Mon–Sat 10:00–18:00 London · UK
Remote & on-site ☎ 0207 096 0936
← Guides
Security

Ransomware Recovery: A Step-by-Step Guide

What to actually do in the hours after a ransomware attack — a calm, practical recovery playbook that protects your evidence, your backups and your business.

There’s a common assumption about ransomware that gets businesses into trouble: the idea that recovery means paying a ransom, or clicking “restore” and being back to normal by lunchtime. Both are wrong, and believing either can turn a bad day into a genuine crisis.

Real recovery is a controlled sequence. Rush it and you can wipe the evidence you’ll need, restore the malware along with your files, or hand the attackers a second bite. Done properly, it’s methodical, and most businesses with decent backups come through it. Here’s the playbook we work through, in the order that actually matters.

First, correct the panic

The instinct when screens lock up is to start deleting things, rebooting servers, or reaching for the ransom note’s payment link. Resist all three. Deleting files can destroy evidence and clean copies. Rebooting can trigger further encryption or lose useful data held in memory. And paying — before you even know what’s encrypted — is the least informed decision you can make.

Ransomware also isn’t only an encryption problem any more. Most modern attacks steal data before they lock it, then threaten to publish it. That changes recovery: even a perfect backup restore doesn’t undo the fact that data may have left the building. You need to treat it as a security incident, not just an IT outage.

Step 1 — Isolate, don’t destroy

Your first job is to stop the spread. Disconnect affected machines from the network — unplug the ethernet cable, switch off Wi-Fi — but leave them powered on unless a specialist tells you otherwise. Powering down can lose forensic data that helps identify how the attackers got in.

Isolate shared drives and servers too, and pause any backup jobs so a clean backup doesn’t get overwritten with encrypted files. If you use cloud storage that syncs automatically, disconnect the syncing devices before the encryption propagates to the cloud copy.

Step 2 — Assess the blast radius

Before you can fix anything, you need to know the shape of the problem. Which machines are hit? Which file shares? Is the ransom note naming a specific strain? Are backups intact and, crucially, disconnected from the infected network?

This is where you find out whether your backup and continuity setup earns its keep. A backup that was permanently connected to the network has very likely been encrypted too — which is exactly why off-site, offline or immutable backups matter so much. If you’re not sure what’s clean, don’t guess. Restoring from a compromised backup just restarts the whole nightmare.

Step 3 — Bring in help and preserve the evidence

This is the point to call in specialists, and to notify your cyber insurer if you have one — many policies require it before you take major steps, and some provide a response team. Keep the ransom note, take photographs of affected screens, and write down a rough timeline of what you noticed and when.

You may also have reporting duties. In the UK, ransomware should be reported to Action Fraud, and if personal data is involved, UK GDPR can require you to notify the ICO within 72 hours. Good cyber security support means having someone who knows these obligations rather than working them out mid-crisis.

Step 4 — Eradicate before you restore

Once you understand the attack, the infected systems need to be cleaned or, more often, rebuilt from scratch. Wiping and reimaging is usually safer than trying to scrub malware off a machine, because attackers frequently leave hidden ways back in. This is also the moment to force password resets across the business and revoke any sessions that could still be live.

Skipping this step is the classic mistake. Restore your files onto a machine that’s still compromised and you’ll be encrypted again within days. Thorough virus and malware removal comes before recovery, not after.

Step 5 — Restore in a sensible order

Now you rebuild. Start with the systems the business most depends on, and restore from your cleanest verified backup. Bring things back gradually, checking each system before it rejoins the wider network. If your backups are incomplete or partly encrypted, specialist data recovery can sometimes retrieve more than you’d expect — but it’s a fallback, never a plan.

Test as you go. Confirm data is intact, applications work, and nothing odd is phoning home before you declare a system safe.

Step 6 — Learn from it, honestly

When the dust settles, work out how they got in — a phished password, an unpatched server, a dormant account — and close that door properly. Nearly every attack exploits something preventable, and the businesses that recover best are the ones that treat the incident as a lesson rather than bad luck.

If you’re in the middle of this now

If you’re reading this because it’s happening right now, isolate the affected machines, leave them on, stop your backups, and get expert eyes on it before you touch anything else. If you’d rather not face it alone — during an incident or, better, before one ever happens — get in touch and we’ll help you work through it calmly, in the right order.

Frequently asked questions

Should we pay the ransom to get our files back?

It's rarely the right first move, and it's never a guarantee. Paying funds criminal groups, marks you as a business that pays, and often returns a slow, buggy decryptor that only recovers part of your data. Some attackers take the money and vanish. Before anyone even discusses payment, you want a clear picture of what's encrypted, what clean backups exist, and what your legal and insurance obligations are. In most cases a proper restore is faster and safer than negotiating with the people who attacked you.

How long does ransomware recovery usually take?

It depends on how far the attack spread and how good your backups are, so anywhere from a day to a couple of weeks is realistic for a small business. Clean, tested, off-site backups are the single biggest factor — they can turn a two-week rebuild into a two-day restore. The containment and investigation steps take time too, because rushing them risks reinfecting the systems you've just cleaned.

Will we have to tell anyone, like the ICO or our clients?

Quite possibly. If personal data was accessed or stolen, UK GDPR may require you to report the breach to the ICO within 72 hours of becoming aware of it, and to notify affected people if the risk to them is high. Cyber insurers usually want to be told immediately too. This is exactly why the evidence-preserving steps early on matter — you need to be able to say what happened, not guess.

Related services

Free · no obligation

Want a hand with any of this?

Tell us what you're trying to sort out and we'll come back with a clear, no-obligation plan and price.