Cybersecurity

    Ransomware Attack Response: What to Do When Your Business is Hit

    29 January 2026
    Updated 18 August 2026
    6 min read
    Ransomware attack response and recovery guide

    Step-by-step guide on what to do if your business suffers a ransomware attack. Learn immediate actions, who to contact, recovery steps, and how to prevent future attacks.

    Your Business Has Been Hit by Ransomware - What Now?

    Discovering your business has fallen victim to a ransomware attack is terrifying. Files are encrypted, systems are locked, and criminals are demanding payment. In these critical moments, the actions you take can mean the difference between recovery and disaster.

    This guide provides a clear, step-by-step ransomware response plan to help Isle of Man businesses navigate this crisis effectively.

    Immediate Actions: The First 30 Minutes

    Time is critical. Here's what to do immediately when you discover a ransomware infection:

    1. Don't Panic - But Act Fast

    Stay calm and focused. Panic leads to mistakes that can make the situation worse.

    2. Disconnect Affected Systems Immediately

    This is the most critical step to stop ransomware spreading:

    • Unplug network cables from affected computers
    • Disable Wi-Fi on infected devices
    • Do NOT power off the computers yet (forensic evidence may be needed)
    • Disconnect from VPN if connected remotely
    • Isolate network segments if possible

    3. Disconnect Backup Systems

    Immediately disconnect any backup drives or systems to prevent the ransomware encrypting your backups:

    • Unplug external backup drives
    • Disconnect cloud backup sync
    • Isolate backup servers from the network

    4. Document Everything

    Take photos of:

    • Ransom notes on screens
    • File extensions on encrypted files
    • Any error messages
    • The time you discovered the attack

    5. Alert Your IT Team or Provider

    Contact your IT support immediately. If you have a managed IT provider like Omega IT, call our emergency line. We can begin incident response procedures straight away.

    The First Hour: Containment and Assessment

    6. Identify the Scope of the Attack

    Work with your IT team to determine:

    • Which systems are affected?
    • Which systems are still clean?
    • What data has been encrypted?
    • Are backups intact and accessible?
    • When did the attack likely begin?

    7. Identify the Ransomware Variant

    Knowing the specific ransomware helps determine recovery options:

    • Check the ransom note for identifying information
    • Note the file extensions added to encrypted files
    • Use tools like ID Ransomware (id-ransomware.malwarehunterteam.com) to identify the variant
    • Some older variants have free decryption tools available

    8. Preserve Evidence

    Before any recovery attempts:

    • Create forensic images of affected systems if possible
    • Save copies of ransom notes
    • Preserve system logs
    • Document the attack timeline
    • This evidence may be needed for insurance claims or law enforcement

    Who to Contact After a Ransomware Attack

    Law Enforcement

    Report the attack to:

    • Action Fraud (UK): 0300 123 2040 or actionfraud.police.uk
    • Isle of Man Constabulary: Report cybercrime through official channels
    • National Cyber Security Centre (NCSC): report@phishing.gov.uk

    Your Cyber Insurance Provider

    If you have cyber insurance, contact them immediately:

    • Many policies have 24/7 incident response hotlines
    • They may provide access to specialist incident response teams
    • Document everything for your claim
    • Follow their guidance on ransom payment decisions

    Legal Counsel

    Consider contacting a lawyer experienced in cyber incidents, especially if:

    • Customer or employee data may have been stolen
    • You operate in regulated industries
    • You're considering ransom payment

    Data Protection Authority

    Under GDPR, you may need to report to the ICO within 72 hours if personal data has been compromised:

    • Information Commissioner's Office (ICO): ico.org.uk
    • Report if there's a risk to individuals' rights and freedoms
    • Document your breach assessment

    Should You Pay the Ransom?

    This is the most difficult decision. Here's what to consider:

    Reasons NOT to Pay

    • No guarantee of recovery: Many victims pay and never receive decryption keys
    • Funds criminal activity: Payment encourages more attacks
    • You become a target: Paying makes you a known payer for future attacks
    • May be illegal: Paying certain groups violates sanctions laws
    • Data may already be stolen: Payment doesn't prevent data being sold

    When Businesses Consider Paying

    • No viable backups exist
    • Business survival depends on immediate recovery
    • Critical data cannot be recreated
    • Insurance covers the payment

    Our Recommendation

    Do not pay unless absolutely necessary. Work with your IT provider and cyber insurance to explore all recovery options first. If you must pay, use experienced negotiators - never deal directly with attackers.

    Recovery: Getting Your Business Back Online

    Option 1: Restore from Backups

    This is the preferred recovery method if clean backups exist:

    1. Verify backups are clean - scan before restoring
    2. Rebuild systems from scratch - don't just restore over infected systems
    3. Restore data from the most recent clean backup
    4. Test restored systems before reconnecting to network
    5. Update all passwords across the organisation

    Option 2: Decryption Tools

    Check if free decryption tools exist:

    • No More Ransom Project: nomoreransom.org
    • Tools exist for many older ransomware variants
    • Your IT provider can check for available decryptors

    Option 3: Professional Data Recovery

    Specialist firms may be able to recover some data through forensic techniques.

    Post-Incident: Preventing Future Attacks

    Once recovered, take immediate steps to strengthen your defences:

    Immediate Security Improvements

    • Reset ALL passwords - especially admin and service accounts
    • Enable MFA (Multi-Factor Authentication) everywhere
    • Patch all systems - apply outstanding security updates
    • Review admin access - remove unnecessary privileges
    • Improve email security - consider Proofpoint or similar

    Long-Term Security Strategy

    • Implement MDR (Managed Detection and Response) for 24/7 monitoring
    • Deploy EDR (Endpoint Detection and Response) on all devices
    • Regular security awareness training for all staff
    • Test backups regularly - including full restoration tests
    • Develop an incident response plan before the next attack
    • Consider cyber insurance if you don't have it

    Ransomware Response Checklist

    Print this checklist and keep it accessible:

    Immediate (0-30 minutes)

    • ☐ Disconnect affected systems from network
    • ☐ Disconnect backup systems
    • ☐ Document/photograph ransom notes
    • ☐ Alert IT team or provider
    • ☐ Do NOT power off systems

    First Hour

    • ☐ Assess scope of infection
    • ☐ Identify ransomware variant
    • ☐ Preserve evidence
    • ☐ Contact cyber insurance

    First 24 Hours

    • ☐ Report to law enforcement
    • ☐ Assess GDPR reporting requirements
    • ☐ Begin recovery planning
    • ☐ Communicate with stakeholders

    Get Help Now

    If your Isle of Man business is experiencing a ransomware attack, contact Omega IT immediately. Our team can provide:

    • Emergency incident response
    • Forensic analysis and containment
    • Recovery and restoration support
    • Post-incident security improvements

    Don't face a ransomware attack alone. Call us now on 0800 254 5458 for immediate assistance.

    Frequently Asked Questions

    Related Topics

    ransomware attack
    ransomware response
    cyber attack
    incident response
    ransomware recovery
    cybersecurity
    data breach

    Need IT Support in the UK?

    Contact Omega IT today for expert IT support, cybersecurity, and Microsoft 365 services tailored for UK businesses.