Ransomware: the first 10 minutes
A checklist with a timer so you know what to do, in order, when a ransom note appears on screen. Tick each step as you go.
- 2 minutes
- No sign-up
- Instant result
0–2 min: stop the spread
2–5 min: protect backups and accounts
5–8 min: preserve evidence and raise the alarm
8–10 min: organise the response
What NOT to do
- Pay the ransom before consulting a specialist and your insurer: it does not guarantee you get files back.
- Delete files, logs or the ransom note.
- Restore from backup before confirming the attacker is out of the network: you will be encrypted again.
- Inform customers or the public before you agree what you actually know.
Need help right now?
If your business already has a problem, talk to us. You can also report to the Hellenic Police Cyber Crime Division.
This list is general and does not replace an incident response plan or legal advice. Deadlines and duties depend on the law and your contract. Your progress is not stored anywhere.
Want us to look at it together?
Leave your details and we will get in touch about the result and the next steps.
The checklist runs in your browser, stores nothing and is general: it does not replace an incident response plan.
What it checks
A timed checklist for the first steps in a ransomware incident: isolation, preserving evidence, notifications and what not to do.
How to read the result
Order matters. Network isolation comes before investigation, and wiping or rebooting machines can destroy evidence.
What to do next
The list is general. If an incident is happening now, contact us immediately.