What to Do After a Ransomware Attack: An SME Response Guide
What to Do After a Ransomware Attack: An SME Response Guide A ransomware incident rarely begins with a dramatic message appearing on every screen. The first warning may be a user unable to open a document, a shared folder containing strangely renamed files or a computer suddenly running unusual processes. What happens during the next […]
What to Do After a Ransomware Attack: An SME Response Guide
A ransomware incident rarely begins with a dramatic message appearing on every screen. The first warning may be a user unable to open a document, a shared folder containing strangely renamed files or a computer suddenly running unusual processes.
What happens during the next hour can determine whether the incident affects one computer or spreads across the business.
South African SMEs should have a simple ransomware response plan that employees and decision-makers can follow without improvising under pressure.
1. Isolate affected devices
Disconnect a suspected computer from wired and wireless networks as quickly as possible. Remove its network cable or disable Wi-Fi, but do not immediately erase, reset or reinstall it.
If several devices show similar symptoms, disconnect affected network segments and shared storage where practical. The objective is to limit further encryption, data theft and movement between computers.
Do not continue opening files to test whether they work. Every additional action may spread damage or overwrite useful evidence.
2. Contact your IT and security provider
Treat the event as a security incident rather than an ordinary computer fault.
Your provider needs to determine:
- Which users and devices are affected
- Whether administrator credentials may be compromised
- Whether files are still being encrypted
- Whether Microsoft 365 or other cloud accounts were accessed
- Whether data may have been stolen
- Whether backups remain safe
- How the attacker gained access
Modern ransomware incidents may include data theft before encryption. Restoring files alone does not establish that the threat has been removed.
3. Protect identities and administrative access
If account compromise is suspected, passwords and sessions may need to be reset from a known-clean device. Administrative accounts, remote-access tools, VPN credentials and Microsoft 365 access should receive priority.
Simply changing one employee’s password may be insufficient. Attackers sometimes create forwarding rules, add authentication methods or establish alternative accounts that allow them to return.
Security changes should be coordinated carefully so the response team does not accidentally lose access to essential evidence or recovery systems.
4. Preserve evidence
Keep affected devices, ransom notes, suspicious emails, timestamps and security logs. Take photographs or screenshots where appropriate, but do not interact unnecessarily with malicious files.
Evidence can help establish the entry point, scope of the incident and whether personal information was affected. This may also be important for cyber-insurance claims, regulatory obligations and law-enforcement reporting.
Where personal information may have been compromised, the business should obtain appropriate POPIA and legal guidance regarding notification requirements.
5. Verify backups before restoring
Do not reconnect backup drives or begin restoring data until the environment has been assessed.
A backup connected too early could also be encrypted or contaminated. The recovery team should confirm that the backup predates the attack, remains isolated and can be restored into a clean environment.
Recovery should follow business priorities. Email, accounting, customer records and operational systems may need to be restored in a planned sequence.
Should a business pay the ransom?
Paying does not guarantee that criminals will provide a working decryption key, delete stolen information or avoid attacking again. Payment may also create legal, ethical and insurance complications.
This decision should not be made impulsively. Obtain specialist incident-response, legal and insurance advice based on the exact circumstances.
Prepare before the attack
The best time to decide who disconnects systems, contacts the insurer and authorises recovery is before ransomware is discovered.
RandTech IT helps SMEs implement managed endpoint protection, Microsoft 365 security, independent backups and tested incident-response procedures.
If you suspect ransomware, stop using the affected device, disconnect it from the network and contact professional support immediately. Fast containment is far less expensive than allowing a single compromised computer to become a business-wide outage.
Source: CISA StopRansomware Guide


