I wanted to put together a clear guide on what to do once ransomware hits, since most people are making decisions under pressure and don't have time to research on the fly.
1. Isolate the affected systems
Disconnect infected machines from the network right away. Pull the network cable or disable Wi-Fi, don't just shut the machine down. Shutting down can wipe volatile memory that forensic teams need later, and it won't stop the ransomware from having already reached shared drives or backups still connected to the network.
2. Confirm it's ransomware and identify the strain
Look for the ransom note, the file extension changes, and any lock screen message. Tools like ID Ransomware or a quick search of the ransom note text can tell you which strain you're dealing with. This matters because some strains have known decryption tools, and some behave differently in terms of what they encrypt and how they spread.
3. Activate your incident response plan
Call in your incident response team, and loop in legal counsel and leadership early. If you have cyber insurance, this is also the point to contact your carrier, since many policies require notification within a specific window and have preferred vendors for forensics and negotiation.
4. Preserve evidence before you touch anything else
Take images of affected systems, or at minimum save logs, before you start remediation. I think this step gets skipped too often because people want to move fast, but without evidence you lose the ability to understand how the attacker got in, and you may need it for insurance claims or law enforcement.
5. Report the incident
In the US, report to the FBI's Internet Crime Complaint Center (IC3) and CISA. Reporting doesn't cost you anything and it can connect you with decryption keys or intelligence on the specific threat actor group. CISA's #StopRansomware guide is a good reference for this phase and the ones that follow (cisa.gov/stopransomware).
6. Assess your backups
Check whether your backups are actually clean and were disconnected or air gapped at the time of the attack. This is usually the step that determines how the whole recovery goes. If backups are intact, you have a real path to recovery without paying anyone. If they were connected to the network and got encrypted too, your options narrow a lot.
7. Decide on the ransom question, carefully
I'd avoid a snap decision here. Paying doesn't guarantee you get a working decryption key, and it can mark you as a target willing to pay again. Not paying might mean a longer rebuild. This is a decision for leadership, legal, and often law enforcement together, not something to decide alone at 2am. Ontrack has written about the tradeoffs in more depth if you want to go deeper on this (should we pay the ransom).
8. Rebuild and restore from clean systems
Wipe affected machines and rebuild from known-good images, then restore data from backups you've verified are clean. Prioritize the systems that matter most for safety and revenue first, and rebuild in a segmented environment so you're not reconnecting anything to the live network until it's confirmed clean.
9. Scan everything before reconnecting
Run full malware scans on restored systems before they go back on the network. Don’t rush this step. Move too fast here and you can reinfect an environment you just cleaned.
10. Review what happened and close the gaps
Once things are stable, do a proper post-incident review. Figure out the entry point, whether it was phishing, an exposed RDP port, or an unpatched vulnerability, and fix that specific gap. Update your incident response plan based on what you actually learned, not just what the textbook says.
A few honest notes: recovery timelines vary a lot depending on backup quality and how fast you isolate the threat, so I'm hesitant to promise a specific number of days. If you're dealing with an active incident right now, steps 1 through 5 are the ones to act on immediately, everything else can follow once things are contained.
Sources: