It is 7:23 AM. An employee calls to say her computer is displaying a message stating that all files are encrypted and you must pay €50,000 to get them back. What do you do now?

If your answer is "I'm not really sure," it is time to create an emergency plan before the situation arises. Because during an attack, you do not think clearly. Adrenaline, panic, and time pressure are a poor combination. A written plan gives you a script to follow when your brain stops functioning optimally.

The first hour: isolate, document, contact

Isolate the affected systems

The most critical first step: disconnect the affected devices from the network. Unplug the network cable, disable Wi-Fi, isolate the device. The goal is to stop propagation. Ransomware and malware actively move across the network and infect everything they can reach.

Do not shut down the computer. It sounds counterintuitive, but shutting down can erase evidence that is important for investigation and insurance. Leave it on but isolated.

Document what you see

Take photos of all screens with your phone. Note timestamps, error messages, and which systems are affected. This documentation is critical for insurance claims, police reports, and potential regulatory notification.

Call your IT partner

Now. Not in two hours. Call immediately. Your IT partner knows your infrastructure and can help assess the scope and take the next steps. If you do not have an IT partner, your first call should be to CFCS (Centre for Cyber Security) at 33 32 55 80.

Do not pay the ransom as the first step. It does not guarantee that you will get your files back. It funds criminals. And it tells the attackers that you pay, which increases the risk of being hit again. Always consult your IT partner and, if relevant, the police first.

Hours 2–6: assessment and escalation

Map the scope

What is affected? Only workstations or also servers? Is the backup intact? Are there signs that data was copied out before encryption (double extortion)? These answers determine the next strategy.

Who should be contacted?

  • IT partner: already done
  • Cyber insurance: call and report the incident. It typically includes a crisis management service.
  • Danish Data Protection Agency: if personal data is involved, you must report it within 72 hours. This is a GDPR requirement.
  • Police: particularly in the case of ransomware with a ransom note, you should file a report with the police.
  • Board / owners: management must be informed.

Communication with employees

Tell employees what happened, concisely and factually. Ask them not to speak with the press or share on social media. Explain what they should and should not do in the meantime. Uncertainty and rumors are nearly as damaging as the attack itself.

Hours 6–24: recovery and analysis

Now the technical recovery begins, but it happens only from verified, clean backups. Reinstall systems from scratch. Restore data from backup. Verify that the backup is clean before you reconnect it to the network.

In parallel, technical analysis begins: how did the attackers get in? When did the initial compromise occur? What can you do to prevent it next time?

Create the plan now, not after the fact

An IT emergency plan does not need to be long. One page with names, phone numbers, and sequence of actions is sufficient. Keep it printed in a physical location, because if your systems are encrypted, you cannot access a digital document.