Ransomware encrypts files and demands a ransom for decryption. What happens in the first few minutes often determines how big the damage ends up being — for better or worse.

Immediately: disconnect, don't shut down

The first instinct is often to shut the computer down right away. It's better to disconnect the device from the network — unplug the network cable or turn off Wi-Fi — instead of powering it off. This prevents the encryption from spreading to other devices on the network, while preserving traces that may help with analysis later.

What you should never do

The real lifesaver: your backup

This is exactly where a properly separated backup (see our article on the 3-2-1 principle) stops being a formality. If a recent, unencrypted backup exists, the way back is usually manageable: clean or reinstall affected systems, restore data from the backup, done. Without a backup, the only choice is often between paying and losing your data — both bad options.

Don't forget to report it

A ransomware incident should be reported to the police (in Germany, the state-level Cybercrime Central Reporting Offices, "ZAC"), and depending on whether personal data was affected, potentially also to the relevant data protection authority within 72 hours. This is easily forgotten in the chaos, but it's legally relevant.

The best time to prepare is beforehand

A ransomware incident can rarely be resolved completely damage-free after the fact — but it can be significantly softened if a few things are already in place: current, separated backups, promptly installed security updates, and a rough plan that doesn't need to be invented on the spot.

The difference between "annoying day" and "existential crisis" is usually a clean backup.

Prepared instead of surprised

Whether your backup, patch level, and network are set up so a ransomware incident ends up being a non-event — that's easy to clarify in a short conversation.

Get in touch