Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Isolate affected systems, activate your incident-response plan, preserve evidence, and bring in qualified help. Avoid rushing to shut down devices, wipe systems, or restore backups: those actions can affect evidence or allow the intrusion to spread. Work through containment and recovery with your security team or incident responders, and coordinate reporting with legal counsel and other relevant stakeholders.
What to do first after a ransomware attack
Use the sequence below as an emergency framework, not a substitute for your organization’s incident-response plan. CISA’s September 2023 #StopRansomware Guide advises organizations to follow their approved incident-response plan. Assign someone to coordinate decisions and keep a record of actions and times.
-
Activate the response plan and coordinate people
Notify internal leadership and the people responsible for security, IT, legal, communications, and business operations. Contact your cyber insurer if your policy or response plan calls for it. If attackers may be monitoring company systems, use an out-of-band channel—one not dependent on the potentially compromised environment—to coordinate sensitive response work.
-
Contain the incident without destroying evidence
Identify which devices, systems, and network segments appear affected, then isolate affected systems promptly when it is safe to do so. Disconnect affected devices from wired or wireless networks. If multiple systems or segments may be compromised, CISA says taking the network offline at the switch level may be necessary; coordinate a network-wide action rather than improvising changes that could disrupt containment.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.#1 Best Overall
SaleWD 2TB My Passport, Portable External Hard Drive, Black, backup software with defense against ransomware, and password protection, USB 3.1/USB 3.0 compatible - WDBYVG0020BBK-WESN- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
For affected cloud resources, take volume snapshots for later investigation where appropriate. Avoid powering down devices if network disconnection can contain them: shutdown can destroy volatile-memory evidence. CISA describes shutdown as a fallback when network disconnection is not possible.
-
Preserve evidence and involve qualified responders
When feasible, preserve system images, memory captures, relevant logs, malware samples, and indicators of compromise. Give priority to volatile information and logs that may be retained only briefly. Coordinate collection with incident responders and law enforcement; avoid altering affected systems just to collect details for a report.
Rank #2
WD 4TB My Passport, Portable External Hard Drive, Black, Backup Software with Defense Against ransomware, and Password Protection, USB 3.1/USB 3.0 Compatible - WDBPKJ0040BBK-WESN- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
Ask law enforcement or qualified responders whether a decryptor may be available for the specific ransomware variant. Some variants may have decryptors, but their availability for a particular incident is not guaranteed.
-
Report the incident and coordinate required notices
For a U.S. incident, CISA’s guide identifies CISA, a local FBI field office, and the FBI’s Internet Crime Complaint Center (IC3) as reporting or assistance routes. The FBI also directs ransomware victims to IC3. Preserve original attacker messages and other evidence where feasible.
Recommended Free Tools
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.Rank #3
SaleWD 5TB My Passport, Portable External Hard Drive, Black, backup software with defense against ransomware, and password protection, USB 3.1/USB 3.0 compatible - WDBPKJ0050BBK-WESN- Slim durable design to help take your important files with you
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
Notify customers, regulators, business partners, or other parties according to the organization’s applicable legal and contractual duties and communications plan. There is no single notification deadline in the cited guidance that applies to every business. Duties depend on such factors as location, sector, affected data, and contracts; consult counsel promptly to determine which rules apply. Keep external updates accurate and coordinated.
When filing an IC3 complaint, provide whatever is available: the ransomware variant, encrypted-file extension, cryptocurrency type and address, attacker email address and websites or URLs, demand amount, and whether a payment was made and its amount.
Rank #4
SaleWD 6TB My Passport, Portable External Hard Drive, Black, Backup Software with Defense Against ransomware, and Password Protection, USB 3.1/USB 3.0 Compatible - WDBR9S0060BBK-WESN- World’s First 6TB 2.5” Portable Hard Drive
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
-
Restore only after containment, in a clean environment
Prioritize critical services and confirm the compromise is contained before bringing systems back online. Restore from offline, encrypted backups in an environment that is not itself compromised. Do not reconnect potentially compromised devices or introduce them into the recovery network. CISA recommends testing backup availability and integrity regularly before an incident and documenting lessons after one.
Should your business pay the ransom?
The FBI says, “The FBI does not support paying a ransom in response to a ransomware attack.” A payment does not establish that the business will get working systems back or that stolen data will be deleted. Before making any decision, involve leadership, qualified incident responders, legal counsel, and the insurer where applicable; consult law enforcement about recovery options and possible decryptors. Whether a particular payment is lawful, or permitted by sanctions or an insurance policy, depends on facts and restrictions that require case-specific advice.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsBest Value
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
How to choose outside incident-response help
If your in-house team cannot contain the incident and investigate it, compare providers against the needs of the affected environment and your organization. Ask about:
- Ability to contain the affected environment, including relevant cloud and network systems.
- Forensic scope and evidence-handling procedures, including preservation of logs and volatile information where feasible.
- Time to mobilize and the provider’s geographic and sector coverage.
- How the provider coordinates with legal counsel, insurers, law enforcement, and internal teams.
- Whether the engagement includes recovery support as well as investigation, and what the service terms cover.
Do not assume that every firm offering cybersecurity services has the right incident-response capacity for your situation. Clarify scope, availability, and coordination responsibilities before authorizing work where circumstances allow.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

