IT emergency: stabilize first, then report.

Ransomware, compromised accounts, an attack in progress: the first few minutes are decisive. Carry out the five immediate steps – and then report the incident via the prioritized path below.

Five immediate steps

  1. 01

    Disconnect from the network – do not power off

    Disconnect affected systems from the network (unplug the cable, disable Wi-Fi), but do not switch them off: while running, they preserve traces that are important for analysis and recovery.

  2. 02

    Protect your backups

    Do not touch your backups now: no restore attempts, no overwrites. Disconnect any reachable backup targets from the network so they are not encrypted as well.

  3. 03

    Do not pay, do not negotiate

    Do not contact the attackers and do not make any payment without advice. Both often worsen your position rather than improving it.

  4. 04

    Record a timeline

    Note down what was noticed and when – the first anomaly, the affected systems, the measures taken. This timeline speeds up any analysis and is needed for reporting obligations.

  5. 05

    Secure your accounts from a clean device

    Change the passwords of critical accounts (admin, e-mail, banking) only from a device that is not affected – otherwise the attackers read the new credentials right along with you.

Report an incident

We handle emergency reports by e-mail with priority – the subject line “IT-NOTFALL” is processed as a priority at our end. The button opens a prepared message with the details we need for a quick initial assessment. By phone, you can reach us during business hours at +49 212 240915 0.

For existing customers with a service contract, the agreed escalation paths apply – our NOC monitors managed environments around the clock, and we usually see anomalous events there first.

After the emergency comes prevention:tested backups and contingency plans ·self-check in twelve questions