ISEC7 Digital Workplace Blog

Ransomware Recovery: What to Do After an Attack

Written by Remi Keusseyan | May 25, 2021, 7:30:00 AM

Reviewed and updated in October 2026.

Ransomware is malware that encrypts files on a device, making the files and the systems that rely on them unusable. The attackers then demand a ransom in exchange for decryption. If your organization has just been hit, or wants to make sure it never gets hit twice, this guide walks through what to do now and what to change afterwards.

Ransomware recovery means containing the attack, finding and closing the way the attackers got in, and restoring systems and data from clean backups before returning to normal operations. Government agencies such as the US Cybersecurity and Infrastructure Security Agency (CISA) and the German Federal Office for Information Security (BSI) recommend isolating affected systems immediately, reporting the incident and restoring from offline backups. The FBI does not support paying the ransom.

How does a ransomware attack work?

Ransomware as a Service (RaaS) and Malware as a Service (MaaS) have changed the threat landscape: almost anyone can now become a threat actor. Attacks usually follow the same phases. The attackers gain access to the network, exfiltrate as much sensitive corporate data as possible and finally encrypt the drives. They then threaten to publish the stolen data unless the ransom is paid, a tactic known as double extortion. The BSI rates ransomware as one of the greatest operational threats to cybersecurity.

Victims are often forced to shut down their systems completely and, in the worst cases, to rebuild their entire infrastructure from the ground up. Some companies pay the ransom and treat it as an expensive wake-up call. Others get hacked again and pay a second time. "Fool me once, shame on you; fool me twice, shame on me." The steps below are meant to make sure you are not fooled twice.

What should you do immediately after a ransomware attack?

  • Isolate affected systems. Disconnect infected devices from the network to stop the spread, but do not wipe them yet; they hold evidence.
  • Report the incident. In Germany, organizations covered by the NIS2 implementation act, in force since 6 December 2025, must send an initial report to the BSI within 24 hours. In the US, report to CISA or the FBI via IC3. Also involve law enforcement.
  • Work from a plan. The #StopRansomware Guide published by CISA, the FBI, the NSA and MS-ISAC contains a detailed response checklist.

1. Understand what happened

Perform a full post-incident investigation, using an independent third party if needed, to understand how the company was breached and, more importantly, which areas need improvement to prevent it from happening again. Time is not on your side. Based on the results, make the necessary changes.

2. Review your security posture

CISA's guidance on protecting against ransomware can be summarized in the following measures.

Keep your environment up to date

Update all systems, from back-end servers to desktops, laptops and mobile devices, with the latest patches. The same applies to applications, because outdated software is one of the main attack surfaces. Prioritize vulnerabilities listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, and make sure your policies cover security updates.

Back up regularly and keep backups offline

Back up all mission-critical servers and data regularly, at least daily, and keep copies offline or immutable, for example on tape stored in a safe, so they cannot be deleted or encrypted without physical access. CISA notes that many ransomware variants actively search for and delete or encrypt accessible backups. Keep multiple copies in different locations for redundancy, encrypt them, and test them regularly to make sure data can actually be restored. Many companies have reached for a backup in a crisis only to find it corrupted.

Secure your network

Instruct users not to open unknown links or attachments from unsolicited emails. Configure firewalls to limit inbound and outbound traffic to a defined set of trusted addresses.

Use secure networks when away

Outside the office, use secure connections only. In public places, that means using your mobile carrier connection (4G or 5G) instead of open public Wi-Fi, for example by using your phone as a hotspot for your laptop. At home, use a wired Ethernet connection if available, or make sure your Wi-Fi access point uses WPA3, or at least WPA2 with AES; WEP and the original WPA are insecure. On top of that, let users reach the corporate network from outside only through a VPN or a containerized solution. More on this in Everyday Security Risks: Wi-Fi.

Improve password security

Require long passwords, check new passwords against lists of known compromised ones and do not allow reuse. Current guidance in NIST SP 800-63B-4 no longer recommends forcing periodic password changes; require a change when there is evidence of compromise. Enable multi-factor authentication (MFA) for all access to corporate resources such as mail and applications, preferably with phishing-resistant methods. See Demystifying Security: Multi-Factor Authentication.

Grant only minimum permissions

Grant users only the permissions they need, especially members of the IT team. Administrators should use a separate admin account or, better still, temporary accounts whose privileges are elevated only for specific administrative tasks.

Filter email

Use dedicated software to scan all incoming and outgoing email, filter spam, executable files and phishing emails before they reach users, and flag anything from untrusted sources or domains.

3. Build a disaster recovery plan

Better safe than sorry. Consider how an attack could affect your infrastructure and your whole business, in terms of both reputation and cost, and how you could recover as quickly as possible. Some organizations have had to rebuild everything from the ground up, unable to operate and generate business in the meantime. A fraction of that effort spent on a backup infrastructure beforehand would have let them restore most or all of their systems quickly.

This can range from offline cold-standby servers hosting your core business-critical services, applications and data to a completely separate, isolated backup site. Test these systems regularly, keep them up to date and documented, so they are there when you need them, and hopefully you never will.

4. Train your employees

You are only as strong as your weakest link, and your users are your first and last line of defense. You might have the best security software and hardware, a disaster recovery plan, strong IT policies and MFA, but if users still click any link from an unknown sender or open any attachment, you are not safe.

Brief them on the risks, show how simple, effective habits avoid most of them, and tell them whom to contact when in doubt. Then test them, for example with internal phishing simulations, to see whether they click, ignore or report the bait. Well-trained users can be one of your best assets; untrained ones one of your biggest risks. Read more in Why Training Is Important and Training as Your First Line of Defense.

5. Implement proper cyber defense

Protect every type of endpoint. On servers and workstations, endpoint detection and response (EDR) or extended detection and response (XDR) detects and stops ransomware behavior, such as mass encryption of files. On smartphones and tablets, Mobile Threat Defense (MTD) detects malware and phishing, which are common first steps of an attack. Many of these solutions use machine learning and behavioral analysis to detect previously unknown threats. For an overview of the categories, see Demystifying Security: EPP, EDR and MTD.

6. Consider cyber insurance

Besides technical measures, you may want to look into cyber insurance that covers this risk. It is not a quick way out of trouble: insurers usually expect your environment to be properly secured and audited before they offer cover. And not every attack is covered by every policy; some insurers exclude attacks they classify as acts of war, which can include state-sponsored attacks. As with any insurance, it is better to have it and never need it than to need it and not have it.

Frequently asked questions

Should you pay the ransom?

Authorities advise against it. The FBI does not support paying a ransom, because payment does not guarantee that you get your data back and encourages further attacks. Offline backups and a tested recovery plan are what make it possible to refuse.

What is the first thing to do after a ransomware attack?

Isolate affected systems from the network without wiping them, then report the incident and start your incident response plan. Evidence on the infected systems is needed to find out how the attackers got in.

Do you have to report a ransomware attack?

It depends on your sector and jurisdiction. In Germany, organizations covered by the NIS2 implementation act must send an initial report to the BSI within 24 hours, an update within 72 hours and a final report within one month. If personal data is affected, data protection notification duties under the GDPR may also apply.

How do you avoid being hit a second time?

Close the gap the attackers used, reset credentials, patch known exploited vulnerabilities, keep backups offline and tested, enforce MFA and train your users. A post-incident investigation tells you where to start.

Conclusion

If you are reading this because your company has been hit by ransomware: contain the attack, report it, carry out a post-incident and forensic assessment, educate your employees about the threat, and then improve your security posture step by step. Our earlier posts on preparing for a security breach and learning from one cover the groundwork.

ISEC7 helps you choose and implement EDR, XDR and mobile threat defense, integrated into your existing UEM landscape; learn more about our endpoint security services and trainings. If you have questions about improving your security posture, contact us.