Ransomware Response Checklist for UK SMEs - System Force IT

Ransomware Response Checklist for UK SMEs

Ransomware is the incident every business owner dreads, and the one where panic does the most damage. Files stop opening, a ransom note appears, and the instinct is to pull every plug at once. That instinct is understandable, and often wrong. This checklist gives you a calm, ordered way through the first hours and days of a ransomware attack.

It is a focused companion to our full cyber incident response plan guide. Print it, keep it with your offline incident plan, and work through it in order. The single most important idea to hold onto: the goal in the first hour is not to fix everything, it is to stop the spread and protect what is still clean, without destroying the evidence or your route to recovery.

The first 30 minutes

  • Stop and start an incident log with the current time. Every action from here gets a timestamp.
  • Isolate affected machines from the network by unplugging the cable or turning off Wi-Fi. Leave them powered on where you can, so evidence in memory survives.
  • Do not shut everything down indiscriminately. A blanket power-off can destroy useful evidence and complicate recovery.
  • Nominate one person to lead and get your IT provider or an incident-response specialist on the phone.
  • If your cyber insurance policy requires you to call their incident line first, do that before engaging anyone else.
  • Preserve the ransom note and any attacker messages. Photograph the screen. Do not delete anything.

Stop the spread

Ransomware wants to reach as many systems as possible. Your job is to contain it:

  • Segment the network to cut off affected areas from clean ones.
  • Identify which segments, servers and shares are affected, and which are not.
  • Protect your still-clean systems, so you do not lose them while you respond.
  • Check whether identity is compromised. If the attacker controls your Microsoft 365 or Active Directory, containment is much harder and you should get expert help immediately.
Protect your backups first. Modern ransomware operators deliberately go after backup infrastructure, because destroying your backups is how they force you to pay. Isolate and protect your backup systems as an early priority, and do not connect a backup device to an infected network.

Understand the scope

  • Which systems and data are encrypted?
  • Has data been stolen as well as encrypted? Most modern ransomware copies data out before encrypting it, then threatens to leak it. Look for signs of large data transfers.
  • Are your hypervisors or core servers affected?
  • Is your internet or VPN exposed in a way that let the attacker in?
  • How long had the attacker been in the network before triggering the encryption? This “dwell time” matters for recovery, as we explain below.

Reporting and outside help

  • Bring in external incident-response support for anything beyond a single machine.
  • Notify your cyber insurer, following your policy’s process.
  • Report a significant attack to the NCSC at ncsc.gov.uk/report.
  • Where a crime is involved, report to Report Fraud (the police service that replaced Action Fraud in December 2025).
  • If personal data has been stolen and there is a risk to individuals, assess your ICO obligations. Our data breach versus cyber incident guide explains when that applies.

Should you pay?

This is a serious decision with legal, financial and ethical dimensions, and it is not one to take alone or in a hurry. Paying does not guarantee you get working data back, may not stop stolen data being leaked, funds further crime, and can carry legal risk depending on who the attacker is. UK authorities and the NCSC discourage payment. Involve your insurer, a solicitor and specialist advisers, and consider law-enforcement input before any decision. Do not open direct communication with the attacker on instinct.

Recover safely, do not rush

The pressure to get everything working peaks exactly when giving in to it is most dangerous. Reconnect on top of an attacker you have not fully evicted and you hand them a second attempt.

A backup is not automatically clean just because it predates the visible encryption. Attackers often lurk for weeks before triggering the ransomware. A backup taken during that window may already contain their foothold. Validate the environment before you trust it, and rebuild rather than restore where you are unsure.

Before any system goes back on the network, it should pass the recovery gate: root cause understood, the vulnerability or gap remediated, compromised credentials invalidated, attacker persistence removed, the restore source confirmed clean, logging and endpoint protection in place, and a way to detect a recurrence. Reconnect in controlled stages under heightened monitoring, not all at once. For how long this realistically takes, see our guide on how long ransomware recovery actually takes.

Afterwards

Once you are stable, hold a no-blame post-incident review to find the conditions that let the attack succeed, and fix them. The free Cyber Incident Response Toolkit includes a post-incident review template, along with an incident log, evidence register and the full playbook pack.

Would your business survive a ransomware attack?

The businesses that recover fastest are the ones that prepared: isolated backups, tested restores, MFA on identity, and a plan people have rehearsed. We can review where you stand and give you a prioritised list.

Book a free IT and security review

Frequently asked questions

Should I turn all the computers off during a ransomware attack?

Isolating affected machines from the network to stop the spread is usually right. Powering everything down indiscriminately can destroy useful evidence held in memory and complicate recovery. The priority is to stop the spread and protect clean systems and your backups. For anything beyond a single machine, get experienced help before making sweeping changes.

Can I just restore from backup and be done?

Not safely, on its own. A backup that predates the visible encryption is not automatically clean, because attackers often dwell in a network for weeks first. You need to understand the root cause, remove the attacker’s access, validate the backup, and only then restore, ideally through a controlled recovery gate. Otherwise you risk reinfecting yourself.

Do I have to report a ransomware attack?

You should report a significant attack to the NCSC, and to Report Fraud where a crime is involved. If personal data was stolen and there is a risk to the people affected, you may also have a duty to notify the ICO within 72 hours of becoming aware. Regulated sectors may have their own rules. Reporting to one body does not satisfy your duty to another.

Should we pay the ransom?

It is a serious decision that should never be taken alone or quickly. Paying does not guarantee recovery, may not stop stolen data being leaked, funds crime, and can carry legal risk. UK authorities and the NCSC discourage it. Involve your insurer, a solicitor and specialists, and consider law-enforcement input first.

Related reading: the full Cyber Incident Response Plan guide, how long ransomware recovery takes, and the free Cyber Incident Response Toolkit.

Practical guidance, not legal advice. Regulatory references were checked against current UK sources on 26 August 2026. From System Force IT, UKAS ISO/IEC 27001:2022 certified, supporting UK businesses since 2006.

Stay one step ahead of the threats

Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.

Get the free weekly briefing →

Table of Contents

Would you like to know how we can help?

Get in touch

Name