What to Do During a Ransomware Attack: A Malaysian Playbook
4 Aug 2026 · by HyperDEF Team · 5 min read
Discovering ransomware on your systems is one of the most stressful moments a business owner can face. Files are locked, a ransom note is demanding payment, and every instinct screams to do something immediately. In that moment, panic is your enemy and a clear plan is your best friend. This is a calm, step-by-step playbook for what to do during a ransomware attack, written for Malaysian businesses, including who to call and the critical mistakes to avoid.
If you are in an active attack right now, skip to the first-hour steps below, and if the incident is beyond your team, get professional incident response help immediately.
First: do not panic, and do not pay yet
Ransomware is designed to create urgency and fear so you act rashly. Take a breath. Paying the ransom immediately is almost never the right first move: it does not guarantee you get your data back, it marks you as a business that pays (inviting repeat attacks), and modern groups often keep stolen copies of your data anyway. There are better first steps, and often, better options than paying at all.
The first-hour steps
- Isolate, do not shut down. Disconnect affected devices from the network (unplug the cable, disable Wi-Fi) to stop the ransomware spreading. Avoid simply powering machines off if you can help it, as that can destroy useful evidence in memory.
- Assess the spread. Which systems are affected? Is it contained to a few machines or spreading? Check whether backups and critical servers are hit.
- Preserve evidence. Do not wipe or rebuild machines yet. Photograph the ransom note, and keep the affected systems for investigation, you will need them to understand what happened and meet notification duties.
- Activate your incident response plan. Assemble your team and follow the roles you defined in advance, see the IR plan template. If you do not have one, designate a lead now.
- Engage expert help. If this is beyond your team, call a professional incident response provider. Speed and expertise materially affect the outcome.
- Start the notification clock. If personal data may be affected, the PDPA breach-notification obligations may apply, begin assessing this early.
Who to notify in Malaysia
- Your incident response provider / IT security team, first, to contain and investigate.
- CyberSecurity Malaysia / NACSA, for guidance and to report the incident, which also helps protect other businesses.
- The Personal Data Protection Department (JPDP), if personal data is affected and the breach is notifiable.
- Police (PDRM), ransomware is a crime; report it.
- Your bank, if any financial fraud is involved.
Knowing these contacts before an incident shortens the time between discovery and action.
Should you pay the ransom?
This is the hardest question, and there is no simple answer, but strong reasons argue against paying:
- No guarantee. Decryption tools provided by criminals are often slow, buggy, or incomplete.
- It funds crime and marks you as a paying target for the future.
- Data may still leak, because attackers keep a copy even after payment.
Authorities including CISA generally discourage paying. Before even considering it, check whether a legitimate free decryptor exists, the No More Ransom project, a law-enforcement and industry initiative, offers free tools for many ransomware strains. And above all, if you have good backups, you may not need to pay at all.
Recovery: the role of backups
This is where preparation pays off enormously. If you have reliable, tested, offline or immutable backups that the ransomware could not reach, recovery becomes a matter of eradicating the threat and restoring, not negotiating with criminals. This is precisely why we stress backup strategies so heavily. Recovery steps:
- Fully eradicate the ransomware and close the entry point it used.
- Rebuild or clean affected systems.
- Restore data from clean backups, verifying integrity.
- Reset credentials, since attackers often steal them.
- Monitor closely for signs the attacker returns.
After the attack: learn from it
Once operations are restored, review what happened: how did the attacker get in, what worked in your response, and what would you change? Turn the answers into concrete improvements, better backups, MFA, monitoring, and patching, so the same door cannot be used twice. Understanding how these attacks are launched, which we cover in ransomware-as-a-service, helps you shore up the right defences.
Conclusion
Surviving a ransomware attack is far more about preparation and calm execution than heroics in the moment. Isolate rather than shut down, preserve evidence, activate your plan, and bring in expert help. Resist the urge to pay immediately, check for free decryptors and lean on your backups instead. Notify the right authorities, then learn from the incident to close the gap for good. The businesses that recover well are the ones that decided, in advance, exactly how they would respond.
Frequently asked questions
Should I turn off computers hit by ransomware?
Isolate them from the network (unplug the cable, disable Wi-Fi) rather than powering them off, if possible. Shutting down can destroy evidence in memory that helps investigators understand the attack.
Should I pay the ransom?
Generally no. Payment does not guarantee recovery, funds crime, and data may leak anyway. Check for free decryptors (No More Ransom) and rely on tested backups first. Involve professionals before making any decision.
Who do I report a ransomware attack to in Malaysia?
Your IT/security provider first, then CyberSecurity Malaysia/NACSA, the police, and, if personal data is affected, the Personal Data Protection Department under PDPA breach-notification rules.
How can we recover without paying?
With reliable, tested, offline or immutable backups the ransomware could not reach. Eradicate the threat, rebuild, and restore from those backups, the single best reason to invest in backups before you ever need them.
References
- CISA, StopRansomware, cisa.gov/stopransomware
- No More Ransom, nomoreransom.org
- CyberSecurity Malaysia, cybersecurity.my
- National Cyber Security Agency (NACSA), nacsa.gov.my
Related reading: Data backup strategies for SMEs and How to build an incident response plan.
How secure is your business right now?
Find out in 10 minutes. Our free Cybersecurity Health Check gives you a clear, plain-English risk score with AI-powered insights: no jargon, no obligation.