If ransomware is suspected, the first priority is containment—not trying random fixes. Disconnect affected systems from networks, protect backups, preserve evidence, notify the people responsible for IT and incident response, and avoid deleting logs or reinstalling devices until the scope is understood.
Immediate Steps
- Disconnect affected computers or servers from Wi-Fi, LAN, VPN, shared drives, and remote access where practical.
- Do not erase or reformat compromised devices before evidence is preserved.
- Protect backup systems from being reached by infected accounts or machines.
- Disable or reset compromised administrator and remote-access credentials.
- Record what happened, when it was noticed, which devices are affected, and what messages appeared.
- Escalate to your IT, security, management, legal, privacy, and insurance contacts as applicable.
Do Not Assume the Attack Is Only Encryption
Modern ransomware incidents can involve data theft before files are encrypted. That means the response should consider whether personal information, credentials, customer files, employee records, financial data, or confidential business information may have been accessed or copied.
Protect Backups
Do not reconnect backup drives or repositories to infected systems. Check whether attackers had access to backup accounts and whether backup copies predate the compromise. Restore only after the affected environment has been investigated and secured, otherwise the restored system can be compromised again.
Preserve Evidence
Keep ransom notes, screenshots, suspicious emails, timestamps, login records, firewall logs, endpoint alerts, account-change notices, wallet addresses, file extensions, and communications from the attacker. Evidence can help technical investigation, insurance review, legal assessment, and cybercrime reporting.
Reset Access Carefully
Reset passwords for accounts believed to be compromised, especially administrator, email, cloud, VPN, domain, backup, and remote-access accounts. Where possible, perform resets from a known-clean device and enable multi-factor authentication. Review active sessions and revoke suspicious tokens or logins.
Check for a Personal Data Breach
If personal data may have been accessed, copied, altered, destroyed, or exposed, the incident may also need to be assessed under Philippine data privacy rules. Use the Data Breach Response Checklist Philippines and the guide on when the National Privacy Commission must be notified.
Should You Pay the Ransom?
Payment does not guarantee that data will be restored, deleted, or kept confidential. It can also create legal, sanctions, insurance, and repeat-extortion risks depending on the attacker and circumstances. Do not treat payment as an ordinary procurement decision. Escalate it to qualified legal, security, management, and insurance advisers before any decision is made.
Where to Report
Reporting depends on the incident. Philippine cybercrime and cybersecurity channels may include the PNP Anti-Cybercrime Group, NBI cybercrime units, CICC, and relevant sector regulators. If personal data is involved, the National Privacy Commission may also be relevant. Use Cybercode’s Government Cybersecurity Agencies Directory.
Last materially reviewed: September 3, 2026
Direct Answer
If ransomware is detected, isolate affected systems, preserve evidence, disable compromised credentials, activate the incident-response team, and determine which systems and data are affected before restoring operations. Organizations should avoid rushing into recovery before the attacker’s access path is understood and contained.
Primary guidance: CISA StopRansomware Guide. If personal data may have been compromised, also see NPC Breach Reporting.
Key Takeaways
Isolate affected systems quickly. Limit spread before beginning recovery. Preserve evidence. Logs, ransom notes and indicators can help incident responders and investigators. Check backups before restoring. Confirm they are clean and that the original access path has been closed. Assess reporting duties. Personal-data exposure may create separate NPC obligations.
Frequently Asked Questions
Should a business immediately pay a ransomware demand?
Payment does not guarantee recovery and can create additional legal, financial and security risks. Organizations should involve qualified incident-response, legal and law-enforcement resources before making decisions.
Can ransomware also be a personal data breach?
Yes. If personal data was accessed, acquired, exfiltrated or otherwise compromised, the incident should be assessed separately under applicable Philippine data-breach rules.
Official Sources
CISA — StopRansomware Guide
National Privacy Commission — Breach Reporting
Decision Snapshot
| Situation | Immediate action |
| One computer shows ransom note | Disconnect it and check for spread |
| Shared drives are encrypting | Isolate affected network segments and accounts |
| Backups are accessible from infected systems | Protect or isolate backups immediately |
| Customer or employee data may be stolen | Start privacy-breach assessment |
| Attackers demand payment | Escalate before any payment decision |
After Containment
Identify the entry point, remove persistence, patch exploited weaknesses, restore from verified backups, rotate credentials, monitor for renewed access, and document lessons learned. Use the Cyber Incident Response Checklist for a broader response sequence.
