After a ransomware attack, stop it from spreading before trying to restore files. Isolate affected devices, preserve useful evidence, bring in the right responders, remove the attacker’s access, then restore priority services from backups you have verified are clean. Avoid broad cleanup or reconnecting systems until responders are confident the recovery environment is safe.
What to do first: contain the attack
Follow your organization’s incident response plan if you have one. CISA’s #StopRansomware Guide, revised October 19, 2023, puts immediate isolation first: “Determine which systems were impacted, and immediately isolate them.”
If you are an individual or have only one affected device
- Disconnect the device from Ethernet and Wi-Fi. If you cannot disable Wi-Fi through the device’s controls, disconnect it from the network another way, such as turning off the router’s wireless connection if you can do so safely.
- Do not connect backup drives or other storage to the affected device. A ransomware program may be able to reach storage that is still accessible.
- If files are actively changing or the device is part of a work or school network, contact the organization’s IT or security team promptly.
Turning the computer off is not the default first step. Isolation stops network communication while leaving the system available for responders to assess; shutting it down can change or lose volatile information. If you cannot isolate it, or there is an immediate safety risk, seek incident-specific guidance from your IT team or a qualified responder.
If several devices or network segments may be affected
Have IT or security staff identify affected systems and isolate them immediately. If the incident appears to span multiple systems or subnets, responders may need to take the network offline at the switch level. Prioritize isolating critical systems, including those whose continued operation could put people or essential services at risk.
#1 Best Overall
- Easily store and access 2TB to content on the go with the Seagate Portable Drive, a USB external hard drive
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
How to triage and preserve evidence
Identify what is affected and what must keep running
Build an initial list of affected systems, accounts, and services, and note systems not believed to be affected. Identify dependencies for health and safety, revenue, and other critical services so recovery can be prioritized. Review endpoint and network security products and logs for additional compromised systems or signs of an earlier intrusion; ransomware can follow an unresolved compromise.
Preserve evidence before destructive cleanup
Where feasible, work with qualified responders to collect system images and memory captures from representative affected devices, relevant logs, and malware samples or indicators. Memory and logs may be lost, overwritten, or altered, so evidence with limited retention may need prompt attention. Coordinate cleanup with responders rather than wiping or rebuilding systems first; premature changes can destroy information needed to understand how the attacker got in and whether access remains.
Rank #2
- Easily store and access 5TB of content on the go with the Seagate portable drive, a USB external hard Drive
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
Who to notify and how to coordinate
Use the incident response and communications plans to coordinate decisions and keep a record of actions taken. For a U.S. incident, CISA identifies these reporting or assistance routes:
- CISA
- A local FBI field office
- FBI Internet Crime Complaint Center (IC3)
- A local U.S. Secret Service field office
Notify management, IT and security teams, managed service providers, insurers, and other relevant stakeholders as appropriate. If personal or other protected data may have been exposed, involve qualified counsel and follow the breach-notification requirements that apply to your organization, sector, and location. A ransomware event may involve data theft and extortion as well as file encryption, so do not assume that recovering encrypted files resolves every part of the incident.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Rank #3
- Easily store and access 1TB to content on the go with the Seagate Portable Drive, a USB external hard drive.Specific uses: Personal
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop. Reformatting may be required for Mac
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
How to remove the attacker’s access
Do not assume the visible encrypted computers are the only systems involved. Work with incident responders to identify systems and accounts used for initial access, including email accounts, and investigate remote access routes that may still be available to the attacker. CISA calls out VPNs, remote access servers, single sign-on resources, and public-facing assets as possible containment considerations.
Consider credentials and remote access pathways potentially compromised. Plan account and access changes with responders so you do not inadvertently disrupt evidence collection or leave another route open. Use trusted guidance specific to the ransomware variant, along with qualified response help where needed, before declaring the environment clean.
Rank #4
- Easily store and access 4TB of content on the go with the Seagate Portable Drive, a USB external hard drive.Specific uses: Personal
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
How to restore files and services without reinfection
Choose a clean source and restore in priority order
Restore data from offline, encrypted backups, following the priority order established during triage. Before systems rejoin the recovery network, verify that they are clean; reconnecting a compromised system or restoring into an unsafe environment can lead to reinfection. Use regularly updated golden images to rebuild critical systems where available.
Check backup integrity and plan for gaps
Do not treat the existence of a backup as proof that it is usable or uncompromised. CISA recommends regularly testing backup availability and integrity in a disaster recovery scenario. Ransomware may seek out backups that remain accessible and delete or encrypt them, which is why isolation matters as well as testing.
Recommended Free Tools
Best Value
- [Upgraded Version] - This external hard drive features a mirrored logo stripe combined with a striped anti-slip design, and the rounded corners of the casing make it easier to grip. The stripes also have a heat dissipation function, ensuring stable and fast data transfer.
- 【Ultra-thin and quiet】 - The motherboard adopts JMicron 578 noise-free solution, giving you a quiet working environment. Lightweight and portable size designed to fit in your pocket for easy portability.
- 【Ultra-Fast Data Transfers】 - Pairing this external hard drive with JMicron 578 solution USB 3.0 and USB 2.0 interfaces enables blazing-fast data transfer. It boasts theoretical read speeds of up to 125MB/s and write speeds of up to 103MB/s.
- 【Plug and Play】 - With no software to install, just plug it in and the drive is ready to use.The hard disk chip is wrapped with an aluminum anti-interference layer to increase heat dissipation and protect data.
- 【What You Get】 - 1 x Portable Hard Drive, 1 x USB 3.0 Cable, 1 x User Manual, Gift-type shell packaging ,Three-year manufacturer's warranty and free technical support services.
A disconnected, encrypted external drive can hold one offline backup copy, particularly for an individual or small organization. Match its capacity and encryption to the data and systems being backed up, keep it disconnected except during backup, and test whether data can actually be restored. One drive is not, by itself, a complete resilience plan for critical business systems; those systems need a broader design with isolated copies and recovery procedures.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Can you recover without paying, and might a decryptor work?
Possibly, but neither outcome can be guaranteed. CISA advises consulting federal law enforcement about possible decryptors: researchers have released tools for some ransomware variants, but availability and effectiveness depend on the specific variant and infection. Do not assume a tool exists or that it will work on your files.
The general CISA guide does not settle whether a victim should pay or provide a complete legal analysis for every jurisdiction. Before making a payment decision, involve qualified incident responders, counsel, your insurer, and law enforcement. The right advice depends on the incident and the laws and obligations that apply to you.
What to review after recovery
Document what happened, what was restored, and the lessons learned. Update incident response and communications plans, backup and recovery procedures, and other policies where the incident exposed gaps. Consider sharing relevant lessons or indicators with CISA or a sector information-sharing group.
Free tools Windows power users keep installed
One-click scans. No signup required.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

