Part of our Cyber Information Series
This guide is designed to help you prepare for and mitigate the effects of a ransomware attack.
For more information on ransomware, plus protection and insurance strategies, read the full guide.
How to prepare for a ransomware incident?
Ransomware attacks can be devastating. Even if data can be recovered, it may take several weeks, during which time brand reputation may suffer and the financial impact could be shattering.
Here’s what to do to help you recover faster following an attack:
- Plan for an attack, even if you think it might never happen
- Develop an internal and external communication strategy to ensure the right information reaches the right people at the right time
- Work out how you will respond to the ransom demand, as well as the threat to your data being published
- Keep incident management processes in an accessible format so that they can still be utilised should you lose access to your systems
- Make sure you are aware of your legal obligations regarding incident reporting to regulators
How to mitigate the effects of a ransomware attack?
Take regular backups
Recent backups are the most effective way of recovering from a ransomware attack.
Make regular backups of your critical data, test them to ensure they work, and make sure you know how to restore them. Be sure to scan backups for malware before you restore them.
Offline backups kept in a separate location from your core network are essential, bearing in mind ransomware actively targets backups.
The best scenario is to make multiple backups using a variety of platforms and keeping them in different locations. Never leave any portable backup devices connected to your network, as attackers will target these as well.
There are known cases where ransomware attackers have destroyed file copies or disrupted backup recovery processes before they’ve made their attacks.
Prevent the spread of malware
There are various ways in which you can reduce the likelihood of ransomware reaching your devices and spreading across your network:
- Only allow approved file types to be opened on your system
- Use specialist software to block websites that are known to be malicious
- Use mail and spam filtering to block malicious emails and remove untrusted attachments
- Use internet security gateways to inspect content for known malware
- Use safe browsing lists within your web browsers to prevent access to websites known to host malicious content
Ransomware is frequently used by attackers who gain access to systems remotely via remote desktop access software (Remote Desktop Protocol or RDP) or remote access devices that haven’t been security patched.
Disabling RDP when not in use and completely if not required is advisable, as is enabling Multi-Factor Authentication (MFA) at remote access points.
Keeping up to date with security patches and software updates as soon as they become available is vital to prevent in-roads for attackers.
It is advisable to enlist the help of an IT professional with specialist experience in protecting against cyber-attacks. As well as helping you protect your systems with firewalls and other anti-malware solutions, many will also be able to offer a round-the-clock monitoring service to detect early signs of vulnerability and unusual activity.
Further reading
There is more detailed information on preventing the spread of malware in this National Cyber Security Centre guide which we strongly suggest you take time to read.

