IT emergency at work — what matters in the first hour
This page is a guide, not an emergency hotline. It helps immediately and free of charge with what really matters in the first hour — no sign-up, nothing you have to pay for.
First: what you should not do right now
Before anything else happens, four things that make the damage worse:
- Don't restart. A restart can wipe traces that are needed later for the investigation.
- Don't delete anything. Even suspicious files or messages — they are evidence later.
- Don't pay. With ransomware, a payment is no guarantee of decryption, and it funds the next wave.
- Don't overwrite anything. No reset, no reinstall, as long as the situation is not clarified — every action can destroy traces that matter for the investigation.
The first six steps
- 1. Disconnect. Disconnect affected devices from the network (unplug the network cable, turn off Wi-Fi) so nothing spreads further.
- 2. Document. What was observed, when, on which device — a phone photo is fine if it needs to be quick.
- 3. Protect backups. Check whether a backup exists that is disconnected from the affected system, and never connect it to the affected network.
- 4. Inform the people responsible. Management or the owner, if not already aware, and your existing IT provider.
- 5. Check reporting duties. See below — where personal data is involved, a deadline is running.
- 6. Bring in specialists. Involve your existing IT provider or a specialist unit for IT security incidents, rather than carrying on alone.
Encrypted: what sets ransomware apart from a normal outage
A normal system outage usually has a technical cause — hardware failure, power cut, a faulty update — and can usually be restored from a clean backup. With ransomware, files are deliberately encrypted and often come with a ransom demand; on top of that comes the question of how the attack got into the system and whether other systems are affected — a plain restore is not enough without clarifying that question.
Reporting duties and contact points
If personal data is affected, GDPR generally sets a 72-hour reporting deadline to the competent supervisory authority, once the incident becomes known. For reporting cyberattacks to the police, North Rhine-Westphalia has the Zentrale Ansprechstelle Cybercrime (ZAC NRW), and for general guidance and warnings, the Federal Office for Information Security (BSI).
Responsibilities and reporting channels checked in August 2026 — in a genuine emergency, please check the current page of the relevant body.
How Digitalbucht can help here — and how it can't
Digitalbucht is the sole proprietorship of Emil Deak, based in Wülfrath, near Düsseldorf, Germany — and not an emergency control centre. There is no 24/7 on-call service here. I usually answer email enquiries within one working day. If your business is down right now and you need someone immediately, the checklist above is what you can do without delay — and the right next call goes to your existing IT provider or the relevant reporting body.
Beforehand: the three things that keep the damage small
The best time for these three things is before the emergency, not after: a tested backup that provably works when it is needed; a separate backup that is not on the same network as the systems it is meant to protect; and documented access, so that in an emergency nobody has to first work out who has access to what. That is exactly the core task of ongoing IT leadership — more on that under Interim IT Manager.
Digitalbucht is the sole proprietorship of Emil Deak, based in Wülfrath, Germany. No team, no agency, no layer in between — the reason for short paths, and equally the limit of what can run in parallel.
Frequently asked questions
What to do in a ransomware attack?
Disconnect affected devices from the network, don't delete or overwrite anything, protect backups, inform the people responsible and bring in specialists — see the six steps above.
Should you pay the ransom?
Generally not recommended: a payment guarantees no decryption, makes the target interesting for further attacks, and should at most be considered after consulting specialists and the police — not as a first reaction.
Does a cyberattack have to be reported?
If personal data is affected, yes — within 72 hours to the competent data protection supervisory authority. Reporting to the police or ZAC NRW is also sensible.
How long does it take to be back up and running after an attack?
There is no blanket answer — it depends on how clean the backups are, how deep the attack went and how quickly specialists get involved. A tested backup shortens this time considerably.
Who helps small businesses with an IT emergency?
The existing IT provider first, supplemented by the relevant reporting bodies (BSI, ZAC NRW). Digitalbucht helps afterwards with rebuilding and with preparing for the future — not as an emergency service in the acute hour.
Next: Interim IT Manager — how to keep the next emergency smaller from the start. If the acute emergency turns into an ordered project afterwards, such as a system change: External IT Project Manager. For preparedness on your own device: Custos — a crisis guide that also works offline.
Last updated: august 2026
Briefly describe what happened.
No “call now” button, no 24/7 promise: we usually reply within one working day.