Who this applies to
Any organization that depends on its systems being available.
What to know
- The Cyber Centre publishes a guide on how to prevent and recover from ransomware, and a separate playbook for responding to an incident.
- The controls that matter most are tested offline backups, prompt patching, multi-factor authentication, and limiting what an account can reach.
- Decisions about contacting or paying attackers involve legal, insurance, and sanctions questions. Get advice before any contact.
What to do
- Keep at least one backup copy that an attacker on your network cannot reach, and test restoring from it.
- Print the first-hour steps and your key contacts, because your systems may be down when you need them.
- Report the incident. See the incident help page for where.
This guide is a plain-language summary for general information. It is not legal advice and it does not replace the official source. Requirements change, so check the linked source before you act.