Skip to content
Back to WikiIncident Types

What to do after a ransomware attack

Isolate affected hosts from the network immediately, but do not power them off or reboot them. Volatile memory may hold decryption keys, the ransomware binary, and forensic evidence. Engage your incident response lead, or call SecDesk on 088 SECDESK (7323375), within the hour. Do not pay the ransom until a senior responder has checked nomoreransom.org for a free decryptor, confirmed whether data has already been exfiltrated, and reviewed the decision with legal counsel. Notify the Autoriteit Persoonsgegevens within 72 hours if personal data was affected, and file aangifte with politie cybercrime through the national portal. The first 24 hours drive the cost and duration of recovery more than any other factor.

The first hour

Isolate every system showing signs of encryption from the wired and wireless network. Keep them running. Volatile memory on an encrypted workstation can hold fragments of the ransomware binary, decryption keys in process memory, or network indicators that point to the attacker group. Pulling the power destroys that evidence.

Call your incident response provider before contacting the attacker through the ransom note. Attackers watch victim communications and raise demands when organisations look disorganised. SecDesk answers the incident line and has a [senior responder on the call within two hours](/phishing-incident-response).

What not to do

Do not reboot or reimage affected systems before forensic snapshots are taken. Do not delete the ransom note, ransomware binary, or related artefacts. Do not restore from backups onto the same network segment the attackers still have access to, because the restored systems will be re-encrypted within hours. Do not negotiate or pay without legal, forensic, and law-enforcement input, because payment funds criminal infrastructure and does not guarantee recovery.

Reporting obligations

If personal data was encrypted, altered, or exfiltrated, a ransomware incident is a personal data breach under the AVG (GDPR) and must be notified to the Autoriteit Persoonsgegevens (AP) within 72 hours under article 33. If the affected data creates a high risk to the people involved, those individuals must also be informed directly in clear language under article 34.

File aangifte with politie cybercrime via the national portal. If your organisation is in scope of NIS2 (in the Netherlands: the Cyberbeveiligingswet, Cbw) as an essential or important entity, notify the relevant sector supervisor and NCSC-NL: 24-hour early warning, 72-hour incident notification, one-month final report. Reporting does not obligate payment and does not expose your organisation to reputational damage: reports are treated confidentially during active investigation.

Recovery decisions

Recovery starts with backup integrity. Confirm that offline or immutable backups exist, that they are recent enough to be useful, and that the backup infrastructure itself was not compromised. Modern ransomware groups target backups first, then encrypt production data, which is why offline or air-gapped copies matter more than any other control. Before restoring, verify backups are clean, test restoration in an isolated segment, and watch for re-infection signals on restored hosts.

Check nomoreransom.org for a free decryptor tied to the specific ransomware family and version (LockBit, Cl0p, Play, Akira, and many others have partial or full decryptors published through law-enforcement cooperation). Decide on payment only after forensic scope is clear, legal counsel has reviewed the decision, and sanctions exposure has been checked against the suspected threat actor. If data was exfiltrated, payment does not remove the pressure: copies remain with the attacker regardless of whether the decryption key is delivered. The Dutch government does not prohibit payment but strongly advises against it.

Preventing reinfection

Rebuilding onto a compromised network guarantees a second incident. Before restoring, rotate every credential, revoke every session, patch every known vulnerability, and close the initial access path confirmed by forensic review. Most ransomware groups keep persistence mechanisms on at least one system they have not yet encrypted, which is how reinfections within weeks happen. A full [threat exposure management](/threat-exposure-management) review after recovery closes the external attack surface gaps that made the initial access possible.

Discuss this with a senior responder.

Discuss this with a senior responder
Incident response

Need incident response?

088 SECDESK (7323375)

Call us. A senior responder picks up.

  • Two-hour SLA
  • Dutch senior responders

Emergency form

Two-hour response.

Is this urgent? Call us.

088 SECDESK (7323375)

Cannot wait? Call 088 SECDESK (7323375) now

Emergency line088 SECDESK
Call now