Ransomware encrypts files and demands a ransom for decryption. What happens in the first few minutes often determines how big the damage ends up being — for better or worse.
Immediately: disconnect, don't shut down
The first instinct is often to shut the computer down right away. It's better to disconnect the device from the network — unplug the network cable or turn off Wi-Fi — instead of powering it off. This prevents the encryption from spreading to other devices on the network, while preserving traces that may help with analysis later.
What you should never do
- Don't pay — there's no guarantee your data will actually be decrypted afterward, and it funds further attacks.
- Don't panic-reinstall everything before it's clear which devices are actually affected — you might lose data that could still have been recovered.
- Don't try random decryption tools from the internet without knowing which ransomware variant you're dealing with — in the worst case, that destroys even more.
The real lifesaver: your backup
This is exactly where a properly separated backup (see our article on the 3-2-1 principle) stops being a formality. If a recent, unencrypted backup exists, the way back is usually manageable: clean or reinstall affected systems, restore data from the backup, done. Without a backup, the only choice is often between paying and losing your data — both bad options.
Don't forget to report it
A ransomware incident should be reported to the police (in Germany, the state-level Cybercrime Central Reporting Offices, "ZAC"), and depending on whether personal data was affected, potentially also to the relevant data protection authority within 72 hours. This is easily forgotten in the chaos, but it's legally relevant.
The best time to prepare is beforehand
A ransomware incident can rarely be resolved completely damage-free after the fact — but it can be significantly softened if a few things are already in place: current, separated backups, promptly installed security updates, and a rough plan that doesn't need to be invented on the spot.
The difference between "annoying day" and "existential crisis" is usually a clean backup.
Prepared instead of surprised
Whether your backup, patch level, and network are set up so a ransomware incident ends up being a non-event — that's easy to clarify in a short conversation.
Get in touch