Keep supported software maintained
Use official updates and check the active security product. Be cautious with unexpected attachments and remote-access requests. No security application guarantees that every ransomware attempt will be stopped.
Make backups independent
Keep recoverable copies protected from ordinary account or device access where practical. Sync can propagate harmful changes, and an always-connected writable backup can also be affected. Test a restore instead of trusting a completed status alone.
If files appear to be encrypting
Isolate affected network connections and seek suitable incident advice from a trusted device. Isolation may limit spread but does not necessarily stop encryption already running. Do not attach backup drives to the suspected system.
Plan recovery carefully
Preserve useful evidence and check account exposure before rebuilding and restoring. Payment does not guarantee recovery. Business or sensitive data may require a wider response than a home cleanup, following current incident guidance.
Questions about this guide
Should my only backup stay connected to the computer all the time?
Consider how the backup is protected if the computer is compromised. Keep a recoverable copy with access or disconnection arrangements that prevent one incident from reaching every copy.
What should I do if files suddenly show ransom messages?
Disconnect affected devices from shared connections when safe, preserve the messages and seek appropriate incident advice. Do not start deleting or reinstalling before considering the recovery and evidence needs.