.
  • This is guided response, not a substitute for a qualified incident-response specialist, insurer or legal counsel where the incident is severe or regulated.
  • We do not provide legal advice or make legal determinations for you.

Common questions

Should I turn everything off straight away?
Disconnect affected devices from the network first. Powering them off can lose evidence held in memory that helps establish what happened, so seek advice before a full shutdown unless it is the only way to stop active, visible damage.
Can Cyber Crisis Desk decrypt my files?
No. We do not provide decryption tools or negotiate with attackers. We help you contain the incident, protect and verify backups, and organise evidence for your insurer, legal counsel or a specialist responder.
My backup looks fine — do I still need to check anything?
Yes. Confirm the backup predates the infection and, where possible, test-restore a sample in an isolated environment. Backups connected to the network at the time of the attack may also be affected.
Do I have to tell anyone if I restore from backup and never pay?
Possibly. If data may have been accessed or copied before encryption, notification duties can still apply regardless of whether you paid or restored successfully. Check with your regulator and legal counsel.

Related incident help

Work through it with a plan

Emergency triage is free and takes a couple of minutes.