Skip to main content

Mitigating malware and ransomware attacks

How to defend organisations against malware or ransomware attacks.

iStock.com/Olemedia

This guidance helps private and public sector organisations deal with the effects of malware (which includes ransomware). It provides actions to help organisations prevent a malware infection, and also steps to take if you're already infected.

Following this guidance will reduce:

  • the likelihood of becoming infected
  • the spread of malware throughout your organisation
  • the impact of the infection

If you've already been infected with malware, please refer to our list of urgent steps to take

For advice on minimising potential harm smaller organisations should refer to the NCSC's Small Business Guide. For information about protecting your devices at home, please read our guidance especially written for individuals and families.



Should you pay the ransom?

Law enforcement do not encourage, endorse, nor condone the payment of ransom demands. If you do pay the ransom:

  • there is no guarantee that you will get access to your data or computer
  • your computer will still be infected
  • you will be paying criminal groups
  • you're more likely to be targeted in the future

Attackers will also threaten to publish data if payment is not made. To counter this, organisations should take measures to minimise the impact of data exfiltration. The NCSC's guidance on Protecting bulk personal data and the Logging and protective monitoring guidance can help with this.

Using a defence in depth strategy

Since there's no way to completely protect your organisation against malware infection, you should adopt a 'defence-in-depth' approach. This means using layers of defence with several mitigations at each layer. You'll have more opportunities to detect malware, and then stop it before it causes real harm to your organisation.

You should assume that some malware will infiltrate your organisation, so you can take steps to limit the impact this would cause, and speed up your response.



Note

Files encrypted by most ransomware typically have no way of being decrypted by anyone other than the attacker. However, the No More Ransom Project provides a collection of decryption tools and other resources from the main anti-malware vendors, which may help.


Published

Publish date

Reviewed

Version

3.0