What to do — and what not to do — when you discover ransomware.
Every action in the first hour affects whether you can recover, claim insurance, and satisfy POPIA. A skilled partner helps you make the best of a bad situation — starting with preserving evidence, not destroying it.
Six phases from containment to hardening — so you recover once, properly.
Isolate infected endpoints and servers. Stop active encryption, block lateral movement, and protect clean systems from spread.
Forensic imaging before remediation. See Digital Forensics for evidence collection that supports insurance and POPIA reporting.
Remove malware, close entry points, reset compromised credentials, and patch vulnerabilities the attacker exploited.
Restore from verified clean backups. Validate data integrity before reconnecting to production. Rebuild compromised systems from scratch where needed.
POPIA breach notification support, insurer documentation, and board-ready incident summary.
Post-incident review, IR plan update, and preventive controls — Managed Security and Cyber Awareness Training.
Windows and Linux file servers, domain controllers, and hypervisor-hosted workloads.
Exchange, OneDrive, SharePoint, and Teams data from backup or tenant recovery tools.
On-premise and cloud-hosted shared drives — the data most ransomware targets first.
Accounting, ERP, CRM, and industry-specific applications restored to a clean baseline.
Two paths — emergency response when you're under attack, or a retainer so you're ready before it happens.
P1 — respond now
Project engagement when ransomware is already affecting your business. AOLC logs confirmed incidents as P1 with immediate escalation to our security lead and 24/7 after-hours response through our Managed Security runbook.
Pre-signed — faster SLA
Reserved forensic and remediation hours with a guaranteed response SLA. Basic (10 hrs/year, 1 business day) or Standard (20 hrs/year, 4 business hours). Unused hours convert to proactive security work.
Ransomware is one of the most stressful events a business can face. Many of our clients tell us they felt alone and judged when it happened. AOLC's role is the opposite — experienced, calm, and focused on recovery.
We have supported South African law firms, schools, manufacturers, and professional services firms through active incidents. We coordinate with your insurer, legal counsel, and existing IT team. No blame — just a clear path back to operations, with the documentation POPIA and your board require.
Get Help Now
Direct answers to the questions that come up most often. Encoded as FAQPage structured data so AI search engines can quote them accurately.
Isolate affected systems from the network immediately — unplug Ethernet or disable Wi-Fi. Do not reboot or shut down unless instructed. Do not pay the ransom yet. Preserve firewall and cloud logs. Call AOLC on +27 87 55 00 555 and follow our POPIA Breach Playbook at aolc.tech/resources/popia-breach-playbook.html.
AOLC does not recommend paying as a first response. Over 60% of South African businesses that pay still do not recover all their data. We first attempt recovery from clean backups, assess whether decryption is viable, and coordinate with your insurer and legal counsel before any payment decision.
Often yes — if you have offline or immutable backups that were not encrypted. AOLC validates backup integrity, restores to clean infrastructure, and verifies data before reconnecting to production. Where backups are unavailable, we assess decryption options and coordinate with insurers.
Confirmed ransomware is logged as P1 with immediate escalation to AOLC's security lead and 24/7 after-hours response. Clients with an Incident Response Retainer receive a faster guaranteed SLA — 4 business hours for Standard, 1 business day for Basic.
Yes. AOLC documents scope of impact, supports your notification to the Information Regulator under POPIA section 22, and helps prepare communications to affected data subjects. See our POPIA Breach Playbook for the full process.
Emergency response is a project engagement scoped when an incident is already happening — we respond as fast as possible but contracts and scope are agreed under pressure. An IR Retainer is pre-signed with reserved hours and a guaranteed SLA, so response starts within hours instead of days.
Yes. AOLC regularly coordinates with internal IT teams, external MSPs, legal counsel, and cyber insurers. We can take the lead on containment and forensics while keeping your existing provider informed, or work entirely alongside them.
Active incident or planning ahead — tell us your situation and we'll respond urgently.