What do updates change?
Security updates close known flaws in operating systems, browsers, apps and network equipment. Enable automatic updates where suitable. On work devices, follow the IT team’s schedule because compatibility testing and controlled rollout may be required.
Start updates through the built-in function or the vendor’s official site. An unexpected “your device is infected — update now” message may itself be a scam.
Make a backup that survives the incident
Keep important data in multiple copies and separate at least one so the compromised device cannot continuously modify it. In an organisation, define ownership, frequency and the order in which systems will be restored.
Periodically test a restore. The presence of a backup file or a software success message is not the same as confirmed recovery.
For backup setup, choose Android, iPhone, Windows or Mac. Each guide also covers system updates and explains the controls.
Reduce the chance of initial infection
- Do not open unexpected attachments or run commands a web page tells you to paste into a system window.
- Install software only from verified sources and limit administrator rights.
- Protect remote access with strong authentication and disable it when not needed.
- In an organisation, practise where employees report a suspicious message or device behaviour.
If you suspect ransomware
- Stop using the device and isolate it from the network; do not connect backup drives.
- On a work device, notify IT or security immediately. Do not power off, erase or reinstall without their instruction.
- Record what you observed and when. A photograph of the ransom note may help if it can be taken without further use of the affected system.
- Do not assume payment is a safe recovery path. It does not guarantee a key, full restoration or an end to data misuse.
- Report through the internal process and, where applicable, to FIN-CSIRT.