top of page
it support sheffield

Cyber Incident Response

What to do when a Ransomware Attack Happens

By Steve Harper  |  8 min read  | Last updated:

6 August 2026 at 11:40:04

In this guide:

- What a ransomware attack is


- What to do in the first 15 minutes


- What to do in the first hour


- Common mistakes to avoid during a ransomware incident


- Who to contact after a ransomware attack


- How to recover in the right order


- What to do after the incident has been contained


- How to reduce the risk of future ransomware attacks


- How IT Desk can help with ransomware resilience and recovery

TL;DR

If a ransomware attack happens, act quickly but carefully. Isolate affected devices, disconnect them from the network where safe to do so, preserve evidence, contact IT or cyber security support, and avoid restoring backups until the environment has been checked. Ransomware recovery should follow a safe order: contain the incident, eradicate the threat, then restore systems from trusted backups.


Key Takeaways

  • Ransomware is malware that blocks access to systems or data, often by encrypting files and demanding payment.

  • The first priority is containment: isolate affected systems and stop the attack spreading.

  • Do not wipe devices, delete evidence or restore backups before understanding the scope of the incident.

  • Ransomware may involve data theft as well as encryption, so businesses should assess whether personal data or sensitive information has been exposed.

  • Recovery should follow a structured order: contain, investigate, eradicate and restore.

  • Tested, protected and ransomware-resistant backups are critical for recovery.

  • IT Desk can help businesses improve ransomware resilience through cyber security, monitoring, backups, disaster recovery planning and managed IT support.

Recovery: Contain → Eradicate → Restore (the safe order)


Containment

  • Block known malicious IPs/domains (where identified).

  • Remove remote tools the attacker used (or isolate systems until forensics is complete).

Eradication

  • Patch exploited vulnerabilities.

  • Remove persistence mechanisms (scheduled tasks, new admin accounts, malicious GPOs).

  • Reset credentials (prioritise admins, service accounts, shared passwords).

  • Review MFA, conditional access, and admin permissions.

Restoration

  • Restore from known-good offline/immutable backups.

  • Validate restored systems before reconnecting to the network.

  • Monitor aggressively for re-entry attempts. Post-incident hardening (so it doesn't happen again)


Most successful ransomware attacks exploit gaps in a few common areas:

  • MFA everywhere (especially admin + remote access)

  • Remove unnecessary admin rights and segment admin accounts

  • Patch management for endpoints, servers, VPNs, firewalls

  • Email security and user training for phishing

  • Network segmentation (limit lateral movement)

  • Backups: 3-2-1 strategy, offline/immutable copies, regular restore tests

  • Logging/monitoring: central logs + alerting


Signs you may still be compromised

Even after recovery, watch for:

  • New admin accounts

  • MFA method changes you didn’t approve

  • Unusual login locations

  • New email forwarding rules

  • Unknown scheduled tasks/services

  • Endpoint tools disabled unexpectedly


If any of these appear, treat it as an active incident until proven otherwise.


People Also Ask

What should a business do first during a ransomware attack?

The first step is to contain the incident. Isolate affected devices, disconnect them from the network where safe to do so, stop using compromised systems and contact IT or cyber security support. Avoid wiping devices or restoring backups until the scope of the attack is understood.


Should you pay a ransomware demand?

Paying a ransom is risky and does not guarantee that systems or data will be restored. It may also encourage further criminal activity. Businesses should seek expert advice, preserve evidence, assess the impact and explore recovery options before making any decisions.


Can ransomware cause a data breach?

Yes. Ransomware can cause a data breach if personal data, customer information, employee records, financial data or sensitive business information is accessed, stolen or disclosed. Businesses should assess whether data has been exposed and whether reporting obligations apply.


How do you know if ransomware is still active?

Signs that ransomware may still be active include files continuing to encrypt, unusual processes, suspicious network activity, repeated alerts, unexpected account activity or new ransom messages. Systems should be checked by IT or security specialists before recovery begins.


Can backups recover data after ransomware?

Backups can help recover data after ransomware if they are recent, tested and protected from the attack. Backups should not be restored until the infected environment has been checked, because restoring into a compromised system can lead to reinfection.


How can businesses prevent ransomware attacks?

Businesses can reduce ransomware risk with multi-factor authentication, regular patching, secure backups, endpoint protection, email security, phishing training, least-privilege access, monitoring and a tested incident response and disaster recovery plan.


Can IT Desk help with ransomware protection and recovery?

Yes. IT Desk can help businesses improve ransomware protection through cyber security solutions, system monitoring, phishing protection, backups, disaster recovery planning and managed IT support. We can also help review recovery readiness and strengthen weak points before an incident occurs.

Need help improving ransomware resilience?


IT Desk helps businesses reduce ransomware risk with cyber security solutions, system monitoring, secure backups, phishing protection, user training and disaster recovery planning. We can review your current setup, identify weak points and help build a practical plan for prevention, response and recovery.



What is a ransomware attack?

A ransomware attack is when criminals gain access to your systems, encrypt files (or lock you out), and demand payment for a decryption key or to prevent data being leaked. Many modern ransomware groups also steal data first (“double extortion”), meaning the risk isn’t just downtime — it can include data exposure, fraud, and reputational damage.


A ransomware incident should be treated as both a technical incident and a business risk. The priority is to contain the spread, protect evidence, understand what has been affected and avoid actions that could make recovery harder.


Do not immediately wipe systems or restore backups without understanding whether the attacker still has access. If ransomware has affected a business environment, involve your IT support provider, cyber security team or incident response support as early as possible.


First 15 minutes: immediate actions

The goal here is to stop the spread and protect evidence.


  1. Isolate affected devices immediately

  2. Disconnect from the network (unplug ethernet, turn off Wi-Fi).

  3. If it’s a server, isolate the host/network segment rather than powering off everything blindly.

  4. Do not reboot, wipe, or “factory reset” yet

  5. Preserve evidence for investigation and insurance requirements.

  6. A rushed wipe can destroy logs that show how the attacker got in.

  7. Document what you’re seeing

  8. Screenshot ransom notes, file extensions, error messages.

  9. Record the time you noticed it and which users/devices are affected.

  10. Stop automated spread

  11. Disable affected user accounts temporarily (especially admin).

  12. If you suspect active encryption across the estate, consider temporarily disabling shared drives.


First hour: assess the blast radius

Now you’re working out what’s impacted and what’s at risk next.


Check:

  • Endpoints: which laptops/desktops are encrypted?

  • Servers & file shares: are shared drives affected?

  • Backups: are backups online/connected and potentially encrypted too?

  • Identity: any signs of compromised admin accounts, MFA changes, unusual logins?

  • Email / Microsoft 365: forwarding rules, unusual sign-ins, malicious OAuth apps.

  • Data exfiltration: evidence of large outbound transfers, new remote tools, unusual VPN activity.


This is where most organisations realise ransomware is rarely “one PC” — it’s often tied to credential theft, remote access, and lateral movement.


What NOT to do (common mistakes)

  • Don’t pay immediately. Paying doesn’t guarantee recovery and can encourage repeat attacks.

  • Don’t announce details publicly too early. Keep comms controlled until facts are confirmed.

  • Don’t restore before containment. If you restore while the attacker still has access, you can be reinfected.

  • Don’t assume backups are clean. Backups can be encrypted or poisoned if attackers had time.


Who to contact (and in what order)

Every business will be different, but a sensible order is:

  1. Your IT/security provider (or incident response partner)

  2. Cyber insurance provider (if applicable) Insurers often require using approved incident-response partners.

  3. Law enforcement / reporting routes In the UK, many organisations report cybercrime via Action Fraud and follow NCSC guidance.

  4. Legal/compliance support Especially if personal data or regulated data might be involved.


Regulatory considerations (UK)

If there’s a chance personal data is compromised, you may need to assess whether this is a reportable breach (e.g., to the ICO) and whether individuals need notifying. This depends on the type of data, likelihood of harm, and confirmed exposure — not just the presence of ransomware.


(Note: this is general guidance, not legal advice.)

Why this matters

A ransomware attack can quickly disrupt business operations, block access to important data and create serious security, legal and reputational risks. The first response matters because rushed decisions can spread the incident, damage evidence or make recovery harder.


This guide explains what to do when a ransomware attack happens, how to contain the incident, who to contact, what mistakes to avoid and how businesses can improve resilience before the next attack.

Ransomware Attack Response

Related Insights

So, why IT Desk?

deceleration.png

Proactive & Reactive Support

In 2024, we achieved an average response time of 13 seconds. Most IT support providers respond anywhere between 30 seconds and 1 minute.

Not only this, 99.5% of our feedback we received was rated 4 out of 4, making this one of our best years yet!

trophy.png

Award Winning

Recognised by Three Best Rated as one of the 'Three Best Rated' IT Service Providers in the Rotherham area. Our feedback definitely reflects this!

Acknowledged by Barnsley & Rotherham Chamber of Commerce over the years for Excellence in Customer Service and Commitment to People Development.

certified.png

Experienced & Certified

Awarded the 'Investors in People' certification, which is an industry standard that shows IT Desk as being actively committed to developing and supporting it's employees.

 

From apprentices to managers to solution engineers, our team of people is truly unique - often described by them as a 'family'!

Reliable & Consistent

Founded in Rotherham in 2006, we started out offering IT support to local businesses. Over the years, we've expanded to serve clients throughout the UK.

With over a decade of experience, we offer exceptional localised IT support, particularly in South Yorkshire, and specialise in assisting SMEs.

Chris W.png
Steve Harper.png
BG---Name---Chloe-Day.png
BG---Name---Morgan-C.png

Experts in the field. Driven by success.

Speak to our team today.

IT Desk are a leader in business growth through consultancy. Contact us today for a no-obligation chat. Your Success, We’re Part of IT.

Book a meeting with our team.

Click below to see our live calendar and book a meeting with our team of experts.

Innovative Solutions for Businesses

20+

Years of Experience

A legacy of excellence in digital solutions.

100%

Zero Carbon

Doing our part for the environment.

Certified by British Gas.

99.9%

Client Satisfaction Rate

Trusted by businesses across all sectors for superior service.

1200+

Projects Completed

Delivering cutting-edge solutions for a seamless digital future.

bottom of page