A ransomware attack in Africa is a business emergency, not just a technical failure. In the first hours after files start locking, the decisions you make — what to disconnect, who to call, whether to pay — shape whether the business recovers or closes. Reporting has put ransomware exposure among South African companies as high as three in four in a single year, and a significant share of affected small businesses shut down afterwards.
This is a timeline: what to do in the first 15 minutes, the first hour, the first 24 hours and the first 72 hours, followed by how to rebuild and prevent a repeat.
How ransomware usually gets in
Most small-business infections start with a phishing email, a stolen or reused password, an unpatched system exposed to the internet, or a malicious file. The malware then spreads across shared drives and connected devices, encrypting as it goes.
First 15 minutes: isolate and stop the spread
- Disconnect affected devices from the network and the internet — unplug the cable, turn off Wi-Fi. Avoid powering them off if you can; that can destroy evidence.
- Disconnect shared storage, external drives and backups that are still attached.
- Tell staff to stop using company systems and not to log in.
First hour: preserve evidence and alert decision-makers
- Photograph the ransom note and any error screens.
- Do not delete files or wipe machines yet.
- Alert the owner or leadership, and whoever handles IT.
- Start a written log: what happened, when, and what you did.
First 24 hours: contact the people who can help
- IT support or a managed security provider to assess scope and begin containment.
- Your bank and mobile money provider if any financial systems, saved cards or payment approvals were on affected machines — ask them to watch for fraud.
- Your cyber insurer, if you have a policy; many require early notification.
- The relevant national CERT or cybersecurity authority for your country, and law enforcement where required.
First 48 hours: assess backups and impact
Determine which backups are clean and offline, how recent they are, and whether customer or payment data was accessed — not just encrypted. Map what is down and what it means for trading. This assessment drives the recovery plan, and whether paying is even a question.
First 72 hours: communicate carefully and plan recovery
If customer or personal data was exposed, prepare a clear, honest notification consistent with your country’s data-protection rules; delayed or misleading disclosure causes more damage than the breach. Internally, agree a recovery sequence: rebuild clean systems, restore from verified backups, reset all credentials, then reconnect in stages.
Should you pay the ransom?
Security agencies generally advise against paying. Payment does not guarantee working decryption, marks you as a business that pays, may breach sanctions rules depending on the attacker, and funds further crime. It is only ever considered when there is no viable backup and the data is existential — and even then, only with professional and legal advice. The real answer is to make sure you never face that choice, by keeping tested offline backups.
Rebuilding securely after an attack
Rebuild affected machines from clean images rather than cleaning them. Restore data only from backups confirmed to predate the infection. Force a password reset across every account, turn on MFA everywhere, patch everything, and review who had access to what. Keep monitoring for weeks — attackers often leave a way back in.
Prevention checklist for African SMEs
- MFA on every account, especially email and remote access.
- Offline, tested backups of everything that matters.
- Automatic updates on all devices and software.
- Staff trained on phishing and payment verification.
- Least-privilege access and prompt removal of former staff.
- A one-page incident response plan everyone can find.
Frequently asked questions
What should be disconnected first during a ransomware attack?
The affected devices, from both the network and the internet, followed by shared drives and any backups still connected. Speed limits how far the encryption spreads.
How can a company recover with no backups?
Options are limited: check whether a free decryptor exists for that ransomware family, rebuild systems and accept the data loss, or seek specialist recovery help. This is why offline backups are the single most important control.
Who should an African SME contact in the first 24 hours?
IT or security support, your bank and mobile money provider, your insurer if you have cover, and your national cybersecurity authority. Preserve evidence for all of them.
How do SMEs prevent repeat attacks?
Assume the original entry point is still open until proven closed: reset all credentials, patch, review access, and monitor. Then build the prevention checklist above into a monthly routine.
Next step: write your one-page incident plan today — contacts, what to disconnect, where the backups are — and store a printed copy offline. For prevention, read our 10-step SME security guide and Cybersecurity in Africa.
TechBrief Africa reports independently and follows a documented editorial standards policy. Spotted an error in this article? Tell us and we will review it.

