Skip to main content
Official Seqrite Distributor in Thailand
GuideOriginally published 25 May 2026 · Seqrite

Hit by ransomware — do you have to pay? Recovering without paying the ransom

A Seqrite guide: what to do in the first hour, five recovery steps, and the preparation that means you never need the attacker.

Seqrite's point is that paying is often unnecessary and never safe — payment guarantees nothing. An organisation that prepared properly can recover on its own.

The first hour

  • Isolate infected machines — pull Wi-Fi and Ethernet, disable VPN, block suspicious IPs.
  • Identify the strain from the ransom note and file extensions (e.g. LockBit, BlackCat/ALPHV, Clop).
  • Keep logs and notes as evidence; don't wipe machines yet.
  • Tell leadership, legal and whoever owns PDPA — there may be a duty to notify.

Five recovery steps

  • Assess the whole incident, including whether data was stolen.
  • Remove malware and persistence, reset credentials, patch.
  • Restore from verified clean backups, in phases.
  • Rebuild harder: patches, MFA, least privilege, network segmentation.
  • Watch for reinfection and check for leaked credentials.

The guide puts small incidents at several days, medium ones at one to three weeks, and organisation-wide ones at months. What helps: offline or immutable backups, free decryptors from No More Ransom, a professional incident-response team, and EDR/XDR that isolates machines automatically.

What a business should do

  • Keep at least one offline or immutable backup — and test restoring it.
  • Write a one-page "first hour" plan now: who unplugs what, who calls whom.
  • Don't wipe before preserving evidence — you need it for insurance and to find the way in.
  • Check nomoreransom.org before assuming data is gone.

More news

Evaluate it in your own organisation

30 days, no cost, no commitment. We'll send a trial licence and install steps to the email you give us.

Or call 090-295-5556 · LINE @528gkanm