How Should a Company Handle a Ransomware Attack?
If you run IT or security for a company of any size, ransomware isn't a hypothetical anymore. It's a Tuesday. The threat has matured past the smash and grab days: today's operators steal your data before they encrypt anything, then threaten to leak it whether or not you pay. That single shift, from "give us money and we'll unlock your files" to "give us money or we publish your contracts, payroll data, and customer records," changed the entire calculus for how a company should respond.
This isn't a theoretical problem confined to a handful of unlucky Fortune 500 firms. According to Sophos's 2025 State of Ransomware survey, 50 percent of organizations reported having data encrypted in a ransomware attack within the prior year. Mid-market companies, the 101 to 1,000 employee range, remain the single largest target band: Coveware by Veeam's Q2 2026 report puts that segment at 35.4 percent of all cases it handled, with organizations between 11 and 10,000 employees accounting for 75.8 percent combined. In other words, this is a mid-market problem as much as an enterprise one, and a lot of mid-market companies still don't have a written plan.
Here's what an incident actually looks like when it hits, and what a company should be doing at each stage.
What changed: this isn't your 2021 ransomware attack
The old model was simple encryption. You lost access to files, you restored from backup or paid for a decryption key, and that was roughly the extent of the damage. Attackers have moved on from that. The dominant pattern now, per Coveware's Q2 2026 data, is identity driven access rather than loud technical exploits: compromised credentials, MFA fatigue, help desk social engineering, and abused remote access tools. Cyber threats increasingly look like normal authentication, not an obvious break in, which is exactly why they're harder to catch early.
One case worth knowing about: a group called Silent Ransom (also tracked as Luna Moth) spent much of Q2 2026 running a campaign against law firms using voice phishing calls, posing as internal IT support, and in some cases physically walking into offices pretending to be maintenance staff. That's not a phishing email with bad grammar. It's a social engineering operation with a script and a plan, and it worked well enough to push the average ransom payment up 176 percent quarter over quarter to $1.88 million, even as the median payment fell to $150,000. Translation: a few enormous payments to sophisticated exfiltration crews are skewing the average, while most victims are paying less and paying less often.
Step 1: Confirm scope before you touch anything
The instinct when you discover ransomware is to start unplugging things immediately. Do that for the obviously infected machines, but first spend the fifteen minutes it takes to understand what you're dealing with. Check which accounts touched the largest volume of encrypted files in the shortest window; that user is often patient zero, and disabling that account should happen before you do much else.
This assessment tells you what kind of incident you actually have. A handful of workstations encrypted is a very different problem than your backup infrastructure being hit too. If backups are intact and isolated, you're in decent shape. If they're not, you're now negotiating from a much weaker position, and that reality needs to reach leadership immediately, not after a few days of wishful thinking.
Step 2: Loop in legal, insurance, and law enforcement, in that rough order
Your legal team should be in the room within the first hour, not after you've made a decision. They'll shape your breach notification obligations (these vary significantly by state and by what kind of data was exposed), your communications with law enforcement, and your options if you're weighing a ransom payment. Failing to bring legal in early is how companies end up non-compliant with notification statutes on top of everything else.
On law enforcement: report to your local FBI field office or through IC3. CISA's #StopRansomware program is also worth engaging directly; they publish decryptor availability and threat actor TTPs that your incident response team may not have visibility into otherwise.
As for cyber insurance: if you have a policy, notify the carrier immediately, because most policies have strict notification windows that can affect coverage if missed. If you don't have one yet, this is the wrong moment to shop for it, but it's worth flagging for after the dust settles. Cyber liability insurance typically covers network security, privacy liability, errors and omissions, and business interruption, though coverage gaps around ransom payments and social engineering fraud are common and worth reading closely.
Step 3: Check whether your backups survived
This matters more than almost anything else in the whole response. According to a 2025 Veeam Ransomware Trends report, roughly 89 percent of ransomware attacks specifically attempt to infect backup repositories, because attackers know that's your escape hatch. If your backups are segregated, immutable, and untouched, you have real leverage and a real path to recovery without paying anyone. If they were on the same network with standard permissions, don't be surprised if they're gone too.
This is the argument for immutable, air gapped, or otherwise segregated backup architecture, and it's not a theoretical best practice. It's the single biggest factor in whether a company recovers on its own terms or someone else's.
Step 4: Isolate, but preserve evidence before you rebuild
Disconnect affected devices from the network, physically if you can, or by disabling network adapters and rotating credentials if you can't. Ransomware spreads laterally by scanning for open shares and weak segmentation, so speed matters here.
The mistake teams make constantly, and this is where a lot of incident response goes sideways, is rushing to wipe and restore before preserving forensic evidence. You need images of the infected systems intact. Law enforcement, your insurer, and your own post incident review all need that evidence, and once you've reformatted, it's gone. Resist the urge to just get back to normal in the first 24 hours. It's uncomfortable to sit with a compromised environment, but reformatting too early is how organizations end up unable to answer basic questions about how the attacker got in, which means you can't be confident you've actually closed the door.
Step 5: Decide whether to negotiate, and understand what paying actually gets you
This is the part everyone wants a clean answer on, and there isn't one. CISA, the FBI, and international partners consistently advise against paying, on the logic that payment funds future attacks and doesn't guarantee a clean outcome. CISA Director Jen Easterly has been explicit that an outright ban on ransom payments isn't realistic in the near term. "I think within our system in the U.S., just from a practical perspective, I don't see it happening," she said at a recent Oxford Cyber Forum discussion, citing the risk that small businesses unable to withstand extended downtime would simply go out of business under a payment ban.
The data on what payment actually buys you is sobering. According to Coveware's Q2 2026 marketplace report, the overall payment rate hit a record low, and the data exfiltration only payment rate specifically dropped to just 15 percent. Companies are increasingly deciding it isn't worth it, and recent incidents explain why: Coveware documented a case involving a group called Icarus that compromised a company called Klue through a SaaS supply chain attack in June 2026. The victim paid to have stolen CRM data deleted, and it later came out that a separate criminal group had retained copies of the same data anyway, leaving the victim exposed to renewed extortion despite having paid. As Coveware put it in their own writeup of the episode, the generic advice that paying a ransom guarantees stolen data gets deleted "turned out to be incorrect advice." There's no contractual enforcement mechanism with a criminal organization; you're trusting people who've already demonstrated they're willing to extort you.
If you do end up negotiating, don't do it yourself. Professional ransomware negotiators exist specifically because the psychology and tactics of these conversations are not intuitive, and a wrong move can escalate demands rather than reduce them.
Step 6: Communicate honestly, internally and externally
Once you have a clearer picture, tell your stakeholders, employees, customers, board, and regulators as required. The instinct to downplay severity to protect the stock price or the brand is understandable and usually backfires. People forgive companies that are straightforward about a bad situation far more readily than ones that get caught minimizing it later. Say what you know, say what you're doing about it, and don't promise timelines you can't hit.
Step 7: Rebuild the security posture, not just the servers
Post incident, the obvious moves apply: multi factor authentication on privileged accounts, network segmentation so lateral movement isn't trivial, and a real network security policy that gets updated based on what you just learned rather than sitting untouched for three years. Given how identity driven modern intrusions are, per Coveware's Q2 2026 vector data, hardening help desk password reset workflows, MFA reset processes, and account recovery procedures deserves as much attention as your firewall rules. Employee awareness training matters here specifically because so many of these intrusions start with someone on the phone convincing a help desk employee to reset a password.
The honest tradeoffs nobody likes to say out loud
There is no version of this where every option is good. Refusing to pay might mean an extended outage that costs your business more in lost revenue than the ransom itself. Paying might mean a worse long term outcome if the attacker doesn't honor the deal, or if a second group retains your data anyway. Fast restoration from backup protects your business continuity but can destroy forensic evidence you need to understand the intrusion and prevent a repeat. Every one of these decisions involves trading one kind of risk for another, and the right call depends on specifics like data sensitivity, regulatory exposure, and how solid your backup posture actually was before the attack, not on a generic checklist.
A non-obvious takeaway: your attacker's motive isn't always money
Most ransomware groups are financially motivated, full stop. But a meaningful subset aren't, or aren't purely. Some are running disruption campaigns against a specific sector, some are nation state adjacent actors using ransomware as cover for espionage, and some genuinely just want to watch an organization struggle. If you're negotiating and the attacker's behavior doesn't track with a rational profit motive, like refusing reasonable offers or escalating demands after partial payment, that's a signal worth escalating to your incident response team and law enforcement rather than assuming you're just bad at negotiating. Understanding what's actually driving the other side changes what a sane response looks like.
Think in terms of resilience, not just recovery. The company that survives a ransomware attack with minimal damage usually isn't the one with the best negotiator. It's the one that had immutable backups, network segmentation, and a rehearsed incident response plan sitting on a shelf before anyone needed them.
