Ransomware is more than encrypted files
Modern ransomware incidents may involve stolen credentials, remote access tools, lateral movement, data theft, encryption, extortion emails and public leak threats. Restoring from backup may be only one part of the answer. You also need to understand how the intrusion began, whether data left the environment and whether the attacker still has access.
Immediate priorities
- Preserve the scene
Photograph ransom notes, record error messages and keep copies of suspicious emails, alerts and logs. - Contain safely
Disconnect affected systems where appropriate, but avoid mass wiping or reinstalling before key evidence is captured. - Map impact
List affected servers, endpoints, accounts, shared drives, backups, cloud systems and business processes. - Plan recovery
Validate backups, identify clean restore points and prioritise essential operations.
Evidence that can answer key questions
- Endpoint alerts, VPN and remote desktop logs.
- Firewall, email, identity provider and cloud audit logs.
- Backup job history and failed login records.
- Ransom notes, attacker emails and leak site references.
- Timeline of first symptoms, discovery and actions taken.
Why specialist triage matters
A rushed restore can bring the attacker back in. A careful forensic brief helps separate recovery, containment, insurance, legal, privacy and communications work so decisions are made with better facts.
Avoid contacting attackers, paying demands or publishing details without appropriate legal, insurance and incident-response advice.
Related help
Evidence checklist
A practical list of what to preserve before logs, screenshots or account records disappear.
Request specialist consultation
Send the facts you have and we will help organise the next steps.
Australian cyber resources
Helpful public resources for cyber, privacy, scams and online safety.