Skip to content
English - United States
  • There are no suggestions because the search field is empty.

What to Do After a Ransomware Attack

The first 24 hours after ransomware, step by step.

After a ransomware attack: isolate affected systems, preserve evidence, call your incident response team and your cyber insurer, then recover from clean backups. Do not pay, wipe or reboot anything until someone with incident response experience is directing the effort.

The first hour

  1. Isolate. Disconnect affected machines from the network (unplug the cable or disable Wi-Fi). Do not power them off; memory may hold evidence and keys.
  2. Stop the spread. Disable compromised accounts, block the attacker's access path, and protect the backup system first.
  3. Call for help. Your IT provider's incident response line, then your cyber insurance carrier. Most policies require notice quickly and have approved response firms.
  4. Preserve evidence. Keep the ransom note, screenshots and logs. Do not delete anything.

The first day

  • Determine the scope: which systems, which data, and whether data was exfiltrated. Many groups steal before they encrypt, which changes your notification obligations.
  • Confirm backups are intact and uninfected before restoring anything.
  • Engage legal counsel, especially if customer, employee or regulated data is involved.
  • Communicate internally with one clear message and one point of contact.

Recovery

Rebuild from known-clean images and restore data from verified backups, in priority order set by your business continuity plan. Reset every credential. Close the entry point before bringing systems back online, or you will do this twice.

Should you pay?

Paying does not guarantee working keys or deleted data, may be restricted depending on who the attacker is, and funds the next attack. Decisions about payment belong with your insurer, counsel and response team, not with whoever is most panicked.

Afterward

Write down what happened and fix the cause: MFA, patching, EDR, immutable backups, training. An incident response plan written now makes the next event far less chaotic.

Mentis Group provides breach remediation and ransomware removal as part of our IT Project Services: identifying the source, containing the threat, restoring systems while preserving forensics, and putting controls in place to prevent recurrence. See does Mentis Group offer breach remediation and, for how attacks start, what is ransomware. Call (866) 901-7808.

Have a question about your own environment? Schedule a consultation with Mentis Group or call (866) 901-7808.