Data Protection

What to Do After a Ransomware Attack

The first steps to take after ransomware: contain, preserve evidence, contact the right people, and recover safely.

Reviewed October 11, 2026 3 minute read Reviewed by Meta IT Pro
What to Do After a Ransomware Attack — Data Protection illustration from Meta IT Pro
Part of the Data Protection & Recovery Learning Center

The first hours after a ransomware attack shape how quickly and safely a business recovers. Containment, evidence preservation, and coordinated communication matter more than speed alone.

Key takeaways

What to know before you act

  • Isolate affected systems quickly, but avoid wiping or rebooting them before evidence is preserved.
  • Bring in your incident response provider, cyber insurer, and legal counsel early.
  • Restore only from backups confirmed to be clean, and fix the entry point before reconnecting.

Why it matters

What business leaders should understand

Rushed actions—wiping systems, restoring infected backups, or contacting attackers without guidance—can make recovery slower and riskier. A calm, ordered response reduces damage.

The right response should reflect your environment, data, vendors, risk, and operational priorities. Use this guide as a practical starting point, then validate important decisions with the people responsible for your technology, cybersecurity, legal obligations, and insurance coverage.

The first hours

CISA's #StopRansomware Guide provides a detailed response checklist. For a small business, the immediate priorities are to stop the spread, preserve evidence, and get the right help involved.

  • Disconnect affected devices from the network and disable Wi-Fi; do not power them off unless advised.
  • If many systems are affected, consider disconnecting the internet connection.
  • Contact your IT or incident response provider and your cyber insurer—many policies require approved vendors.
  • Engage legal counsel to guide notification and privilege considerations.
  • Report the incident to the FBI through IC3 or a local field office, and to CISA.
  • Use out-of-band communication if email or Teams may be compromised.

Investigation and recovery

Determine how the attackers got in, which systems and data were affected, and whether data was stolen. That information drives notification decisions and ensures the same entry point is closed before recovery.

Reset credentials, especially administrator and service accounts, and rebuild or clean affected systems. Restore from backups that predate the compromise and verify them before reconnecting. Recover systems in business-priority order and monitor closely for signs of the attacker returning.

About paying a ransom

The FBI does not support paying ransoms, which does not guarantee recovery and may fund further crime. Payments can also raise legal issues, such as sanctions restrictions. Any decision should involve leadership, counsel, the insurer, and experienced incident responders.

Practical action plan

Steps your business can take

01

Disconnect affected systems from the network without powering them off.

02

Contact your IT or incident response provider, cyber insurer, and legal counsel.

03

Preserve logs and evidence and report the incident to law enforcement.

04

Restore from clean, verified backups in business-priority order.

Recommended next steps

Continue from this article.

These pages expand the specific risks and decisions covered in this guide. Use them to move from general understanding to the service, tool, or related topic that best matches your next question.

Warning signs

Do not ignore these indicators

  • Files renamed with unfamiliar extensions or ransom notes
  • Security tools disabled or backups deleted
  • Unusual administrator activity outside business hours

Frequently asked questions

Common questions, answered.

What should I do first after a ransomware attack?

Isolate affected systems, preserve evidence, and contact your incident response provider, cyber insurer, and counsel.

Should infected computers be turned off?

Disconnect them from the network but avoid powering them off unless responders advise it, to preserve evidence.

Who should we report ransomware to?

Report it to the FBI through IC3 or a local field office, and to CISA.

How Meta IT Pro can help

Related services and practical next steps

Explore the services connected to this topic. These links provide more detail about scope, safeguards, support, and how to start a conversation with our team.

Authoritative references

Sources and further reading

These primary sources support the guidance in this article and provide additional technical or consumer information.

Need help with your IT solution?

Get practical guidance from a local IT and cybersecurity team.

Meta IT Pro helps Massachusetts and Rhode Island businesses improve support, security, Microsoft 365, Google Workspace, networks, backup, recovery, and compliance readiness. Tell us what is not working - or what you want to improve - and we will help identify a sensible next step.