What to do after a ransomware attack
Take a breath — you still have control. The first hours decide what is recoverable. These steps protect your options.
- 1
Isolate affected systems
Disconnect affected machines from the network (unplug cables, disable Wi-Fi). Isolate rather than power off where possible: powering off can destroy volatile evidence and, for some variants, data that is still recoverable.
- 2
Don't engage the attackers
Don't reply to the ransom note or negotiate before the situation is assessed. Contact doesn't improve recovery options and can complicate insurance and legal positions.
- 3
Preserve everything
Leave encrypted files, ransom notes, backups and logs exactly as they are. Don't rebuild servers, reinstall systems or run cleanup tools yet — recovery and investigation both depend on the current state.
- 4
Secure accounts
Reset credentials for administrative and remote-access accounts from a clean device, and enforce MFA. Assume the attacker still has access until proven otherwise.
- 5
Identify what was affected
List affected systems, shares, databases and backups. Note when encryption appears to have started; timestamps on encrypted files help.
- 6
Check backups carefully
Confirm backups exist, are complete and were not encrypted or deleted. Don't restore into the compromised environment until it is confirmed clean.
- 7
Get an assessment
A recovery assessment establishes the variant, what remains recoverable at storage and file level, and a safe restore order — before any irreversible action.
- 8
Notify the right people
Management, insurer, legal advisers and, where required, regulators and affected parties. Your insurer may have specific requirements for how the response is run.
Dealing with this now?
Contact AS for an initial assessment of your recovery situation.
Common questions
Should we pay?
Assess recovery options first. Payment doesn't guarantee working decryption, may be restricted in your jurisdiction and funds further attacks. Where technically feasible, AS investigates available recovery and decryption options before that decision is considered.
Is it safe to keep working on unaffected machines?
Only once they are confirmed unaffected and isolated from the compromised network. Until then, assume spread is possible.
Our backups were encrypted too. Is there anything left?
Often, yes. Partially encrypted files, storage-level remnants and snapshots frequently contain recoverable data. An assessment determines what survived.