The essentials
- Disconnect affected machines from the network — but do not power them off. Memory can hold attacker artifacts and, in some cases, encryption keys.
- Protect your backups before anything else. Attackers hunt backups during the attack, not after it.
- Do not pay, reply to, or negotiate with the attackers before a professional assessment.
- Do not wipe, rebuild, or restore onto affected systems — you may overwrite the only evidence of what was taken.
- Photograph every ransom note and record the exact time you found it.
Ransomware is engineered to make you act before you think: countdown timers, threats to leak data, and a payment address one click away. The attackers have rehearsed this moment hundreds of times. You have not — which is exactly why your first hour should follow a checklist, not an instinct.
The good news: the correct first moves are simple, and none of them require special tools. They require restraint.
Do this now
- Disconnect, don't power off. Unplug network cables or disable Wi-Fi on affected machines, but leave them running. Powering off destroys memory that may contain encryption keys, attacker tooling, and the clearest record of what happened.
- Protect the backups. Take backup systems offline or lock their accounts now, before doing anything else, and identify your last known-good copy. If backups survive, most of your leverage survives with them.
- Photograph the ransom note. Capture every variant of the note, the changed file extensions, and any onion or contact addresses, with your phone. Note the time you first saw each one.
- Contain the accounts. From a device you trust — not an affected one — change passwords for privileged and administrator accounts and revoke active sessions where you can.
- Move communication out of band. Assume the attacker can read company email and chat. Coordinate by phone or a personal-device messenger until responders confirm what is compromised.
- Engage professional responders. The earlier scoping starts, the more options remain open — free decryptors, clean recovery paths, and an informed negotiation posture if it ever comes to that.
What not to do
- Do not contact or pay the attackers on your own — first contact sets the tone, the price, and the legal exposure of everything that follows.
- Do not run antivirus "cleanup", delete encrypted files, or remove ransom notes. They are evidence.
- Do not restore backups onto infrastructure the attacker may still control.
- Do not reboot or power off encrypted machines.
- Do not discuss the incident over company email or chat the attacker may be reading.
Preserve the evidence
Whatever else happens, these are the artifacts the investigation — and any insurance claim, dispute, or prosecution — will be built from:
- The ransom notes and a few sample encrypted files, left in place.
- One affected machine kept network-isolated but powered on, untouched.
- Firewall, VPN, and remote-access logs — export them before they rotate.
- Endpoint security alerts from the days before the encryption began.
- A written timeline: who noticed what, and when, starting from the first anomaly.
Keep a clear head
The countdown timer is theater. It exists to push you into the one irreversible decision — payment — before you understand your position. Hours spent scoping almost always buy better options, not worse ones.
Name one person to lead, one to take notes, and slow the room down. A ransomware event is a marathon in its first mile; teams that pace themselves recover faster and lose less.
Questions victims ask
Should we pay the ransom?
Not before a professional assessment. Payment may be illegal depending on who the attacker is (sanctions), decryptors supplied by criminals routinely fail or only partially work, and your backups may make payment unnecessary. A responder can usually assess your real position within hours.
Should we shut the machines down to stop the encryption?
Isolate them from the network instead. Disconnection stops spread and command-and-control; power-off destroys volatile memory that can contain encryption keys and attacker artifacts investigators need.
Will isolating systems break our operations?
Possibly — and that is usually the right trade. A service interruption you control is recoverable; continued encryption and data theft may not be.