Skip to content
FIN-CSIRT
RS
Report an incident

FIN-CSIRT / Practical lesson

Close known flaws and prepare recovery

Combine updates, backups and the first response to extortion malware into one sustainable routine.

Individuals, employees and small organisationsAbout 6 minutes of reading + 3 questions
Start with the example Files inaccessible or a ransom message displayed?

What you will learn

  • Apply security updates from official sources.
  • Keep a backup that is not continuously accessible to the same device.
  • Limit spread and involve the responsible team when ransomware is suspected.

Practice example

Documents change extension and no longer open

Work computer
Documents change extension and no longer open

A message demands payment to restore files. A network drive is still connected.

Fictional situation for practice.
Show the example explanation
Many files become inaccessible at once
Stop working and do not try random “fixes” found online.
Network resources are connected
Network isolation may help limit further spread.
Payment is demanded
Payment does not guarantee recovery and should not be decided by one user alone.

What do updates change?

Security updates close known flaws in operating systems, browsers, apps and network equipment. Enable automatic updates where suitable. On work devices, follow the IT team’s schedule because compatibility testing and controlled rollout may be required.

Start updates through the built-in function or the vendor’s official site. An unexpected “your device is infected — update now” message may itself be a scam.

Make a backup that survives the incident

Keep important data in multiple copies and separate at least one so the compromised device cannot continuously modify it. In an organisation, define ownership, frequency and the order in which systems will be restored.

Periodically test a restore. The presence of a backup file or a software success message is not the same as confirmed recovery.

For backup setup, choose Android, iPhone, Windows or Mac. Each guide also covers system updates and explains the controls.

Reduce the chance of initial infection

  • Do not open unexpected attachments or run commands a web page tells you to paste into a system window.
  • Install software only from verified sources and limit administrator rights.
  • Protect remote access with strong authentication and disable it when not needed.
  • In an organisation, practise where employees report a suspicious message or device behaviour.

If you suspect ransomware

  1. Stop using the device and isolate it from the network; do not connect backup drives.
  2. On a work device, notify IT or security immediately. Do not power off, erase or reinstall without their instruction.
  3. Record what you observed and when. A photograph of the ransom note may help if it can be taken without further use of the affected system.
  4. Do not assume payment is a safe recovery path. It does not guarantee a key, full restoration or an end to data misuse.
  5. Report through the internal process and, where applicable, to FIN-CSIRT.

Check your knowledge · 3 of 5

Your turn to choose the next step.

Choose one answer for each question shown. More complex lessons select three questions from a wider question bank when the lesson loads.

Questions and explanations are also available without JavaScript. Without JavaScript, the full bank of 5 questions is shown.

Why is a backup on a permanently connected drive not enough against ransomware?

Why does this matter? Malicious processes may reach connected storage locations as well.

  1. A backup must be smaller than the original.

    Size is not the core issue.

  2. A connected copy may also be changed or encrypted.Correct answer

    A separated or properly protected copy limits the same compromise reaching both.

  3. Backups only work in the cloud.

    Backups can be local or remote if appropriately isolated and tested.

A message offers an update through an unexpected link. What do you do?

Why does this matter? A fraudulent update prompt can deliver harmful content.

  1. Open it because updates should be installed quickly.

    Speed does not replace checking the source.

  2. Forward the link to colleagues.

    Forwarding may spread a suspicious message.

  3. Update through built-in settings or the vendor's official site.Correct answer

    The official mechanism separates the update from an unverified link.

A ransom message appears on a work computer. What is the first step?

Why does this matter? The priority is limiting spread and involving the people responsible for response and evidence.

  1. Disconnect it from the network and notify IT or security immediately.Correct answer

    This limits further access and starts a coordinated response.

  2. Delete all files myself.

    Deletion can destroy data and evidence useful for recovery.

  3. Pay a small amount as a test.

    Payment does not guarantee recovery and may increase risk.

A backup exists but has never been restored as a test. What is still unknown?

Why does this matter? A backup file does not establish that the copy is complete, readable and usable for recovery.

  1. Whether the data can actually be restored within the needed time.Correct answer

    A restore test checks the purpose for which the backup exists.

  2. Whether the backup name contains today's date.

    A neat name does not prove the copy is complete or readable.

  3. Whether the original device is switched on.

    The original device's state does not verify backup quality.

A personal device connected to the work network shows ransomware signs. What do you do?

Why does this matter? A connected device may affect business resources, so the event is not only a personal problem.

  1. Disconnect it from the network and notify IT or security immediately.Correct answer

    Isolation and reporting limit spread and start a coordinated response.

  2. Connect another drive to save the files.

    A newly connected drive may also be affected.

  3. Send the suspicious file to colleagues for testing.

    Forwarding may spread harmful content.

No registration. Your answers are not sent; the result is just for you.

A backup matters when it can be restored

Keep at least one separated copy and periodically verify that recovery works.

Recover a suspicious device

References

Sources and further reading

The Serbian National CERT publishes current security update advisories and a publication on ransomware as a service. Our device recovery guide covers individual response steps.

Content last reviewed