IT emergency: stabilize first, then report.
Ransomware, compromised accounts, an attack in progress: the first few minutes are decisive. Carry out the five immediate steps – and then report the incident via the prioritized path below.
Five immediate steps
- 01
Disconnect from the network – do not power off
Disconnect affected systems from the network (unplug the cable, disable Wi-Fi), but do not switch them off: while running, they preserve traces that are important for analysis and recovery.
- 02
Protect your backups
Do not touch your backups now: no restore attempts, no overwrites. Disconnect any reachable backup targets from the network so they are not encrypted as well.
- 03
Do not pay, do not negotiate
Do not contact the attackers and do not make any payment without advice. Both often worsen your position rather than improving it.
- 04
Record a timeline
Note down what was noticed and when – the first anomaly, the affected systems, the measures taken. This timeline speeds up any analysis and is needed for reporting obligations.
- 05
Secure your accounts from a clean device
Change the passwords of critical accounts (admin, e-mail, banking) only from a device that is not affected – otherwise the attackers read the new credentials right along with you.
Report an incident
We handle emergency reports by e-mail with priority – the subject line “IT-NOTFALL” is processed as a priority at our end. The button opens a prepared message with the details we need for a quick initial assessment. By phone, you can reach us during business hours at +49 212 240915 0.
For existing customers with a service contract, the agreed escalation paths apply – our NOC monitors managed environments around the clock, and we usually see anomalous events there first.
After the emergency comes prevention:tested backups and contingency plans ·self-check in twelve questions