Skip to content
FIN-CSIRT
RS
Report an incident

FIN-CSIRT / Practical lesson

Check protection on your Windows computer

Practical steps for a personal Windows 11 computer. Choose the task before changing settings.

People using personal Windows 11 computersAbout 6 minutes of reading + 3 questions
Start with the example The device may be compromised?

What you will learn

  • Find system updates and threat checks.
  • Verify what has been saved outside the computer.
  • Distinguish locking a lost computer from erasing it for handoff.

Practice example

The backup misses a working folder

Data check before handing over a computer
The backup misses a working folder

Windows Backup shows saved folders, but an important document is in another folder on the drive. You are about to erase the computer.

Schematic practice example; selected folders are not a copy of the entire drive.
Show the example explanation
Check coverage
Review which folders are actually included.
Open a test file
Confirm you can open an important document from the backup.
Only then erase
Removing computer data does not create a backup.

Before you start

These steps cover personal Windows 11 computers. Use IT support for an organisation-managed device. If a named setting is missing, search for its name in Start.

Prepare power and a copy of important data. Do not install fixes from pop-up messages. If there are serious signs of an active attack, use the incident steps first.

Install updates

  1. Open Start → Settings → Windows Update.
  2. Select Check for updates.
  3. Choose Download & install if updates are offered.
  4. Save open documents before a requested restart.
  5. After restarting, return to Windows Update and check for pending actions.

You’re up to date means no further updates are currently offered. It does not certify that the computer is free from malware.

Check threat protection

Search Start for Windows Security. Open Virus & threat protection, then Quick scan. Review the result and any recommended actions, not just whether the scan finished.

Scan options provides additional checks. Full scan is a broader scan; Microsoft Defender Offline scan requires a restart, so save work first. Available controls also depend on the installed protection. Do not reconnect a computer under active remote control just to perform this check.

Create and verify a backup

  1. Search Start for Windows Backup.
  2. Check the personal Microsoft account used for storage.
  3. Under Folders, select the available folders to back up to OneDrive.
  4. Start the backup and review the status of each selected item.
  5. From another trusted device, confirm that an important saved file opens.

Windows Backup is not a complete image of every drive. Check documents outside selected folders and transfer instructions for important apps. See the backup guide for a separate copy. Disconnect a backup drive when finished; do not attach it to a computer showing signs of infection.

If the computer is lost

In advance, search Settings for Find my device and check that it is on. This requires a personal Microsoft account with administrator access and location enabled; work and school accounts do not use this consumer procedure.

If the computer goes missing, enter account.microsoft.com/devices on another trusted device. Choose Find My Device, select the correct computer and choose Find. When Lock is available, complete the process and check its status. The feature must have been prepared before the loss; results depend on device availability.

Locking is not remote erasure. Protect exposed Microsoft and other accounts. Report theft to police; do not give passwords to someone claiming to return the computer.

Erase before selling or giving away

First verify your backup and account access. If the drive is encrypted, obtain your BitLocker recovery key, used to unlock the encrypted drive during recovery. It is not your account password. Disconnect backup drives.

If the key was saved to your Microsoft account, enter aka.ms/myrecoverykey on another trusted device and sign in. Match the Key ID to the ID requested on the recovery screen. If it is missing, check an earlier printout or USB copy, or ask whoever set up encryption. Do not publish the key or erase your only data copy just to get past that screen.

Open Settings → System → Recovery → Reset PC. Keep my files retains personal files and is unsuitable for handoff. For handoff, choose Remove everything and enable Clean data. Check the drive scope and final summary before confirming.

Keep power connected and do not interrupt the reset. Leave the initial setup screen for the next user. This is a consumer process, not certification against business data-destruction requirements. Seek specialist help for those requirements or a faulty drive.

If the device may be compromised

For active remote control, extortion or file encryption, disconnect Wi-Fi and Ethernet. Do not enter new passwords or connect backups. Use another trusted device to follow device recovery. If money is at risk, contact the bank immediately.

Check your knowledge · 3

Your turn to choose the next step.

Choose one answer for each question shown. More complex lessons select three questions from a wider question bank when the lesson loads.

Questions and explanations are also available without JavaScript.

Windows Backup saves selected folders. What else should you check before erasing?

Why does this matter? Important files may sit outside selected folders and apps may require separate transfer steps.

  1. Whether the backup icon looks attractive.

    An icon does not confirm backup contents.

  2. Whether important files are included and open from the backup.Correct answer

    Checking coverage and readability reduces the risk of deleting your only copy.

  3. Only the computer name.

    The name says nothing about saved documents.

You are selling the computer. Why is Keep my files unsuitable?

Why does this matter? Reset options have different effects on personal files.

  1. It deliberately retains personal files.Correct answer

    Handoff requires data removal after verifying your backup.

  2. It deletes every backup on other devices.

    That is not what this option means; still disconnect backup drives before resetting.

  3. It is for remotely locking a lost computer.

    Remote locking is a separate feature.

A ransom demand appears and files are becoming unavailable. What comes first?

Why does this matter? An active attack calls for limiting access, not routine maintenance while connected.

  1. Connect the backup drive.

    Connecting the drive can expose the backup too.

  2. Enter passwords to check every account.

    A compromised computer may capture newly entered information.

  3. Disconnect network connections and seek help from another device.Correct answer

    This limits connectivity and separates recovery from the affected system.

No registration. Your answers are not sent; the result is just for you.

A backup must contain what you need

Before resetting, verify important files and recovery keys, then carefully choose what will be erased.

Check your Microsoft account

References

Sources and further reading

Microsoft separately explains finding a BitLocker recovery key.

Microsoft documents Windows updates, threat checks, Windows Backup, finding and locking a device and reset options. Isolation of an actively affected system follows the US cybersecurity agency’s CISA ransomware guide; organisations also follow their own response plan.

Content last reviewed