All articles

The ultimate step-by-step plan for recovering from ransomware

Help, we have been hit by a ransomware attack. What now?

Phase 1. Getting help

The steps in this article are sound. Yet cybercrime changes so incredibly quickly that we recommend engaging an external specialist. A good ethical hacking team knows exactly what the ripple effects and risks are for your network and systems.

Phase 2. Investigation

Objective: establish clarity so you can take the right steps.

  • How far does this attack extend?
  • What is the impact?
  • Where is that impact greatest?
  • What needs to be set in motion immediately?
  • Who around us needs to be informed?

Phase 3. Containment

Objective: limit damage by preventing spread

Isolate affected systems and restrict incoming or outgoing traffic, depending on the impact. To isolate a system immediately, unplug its network cable or switch off Wi-Fi. NEVER switch the systems off or unplug their power, because that erases all traces.

Phase 4. Removal

Objective: clean up your network

Examine your systems, remove all malicious elements and close off attackers' access.

Phase 5. Recovery

Objective: restore normal access

Restore clean backups. You can now gradually increase access to and availability of systems and applications again.

Bonus tip: look after your IT staff. They have probably endured considerable stress during this ordeal, and you will need them for some time yet…

Phase 6. Consolidation

Objective: increase your security level so you are not hit again in future.

Reflect and evaluate. Put everything you learn into clear processes to increase your maturity level. Develop a clear decision and communication tree to prevent panic-driven reactions.


Back to all articles