Your files are encrypted and someone wants payment: what a small business should (and shouldn't) do

Your files are locked by ransomware, there's a ransom note on the screen, and staff can't work. Here's the order to act in, and the mistakes that make it worse.

Last reviewed: 21 July 2026

First: isolate the affected machines

Ransomware spreads across a network. Your first job is to stop it reaching more machines and your backups.

  1. Unplug the network cable and turn off Wi-Fi on any affected machine. Disconnect it from the network, but don't shut it down (shutting down can destroy evidence and, on some variants, files still mid-process).
  2. Disconnect shared drives, NAS units and USB backups from everything. Ransomware actively hunts connected backups to encrypt them too.
  3. Isolate, don't wipe. You want the affected machines off the network but intact for now.

If you've more than a couple of machines or a server and you're not certain you've contained it, pulling the internet connection for the whole site while you assess is a reasonable move.

Don't rush to pay

The note will push urgency: a countdown, a rising price. Slow down.

  • Paying doesn't guarantee a working key. A meaningful share of victims who pay never get their files back, or get a broken decryptor.
  • It marks you as a payer. Businesses that pay are disproportionately targeted again.
  • It funds the next attack and, depending on who's behind it, can carry legal or sanctions risk.

The ACSC's standard guidance is not to pay. Paying is a last-resort business decision made with professional and legal advice, not the first move under pressure.

Work out what's actually been hit

Before you restore, get a picture of the damage:

  • Which machines show the ransom note or encrypted (renamed) files?
  • What did those machines have access to: shared drives, the server, cloud-sync folders?
  • Was any data copied out before it was encrypted? Modern ransomware often steals data first and threatens to publish it. That can make it a notifiable data breach with legal obligations (the OAIC Notifiable Data Breaches scheme).

Restore from a clean, offline backup

This is what offline backups are for. If you don't have one yet, our guides to a backup that ransomware can't touch and small business backup cover setting one up.

  1. Don't restore onto a still-infected machine. Rebuild or reimage the machine first, or restore to known-clean hardware.
  2. Restore from a backup that was offline or disconnected when the attack hit. An always-connected backup may be encrypted too.
  3. Verify the backup is clean before you reconnect anything to the network.
  4. Change passwords (email, admin, remote access) from a clean device once you're back up, and assume credentials were captured.

Report it

What NOT to do

  • Don't reconnect a still-infected machine to the network "just to grab a file": that's how it re-spreads.
  • Don't wipe or reformat everything immediately if you may need to understand the breach or meet reporting obligations. Isolate first, then decide.
  • Don't pay before getting advice.
  • Don't assume it's over once files are restored. How did they get in: an unpatched remote-access port, a phished password, a dodgy download? If you don't close the door, it happens again.

When to get professional help

If it's on a server, has spread past one machine, involves stolen customer data, or you don't have a backup you trust, bring in professional incident response rather than experimenting. The cost of a wrong move (paying and getting nothing, wiping evidence, re-infecting) is usually far higher than the callout.

The short version: isolate affected machines immediately (unplug network and Wi-Fi, disconnect backups), don't rush to pay, work out what's hit and whether data was stolen, restore from a clean offline backup onto a reimaged machine, change passwords, and report via ReportCyber. Close the entry point before you reconnect, and get professional help if it's past one machine or customer data is involved.

General guidance, not incident-specific advice. safe2recover doesn't negotiate ransoms or decrypt files; for an active incident, isolate first and report via ReportCyber. A clean, offline backup is what actually gets you back, and it's the kind of thing worth having in place before you ever need it. If money has moved, contact your bank first.