Cybersecurity June 2025 7 min read

Ransomware Hit Your Business: What to Do in the Next 60 Minutes

Ransomware attacks on South African businesses increased 100% year-on-year in 2024. If it happens to you, the decisions you make in the first hour determine whether you recover in days or months - and whether you pay the ransom.

South Africa is now among the top 10 most targeted countries for ransomware globally. The average ransom demand targeting a South African SME sits between R200,000 and R2,000,000 - and paying it does not guarantee you get your data back. Roughly 40% of businesses that pay a ransom receive corrupted or incomplete decryption keys.

This guide is a practical response playbook. Save it, print it, share it with your team. The worst time to figure out what to do is when it's already happening.

How to recognise a ransomware attack

The signs are usually unmistakeable - but knowing them helps you respond faster:

  • Files have been renamed with an unfamiliar extension (e.g. .locked, .encrypted, .enc)
  • A ransom note has appeared on screen - typically a text file or wallpaper change with payment instructions
  • Files can no longer be opened - they appear corrupt
  • Your computer or server is running unusually slowly
  • Network shares that were accessible are now unavailable
  • Antivirus software has been disabled or is generating alerts

The first 60 minutes: step by step

Minutes 0-5: ISOLATE immediately

Disconnect every affected machine from the network right now. Pull the network cable. Disable Wi-Fi. Do NOT shut the machines down - powered-on machines preserve forensic evidence and may still have unencrypted files in memory. Isolation stops the ransomware from spreading to other machines and network shares.

Minutes 5-10: Identify the scope

While isolating, quickly walk through your environment: which machines are affected? Are your server and network-attached storage (NAS) affected? Are cloud drives (OneDrive, SharePoint, Google Drive) syncing encrypted files? If yes - pause the sync immediately from an unaffected device.

Minutes 10-15: Call your IT provider

This is the call that makes or breaks the recovery. If you have a managed IT provider, this is exactly why you pay them - call the emergency line. If you don't have one, call a reputable IT security firm immediately. Do NOT attempt to restore backups yourself before consulting an expert - incorrect restoration can overwrite evidence and re-encrypt restored data.

Minutes 15-30: Preserve evidence

Take photographs of every ransom note screen. Note the exact time the attack was discovered, which machines are affected, and any unusual activity you noticed in the hours before (slow computers, strange emails, login alerts). This is required for insurance claims and for identifying the attack vector.

Minutes 30-45: Assess your backups

With your IT provider: determine whether you have clean, offline backups that predate the attack. This single factor determines whether you negotiate with attackers or restore independently. If backups exist and are clean - you have significant leverage. If backups are also encrypted or don't exist - your options narrow dramatically.

Minutes 45-60: Notify stakeholders

Inform your leadership team. If client data may have been accessed or exfiltrated, begin assessing your POPIA notification obligations - under POPIA you must report data breaches to the Information Regulator and affected individuals as soon as reasonably possible. Check your cyber insurance policy if you have one.

Should you pay the ransom?

The official guidance from SAPS, Interpol, and every reputable cybersecurity firm is: do not pay. Here's why:

  • Payment funds criminal organisations and marks your business as a willing payer - increasing the likelihood of a repeat attack
  • Roughly 40% of businesses that pay do not receive working decryption keys
  • Some ransomware groups exfiltrate data before encrypting it and extort you further after receiving payment
  • Payment may violate South African financial regulations if the attackers are on sanctions lists
  • In most cases with clean backups, recovery without paying is faster than waiting for a decryption key that may not work

The only scenario where payment might be considered is if no other recovery path exists, the business would otherwise cease operations, and legal counsel has been involved. Even then, engage a professional ransomware negotiation firm - never negotiate directly.

After the attack: the recovery phase

Once contained, recovery typically follows this sequence:

  1. Forensic investigation - how did the attacker get in? The most common entry points are phishing emails, unpatched vulnerabilities, and exposed Remote Desktop Protocol (RDP) ports.
  2. Eradicate the threat - rebuild or reimage affected machines. Do not simply run antivirus and resume - ransomware often installs persistent backdoors.
  3. Restore from clean backups - restore to a known-clean state, verify integrity, and test before reconnecting to the network.
  4. Reset credentials - change all passwords, revoke sessions, and implement MFA on everything. Attackers commonly harvest credentials before deploying ransomware.
  5. Close the entry point - patch the vulnerability, retrain staff on the phishing email that was clicked, or lock down the exposed service that was exploited.
  6. Document and report - file a report with SAPS (for insurance), notify the Information Regulator if personal data was accessed, and conduct an internal incident review.

How to make sure this never happens again

The three controls that prevent the majority of ransomware attacks are:

  • Offline, tested backups - the 3-2-1 rule: 3 copies of data, on 2 different media types, with 1 stored offsite or offline. Tested monthly.
  • Multi-factor authentication on everything - especially email, remote access, and Microsoft 365. Credential compromise is the most common ransomware entry point.
  • Patching and endpoint protection - keeping operating systems and applications up to date, with a monitored EDR (Endpoint Detection and Response) solution in place.

All three are standard components of a managed IT contract. If your current IT arrangement doesn't include them, you're unprotected.

InfoServ Technologies provides 24/7 endpoint monitoring, automated patch management, and tested offsite backups for South African SMEs. Book a free security audit to see exactly where your ransomware exposure lies - before an attacker finds it.