.png)
Cyber Incident Response
What to do when a Ransomware Attack Happens
By Steve Harper | 8 min read | Last updated:
6 August 2026 at 11:40:04
In this guide:
- What a ransomware attack is
- What to do in the first 15 minutes
- What to do in the first hour
- Common mistakes to avoid during a ransomware incident
- Who to contact after a ransomware attack
- How to recover in the right order
- What to do after the incident has been contained
- How to reduce the risk of future ransomware attacks
- How IT Desk can help with ransomware resilience and recovery
TL;DR
If a ransomware attack happens, act quickly but carefully. Isolate affected devices, disconnect them from the network where safe to do so, preserve evidence, contact IT or cyber security support, and avoid restoring backups until the environment has been checked. Ransomware recovery should follow a safe order: contain the incident, eradicate the threat, then restore systems from trusted backups.
Key Takeaways
Ransomware is malware that blocks access to systems or data, often by encrypting files and demanding payment.
The first priority is containment: isolate affected systems and stop the attack spreading.
Do not wipe devices, delete evidence or restore backups before understanding the scope of the incident.
Ransomware may involve data theft as well as encryption, so businesses should assess whether personal data or sensitive information has been exposed.
Recovery should follow a structured order: contain, investigate, eradicate and restore.
Tested, protected and ransomware-resistant backups are critical for recovery.
IT Desk can help businesses improve ransomware resilience through cyber security, monitoring, backups, disaster recovery planning and managed IT support.
Recovery: Contain → Eradicate → Restore (the safe order)
Containment
Block known malicious IPs/domains (where identified).
Remove remote tools the attacker used (or isolate systems until forensics is complete).
Eradication
Patch exploited vulnerabilities.
Remove persistence mechanisms (scheduled tasks, new admin accounts, malicious GPOs).
Reset credentials (prioritise admins, service accounts, shared passwords).
Review MFA, conditional access, and admin permissions.
Restoration
Restore from known-good offline/immutable backups.
Validate restored systems before reconnecting to the network.
Monitor aggressively for re-entry attempts. Post-incident hardening (so it doesn't happen again)
Most successful ransomware attacks exploit gaps in a few common areas:
MFA everywhere (especially admin + remote access)
Remove unnecessary admin rights and segment admin accounts
Patch management for endpoints, servers, VPNs, firewalls
Email security and user training for phishing
Network segmentation (limit lateral movement)
Backups: 3-2-1 strategy, offline/immutable copies, regular restore tests
Logging/monitoring: central logs + alerting
Signs you may still be compromised
Even after recovery, watch for:
New admin accounts
MFA method changes you didn’t approve
Unusual login locations
New email forwarding rules
Unknown scheduled tasks/services
Endpoint tools disabled unexpectedly
If any of these appear, treat it as an active incident until proven otherwise.
People Also Ask
What should a business do first during a ransomware attack?
The first step is to contain the incident. Isolate affected devices, disconnect them from the network where safe to do so, stop using compromised systems and contact IT or cyber security support. Avoid wiping devices or restoring backups until the scope of the attack is understood.
Should you pay a ransomware demand?
Paying a ransom is risky and does not guarantee that systems or data will be restored. It may also encourage further criminal activity. Businesses should seek expert advice, preserve evidence, assess the impact and explore recovery options before making any decisions.
Can ransomware cause a data breach?
Yes. Ransomware can cause a data breach if personal data, customer information, employee records, financial data or sensitive business information is accessed, stolen or disclosed. Businesses should assess whether data has been exposed and whether reporting obligations apply.
How do you know if ransomware is still active?
Signs that ransomware may still be active include files continuing to encrypt, unusual processes, suspicious network activity, repeated alerts, unexpected account activity or new ransom messages. Systems should be checked by IT or security specialists before recovery begins.
Can backups recover data after ransomware?
Backups can help recover data after ransomware if they are recent, tested and protected from the attack. Backups should not be restored until the infected environment has been checked, because restoring into a compromised system can lead to reinfection.
How can businesses prevent ransomware attacks?
Businesses can reduce ransomware risk with multi-factor authentication, regular patching, secure backups, endpoint protection, email security, phishing training, least-privilege access, monitoring and a tested incident response and disaster recovery plan.
Can IT Desk help with ransomware protection and recovery?
Yes. IT Desk can help businesses improve ransomware protection through cyber security solutions, system monitoring, phishing protection, backups, disaster recovery planning and managed IT support. We can also help review recovery readiness and strengthen weak points before an incident occurs.
Need help improving ransomware resilience?
IT Desk helps businesses reduce ransomware risk with cyber security solutions, system monitoring, secure backups, phishing protection, user training and disaster recovery planning. We can review your current setup, identify weak points and help build a practical plan for prevention, response and recovery.
What is a ransomware attack?
A ransomware attack is when criminals gain access to your systems, encrypt files (or lock you out), and demand payment for a decryption key or to prevent data being leaked. Many modern ransomware groups also steal data first (“double extortion”), meaning the risk isn’t just downtime — it can include data exposure, fraud, and reputational damage.
A ransomware incident should be treated as both a technical incident and a business risk. The priority is to contain the spread, protect evidence, understand what has been affected and avoid actions that could make recovery harder.
Do not immediately wipe systems or restore backups without understanding whether the attacker still has access. If ransomware has affected a business environment, involve your IT support provider, cyber security team or incident response support as early as possible.
First 15 minutes: immediate actions
The goal here is to stop the spread and protect evidence.
Isolate affected devices immediately
Disconnect from the network (unplug ethernet, turn off Wi-Fi).
If it’s a server, isolate the host/network segment rather than powering off everything blindly.
Do not reboot, wipe, or “factory reset” yet
Preserve evidence for investigation and insurance requirements.
A rushed wipe can destroy logs that show how the attacker got in.
Document what you’re seeing
Screenshot ransom notes, file extensions, error messages.
Record the time you noticed it and which users/devices are affected.
Stop automated spread
Disable affected user accounts temporarily (especially admin).
If you suspect active encryption across the estate, consider temporarily disabling shared drives.
First hour: assess the blast radius
Now you’re working out what’s impacted and what’s at risk next.
Check:
Endpoints: which laptops/desktops are encrypted?
Servers & file shares: are shared drives affected?
Backups: are backups online/connected and potentially encrypted too?
Identity: any signs of compromised admin accounts, MFA changes, unusual logins?
Email / Microsoft 365: forwarding rules, unusual sign-ins, malicious OAuth apps.
Data exfiltration: evidence of large outbound transfers, new remote tools, unusual VPN activity.
This is where most organisations realise ransomware is rarely “one PC” — it’s often tied to credential theft, remote access, and lateral movement.
What NOT to do (common mistakes)
Don’t pay immediately. Paying doesn’t guarantee recovery and can encourage repeat attacks.
Don’t announce details publicly too early. Keep comms controlled until facts are confirmed.
Don’t restore before containment. If you restore while the attacker still has access, you can be reinfected.
Don’t assume backups are clean. Backups can be encrypted or poisoned if attackers had time.
Who to contact (and in what order)
Every business will be different, but a sensible order is:
Your IT/security provider (or incident response partner)
Cyber insurance provider (if applicable) Insurers often require using approved incident-response partners.
Law enforcement / reporting routes In the UK, many organisations report cybercrime via Action Fraud and follow NCSC guidance.
Legal/compliance support Especially if personal data or regulated data might be involved.
Regulatory considerations (UK)
If there’s a chance personal data is compromised, you may need to assess whether this is a reportable breach (e.g., to the ICO) and whether individuals need notifying. This depends on the type of data, likelihood of harm, and confirmed exposure — not just the presence of ransomware.
(Note: this is general guidance, not legal advice.)
Why this matters
A ransomware attack can quickly disrupt business operations, block access to important data and create serious security, legal and reputational risks. The first response matters because rushed decisions can spread the incident, damage evidence or make recovery harder.
This guide explains what to do when a ransomware attack happens, how to contain the incident, who to contact, what mistakes to avoid and how businesses can improve resilience before the next attack.

Related Insights
So, why IT Desk?

Proactive & Reactive Support
In 2024, we achieved an average response time of 13 seconds. Most IT support providers respond anywhere between 30 seconds and 1 minute.
Not only this, 99.5% of our feedback we received was rated 4 out of 4, making this one of our best years yet!

Award Winning
Recognised by Three Best Rated as one of the 'Three Best Rated' IT Service Providers in the Rotherham area. Our feedback definitely reflects this!
Acknowledged by Barnsley & Rotherham Chamber of Commerce over the years for Excellence in Customer Service and Commitment to People Development.

Experienced & Certified
Awarded the 'Investors in People' certification, which is an industry standard that shows IT Desk as being actively committed to developing and supporting it's employees.
From apprentices to managers to solution engineers, our team of people is truly unique - often described by them as a 'family'!

Reliable & Consistent
Founded in Rotherham in 2006, we started out offering IT support to local businesses. Over the years, we've expanded to serve clients throughout the UK.
With over a decade of experience, we offer exceptional localised IT support, particularly in South Yorkshire, and specialise in assisting SMEs.

Innovative Solutions for Businesses
20+
Years of Experience
A legacy of excellence in digital solutions.
100%
Zero Carbon
Doing our part for the environment.
Certified by British Gas.
99.9%
Client Satisfaction Rate
Trusted by businesses across all sectors for superior service.
1200+
Projects Completed
Delivering cutting-edge solutions for a seamless digital future.











