Ransomware can shut your business down within minutes. What you do in the first hour, starting with disconnecting affected devices and calling your IT provider, determines whether you recover quickly or lose everything.
You arrive at the office and turn on your computer. Instead of your desktop you see a message telling you your files have been encrypted and demanding payment in cryptocurrency to get them back. Or maybe a staff member calls you in a panic because every file on the shared drive has been renamed to something unreadable. This is ransomware and it is one of the most damaging things that can happen to a small business.
What you do in the next sixty minutes will determine whether this is a bad day or a catastrophe. Here is the step by step.
Step one: disconnect everything immediately
The moment you suspect ransomware, disconnect the affected device from your network. Pull out the ethernet cable and turn off Wi-Fi. Do not shut the computer down. Do not restart it. Just disconnect it from the network.
Ransomware spreads across networks. If one computer is infected and it is connected to your shared drives, your server or other devices on the same network, the encryption will spread to those too. Every second it stays connected is another second it has to encrypt more files on more machines.
If you are not sure which device was hit first, disconnect everything from the network as a precaution. It is better to have ten minutes of downtime while you figure out the scope than to let the ransomware encrypt your entire business.
Step two: do not pay the ransom
This is important. Do not pay. There is no guarantee you will get your files back. Many businesses that pay never receive a working decryption key. Even if you do get one, the attackers now know you are willing to pay and may target you again. And paying funds criminal operations that will go on to attack other businesses.
The South African Police Service and international law enforcement agencies all advise against paying ransoms. Focus your energy on containment and recovery instead.
Step three: contact your IT provider
If you have a managed IT provider, call them immediately. Do not email, do not submit a ticket, pick up the phone. This is an emergency and it needs to be treated as one.
Your IT provider can assess the scope of the attack, identify which systems and files have been affected, determine how the attacker got in and begin the recovery process. If you do not have an IT provider, you will need to find a cybersecurity incident response specialist urgently. This is not something to attempt on your own.
Step four: identify what has been affected
While your IT provider works on containment, start documenting what you know. Which devices are showing signs of encryption? Which staff members reported problems and when? What shared drives or cloud services were accessible from the affected devices? Were any backup drives connected at the time?
This information helps your IT provider understand the blast radius and prioritise recovery. It is also important for any legal reporting you may need to do later.
Step five: check your backups
This is where the difference between businesses that recover and businesses that do not becomes clear. If you have a proper backup strategy with offsite or cloud backups that were not connected to the infected network, your data can be restored. The ransomware becomes an inconvenience rather than a disaster.
If your backups were on a drive connected to the same network, there is a chance they have been encrypted too. If your backups have not been tested, there is a chance they will not restore cleanly. If you have no backups at all, your options become very limited.
This is why we stress backup strategy so heavily. A backup that is tested, stored offsite and isolated from your main network is the single most effective defence against ransomware. Not because it prevents the attack, but because it makes the attack survivable.
Step six: report the incident
Under POPIA, if personal information may have been compromised you are legally required to notify the Information Regulator and the affected individuals. Modern ransomware operations almost always steal data before encrypting it so even if you recover your files from backup, the attacker may still have a copy of your client data, employee records or financial information.
Your IT provider can help you assess whether data was exfiltrated and what your reporting obligations are. Do not skip this step. The penalties for failing to report a breach under POPIA can be severe and the reputational damage of a cover up is worse than the breach itself.
You should also report the attack to the South African Police Service. While the chances of catching the attackers are slim, reporting helps law enforcement track ransomware trends and may assist with insurance claims.
Step seven: recover and rebuild
Once the attack is contained and the entry point is identified, recovery can begin. If you have clean backups this means restoring your data and rebuilding any affected systems. Your IT provider will also close the vulnerability that the attacker used to get in, whether that was a phishing email, an unpatched system, a compromised password or an exposed remote access point.
Recovery time depends on the scope of the attack and the quality of your backups. A business with daily cloud backups and a clear recovery plan can be back up and running within hours. A business with no backups or untested backups may face days or weeks of disruption and some data may be permanently lost.
How ransomware gets in
Understanding how ransomware enters your business helps you prevent it from happening again. The most common entry points are phishing emails with malicious attachments or links, compromised credentials from a previous data breach, unpatched software with known vulnerabilities and poorly secured remote access.
Multi-factor authentication blocks the majority of credential-based attacks. Endpoint protection with EDR capabilities catches ransomware behaviour before encryption completes. Email security filtering stops most phishing emails before they reach your staff. And regular patching closes the vulnerabilities that attackers scan for. If you are not sure how strong your current passwords are, our guide on how to create a strong password covers the fundamentals.
The bottom line
Ransomware is not a question of if but when. Every business that uses email and the internet is a potential target. The businesses that survive it are the ones that prepared for it, with proper backups, tested recovery plans and security measures that limit the damage.
If your business does not have a tested backup and recovery plan, if you are not sure your backups are isolated from your network, or if you have never had a conversation about what would happen if ransomware hit tomorrow, now is the time. At Recloud we help Cape Town businesses put the right protections in place and build recovery plans that actually work when they are needed. Get in touch before you need us urgently.