
What to do when cyber attacks disrupt your organisation
How to recover from disruption, get ready for future incidents and make them less likely.
Understanding what ransomware is, how to identify it, and how to respond if you’re a victim of ransomware.
If your organisation has experienced a cyber incident and is based in the UK, you can report it.
In a ransomware attack, you won't be able to access your device and the data stored on it because the files are encrypted.
Usually you're asked to contact the attacker via an anonymous email address or follow instructions on an anonymous web page, to make payment in a cryptocurrency. The attackers may also threaten to leak the data they steal.
Attackers gain access to your network. They establish control and plant malicious encryption software. They may also take copies of your data and threaten to leak it.
The malware is activated, locking devices and causing the data across the network to be encrypted, meaning you can no longer access it.
Usually you will then receive an on-screen notification from the cyber criminal, explaining the ransom and how to make the payment to unlock your computer or regain access to your data.
Payment is usually demanded via an anonymous web page and usually in a cryptocurrency, such as Bitcoin
If your organisation has experienced a ransomware attack there are actions you can take.
The NCSC and UK law enforcement do not encourage, endorse nor condone the payment of ransom demands. But know that if you do pay the ransom:
For this reason, it is important that you always have a recent offline backup of your most important files and data.
Read our guidance to find more information for organisations considering payment in ransomware incidents.
How you or your organisation responds to and recovers from ransomware will hugely affect the impact of an attack. Take a look at our guidance to help you respond and recover.
How to recover from disruption, get ready for future incidents and make them less likely.
Supporting organisations of all sizes to manage their communications strategy before, during and after a cyber security incident.
Guidance for staff responsible for managing a cyber incident response within their organisation.
Advice for organisations experiencing a ransomware attack and the partner organisations supporting them.
Members of this scheme offer NCSC assured Cyber Incident Response services to a wide range of organisations.
There are two levels of NCSC Assured Cyber Incident Response that can help organisations recover from an incident. NCSC Assured Service Providers operating at the technical standard required for CIR Enhanced Level will also be technically competent in providing the incident response services required by CIR Standard Level. If unsure of which level to select, see Information for buyers section.
Download and print our ransomware poster to help protect your colleagues.
How to defend organisations against malware or ransomware attacks.
Protect data where it is vulnerable.
Fifteen best-practice measures to protect digital bulk data.
How to effectively detect, respond to and resolve cyber incidents.









