Seqrite's point is that paying is often unnecessary and never safe — payment guarantees nothing. An organisation that prepared properly can recover on its own.
The first hour
- Isolate infected machines — pull Wi-Fi and Ethernet, disable VPN, block suspicious IPs.
- Identify the strain from the ransom note and file extensions (e.g. LockBit, BlackCat/ALPHV, Clop).
- Keep logs and notes as evidence; don't wipe machines yet.
- Tell leadership, legal and whoever owns PDPA — there may be a duty to notify.
Five recovery steps
- Assess the whole incident, including whether data was stolen.
- Remove malware and persistence, reset credentials, patch.
- Restore from verified clean backups, in phases.
- Rebuild harder: patches, MFA, least privilege, network segmentation.
- Watch for reinfection and check for leaked credentials.
The guide puts small incidents at several days, medium ones at one to three weeks, and organisation-wide ones at months. What helps: offline or immutable backups, free decryptors from No More Ransom, a professional incident-response team, and EDR/XDR that isolates machines automatically.
What a business should do
- Keep at least one offline or immutable backup — and test restoring it.
- Write a one-page "first hour" plan now: who unplugs what, who calls whom.
- Don't wipe before preserving evidence — you need it for insurance and to find the way in.
- Check nomoreransom.org before assuming data is gone.



