Ransomware Response Checklist for UK SMEs
Ransomware is the incident every business owner dreads, and the one where panic does the most damage. Files stop opening, a ransom note appears, and the instinct is to pull every plug at once. That instinct is understandable, and often wrong. This checklist gives you a calm, ordered way through the first hours and days of a ransomware attack.
It is a focused companion to our full cyber incident response plan guide. Print it, keep it with your offline incident plan, and work through it in order. The single most important idea to hold onto: the goal in the first hour is not to fix everything, it is to stop the spread and protect what is still clean, without destroying the evidence or your route to recovery.
The first 30 minutes
- Stop and start an incident log with the current time. Every action from here gets a timestamp.
- Isolate affected machines from the network by unplugging the cable or turning off Wi-Fi. Leave them powered on where you can, so evidence in memory survives.
- Do not shut everything down indiscriminately. A blanket power-off can destroy useful evidence and complicate recovery.
- Nominate one person to lead and get your IT provider or an incident-response specialist on the phone.
- If your cyber insurance policy requires you to call their incident line first, do that before engaging anyone else.
- Preserve the ransom note and any attacker messages. Photograph the screen. Do not delete anything.
Stop the spread
Ransomware wants to reach as many systems as possible. Your job is to contain it:
- Segment the network to cut off affected areas from clean ones.
- Identify which segments, servers and shares are affected, and which are not.
- Protect your still-clean systems, so you do not lose them while you respond.
- Check whether identity is compromised. If the attacker controls your Microsoft 365 or Active Directory, containment is much harder and you should get expert help immediately.
Understand the scope
- Which systems and data are encrypted?
- Has data been stolen as well as encrypted? Most modern ransomware copies data out before encrypting it, then threatens to leak it. Look for signs of large data transfers.
- Are your hypervisors or core servers affected?
- Is your internet or VPN exposed in a way that let the attacker in?
- How long had the attacker been in the network before triggering the encryption? This “dwell time” matters for recovery, as we explain below.
Reporting and outside help
- Bring in external incident-response support for anything beyond a single machine.
- Notify your cyber insurer, following your policy’s process.
- Report a significant attack to the NCSC at ncsc.gov.uk/report.
- Where a crime is involved, report to Report Fraud (the police service that replaced Action Fraud in December 2025).
- If personal data has been stolen and there is a risk to individuals, assess your ICO obligations. Our data breach versus cyber incident guide explains when that applies.
Should you pay?
This is a serious decision with legal, financial and ethical dimensions, and it is not one to take alone or in a hurry. Paying does not guarantee you get working data back, may not stop stolen data being leaked, funds further crime, and can carry legal risk depending on who the attacker is. UK authorities and the NCSC discourage payment. Involve your insurer, a solicitor and specialist advisers, and consider law-enforcement input before any decision. Do not open direct communication with the attacker on instinct.
Recover safely, do not rush
The pressure to get everything working peaks exactly when giving in to it is most dangerous. Reconnect on top of an attacker you have not fully evicted and you hand them a second attempt.
Before any system goes back on the network, it should pass the recovery gate: root cause understood, the vulnerability or gap remediated, compromised credentials invalidated, attacker persistence removed, the restore source confirmed clean, logging and endpoint protection in place, and a way to detect a recurrence. Reconnect in controlled stages under heightened monitoring, not all at once. For how long this realistically takes, see our guide on how long ransomware recovery actually takes.
Afterwards
Once you are stable, hold a no-blame post-incident review to find the conditions that let the attack succeed, and fix them. The free Cyber Incident Response Toolkit includes a post-incident review template, along with an incident log, evidence register and the full playbook pack.
Would your business survive a ransomware attack?
The businesses that recover fastest are the ones that prepared: isolated backups, tested restores, MFA on identity, and a plan people have rehearsed. We can review where you stand and give you a prioritised list.
Frequently asked questions
Isolating affected machines from the network to stop the spread is usually right. Powering everything down indiscriminately can destroy useful evidence held in memory and complicate recovery. The priority is to stop the spread and protect clean systems and your backups. For anything beyond a single machine, get experienced help before making sweeping changes.
Not safely, on its own. A backup that predates the visible encryption is not automatically clean, because attackers often dwell in a network for weeks first. You need to understand the root cause, remove the attacker’s access, validate the backup, and only then restore, ideally through a controlled recovery gate. Otherwise you risk reinfecting yourself.
You should report a significant attack to the NCSC, and to Report Fraud where a crime is involved. If personal data was stolen and there is a risk to the people affected, you may also have a duty to notify the ICO within 72 hours of becoming aware. Regulated sectors may have their own rules. Reporting to one body does not satisfy your duty to another.
It is a serious decision that should never be taken alone or quickly. Paying does not guarantee recovery, may not stop stolen data being leaked, funds crime, and can carry legal risk. UK authorities and the NCSC discourage it. Involve your insurer, a solicitor and specialists, and consider law-enforcement input first.
Related reading: the full Cyber Incident Response Plan guide, how long ransomware recovery takes, and the free Cyber Incident Response Toolkit.
Stay one step ahead of the threats
Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.
Get the free weekly briefing →


