How to recover from a Ransomware attack: A step-by-step guide

Written By: Ontrack

Date Published: Sep 24, 2026, 8:00:04 AM

How to recover from a Ransomware attack: A step-by-step guide

I wanted to put together a clear guide on what to do once ransomware hits, since most people are making decisions under pressure and don't have time to research on the fly.

1. Isolate the affected systems

Disconnect infected machines from the network right away. Pull the network cable or disable Wi-Fi, don't just shut the machine down. Shutting down can wipe volatile memory that forensic teams need later, and it won't stop the ransomware from having already reached shared drives or backups still connected to the network.

2. Confirm it's ransomware and identify the strain

Look for the ransom note, the file extension changes, and any lock screen message. Tools like ID Ransomware or a quick search of the ransom note text can tell you which strain you're dealing with. This matters because some strains have known decryption tools, and some behave differently in terms of what they encrypt and how they spread.

3. Activate your incident response plan

Call in your incident response team, and loop in legal counsel and leadership early. If you have cyber insurance, this is also the point to contact your carrier, since many policies require notification within a specific window and have preferred vendors for forensics and negotiation.

4. Preserve evidence before you touch anything else

Take images of affected systems, or at minimum save logs, before you start remediation. I think this step gets skipped too often because people want to move fast, but without evidence you lose the ability to understand how the attacker got in, and you may need it for insurance claims or law enforcement.

5. Report the incident

In the US, report to the FBI's Internet Crime Complaint Center (IC3) and CISA. Reporting doesn't cost you anything and it can connect you with decryption keys or intelligence on the specific threat actor group. CISA's #StopRansomware guide is a good reference for this phase and the ones that follow (cisa.gov/stopransomware).

6. Assess your backups

Check whether your backups are actually clean and were disconnected or air gapped at the time of the attack. This is usually the step that determines how the whole recovery goes. If backups are intact, you have a real path to recovery without paying anyone. If they were connected to the network and got encrypted too, your options narrow a lot.

7. Decide on the ransom question, carefully

I'd avoid a snap decision here. Paying doesn't guarantee you get a working decryption key, and it can mark you as a target willing to pay again. Not paying might mean a longer rebuild. This is a decision for leadership, legal, and often law enforcement together, not something to decide alone at 2am. Ontrack has written about the tradeoffs in more depth if you want to go deeper on this (should we pay the ransom).

8. Rebuild and restore from clean systems

Wipe affected machines and rebuild from known-good images, then restore data from backups you've verified are clean. Prioritize the systems that matter most for safety and revenue first, and rebuild in a segmented environment so you're not reconnecting anything to the live network until it's confirmed clean.

9. Scan everything before reconnecting

Run full malware scans on restored systems before they go back on the network. Don’t rush this step. Move too fast here and you can reinfect an environment you just cleaned.

10. Review what happened and close the gaps

Once things are stable, do a proper post-incident review. Figure out the entry point, whether it was phishing, an exposed RDP port, or an unpatched vulnerability, and fix that specific gap. Update your incident response plan based on what you actually learned, not just what the textbook says.

A few honest notes: recovery timelines vary a lot depending on backup quality and how fast you isolate the threat, so I'm hesitant to promise a specific number of days. If you're dealing with an active incident right now, steps 1 through 5 are the ones to act on immediately, everything else can follow once things are contained.

Sources:

 

Subscribe

KLDiscovery Ontrack, LLC, 9023 Columbine Road Eden Prairie, MN 55347, United States (see all locations)