Ransomware has grown steadily in both scale and sophistication. Recent industry threat reports show ransomware activity rising sharply year on year, with attacks becoming more frequent and more disruptive. Threat actors keep changing their tactics, so defenders have to keep evaluating their security posture in turn.

For most organisations across the UAE and the wider GCC, the honest reality is this: it is no longer a question of whether you will be targeted, but when.

That is exactly why a ransomware response plan needs to be in place before anything happens. Once an attack lands, panic spreads quickly and decisions get made under pressure. An effective response depends on preparation, not improvisation. The 11 steps below give you a practical sequence to follow.

11 steps to take after an attack

1. Don’t panic

The moment you realise you are a target, stay calm and act with purpose. Reach for your plan rather than reacting on instinct. Contact your security provider or your cyber-insurance company for support straight away, so experienced help is on the way while you work through the first steps.

2. Isolate your systems and stop the spread

Start by establishing the scope of the attack. Put blocks in place at network level — isolating traffic at the switch or firewall — or temporarily drop the internet connection if you need to. For a more contained infection, isolate individual devices by unplugging the Ethernet cable or switching off Wi-Fi. The goal is simple: limit how far the ransomware can travel.

Endpoint protection during a malware attack

Endpoint detection and response (EDR) technology can block ransomware at the process level with minimal disruption. Most attackers get in through an exposed weakness — open RDP, a phishing email or a similar route — and strong endpoint protection helps you catch that activity early, before it turns into real damage.

3. Identify the ransomware variant

The tactics and procedures used by each ransomware family are often publicly documented. Identifying the variant can tell you a great deal about how it behaves, how it spreads and where to look next. For some variants, free decryption tools are already available, which may save you considerable time.

4. Identify the initial access

Working out “patient zero” — the point of first entry — is essential to closing the gap that let the attackers in. Common entry points include phishing, exploits against edge services such as Remote Desktop, and the misuse of stolen or weak credentials. Pinpointing this sometimes calls for the expertise of a forensic team.

5. Identify all infected systems and accounts

Look for active malware, or traces of it, on any systems communicating with command-and-control servers. Attackers commonly establish persistence through new processes, registry keys and scheduled tasks, so check for these as you map the full extent of the compromise.

6. Determine whether data was exfiltrated

Ransomware groups frequently steal data as well as encrypt it, using the threat of publishing confidential information to pressure victims into paying. They may also lean on your business partners and clients the same way. Watch for unusual outbound traffic — for example, large transfers from internal servers to external cloud storage.

The importance of backups

7. Locate your backups and confirm their integrity

Ransomware actively tries to delete online backups and shadow copies. Attackers are typically inside a network for days or even weeks before encryption begins, which means your backups may already contain malicious payloads. Scan them carefully to confirm they are clean before you rely on them for recovery.

8. Clean systems or build new ones

If you are confident you have identified every piece of malware, cleaning existing systems can save time. In practice, though, it is often simpler and safer to rebuild clean systems from scratch. Consider standing up a completely separate, clean environment, and put the right security controls in place from the outset to prevent reinfection.

9. Report the incident

Reporting matters. Your legal team can help you meet any obligations tied to regulated data — for example PCI or HIPAA-equivalent requirements — and, under the UAE’s Personal Data Protection Law (PDPL), personal-data breaches may need to be reported to the UAE Data Office within the required timeframe. For serious attacks affecting multiple regions, you may also need to engage the relevant national authorities and law-enforcement bodies.

Paying the ransom after a malware attack?

10. Should you pay the ransom?

Law-enforcement and security bodies consistently advise against paying. Paying does not guarantee you will get your files back, and it helps fund and encourage further attacks. If it is ever on the table, work through the decision carefully with your legal and security teams rather than under pressure in the moment.

11. Learn and improve

Once the dust settles, review the incident properly and identify what can be strengthened. Train your people regularly on phishing and social engineering. Keep backup procedures up to date and test recovery on a routine basis — a backup is only as good as your last successful restore. Sharing what you learned with peers and the wider security community helps everyone raise their defences.

A closing word

This checklist is a general guide. Every organisation is different, and the right response depends on your environment, your data and your obligations. The strongest results come from working alongside security professionals to build a tailored ransomware response plan, ideally as part of a broader cyber incident response strategy — long before you ever need it.

Worried about ransomware, or recovering from an attack right now? Rootsec can help you respond, recover and harden your defences. Book a free consultation.

Most ransomware starts with a single click on a convincing email. A phishing simulation shows you how your organisation would react before it counts.