Nano-lesson · usually takes 2–3 minutes
Ransomware & malware — react the right way
How ransomware gets in — and what to do in the first few minutes.
The day WHSmith couldn't process a single sale
One morning in 2022, none of the country's Currys stores could ring up a purchase — the tills were locked by ransomware, and every store had to close. Ransomware is a program that locks files and systems and demands a ransom. It usually gets in via a phishing email, a stolen password or a click on an attachment.
Prevent it
- Never enable macros, and only open files you're expecting.
- Keep your operating system and programs updated.
- Report suspicious emails early — before anyone clicks.
An unexpected invoice with a .zip?
That's a classic way to smuggle in malicious programs. Only open files you're expecting — never a .zip or an "enable macros" prompt from a sender you don't know. If in doubt: ask IT before you click.
If the worst happens
Files get locked in a ransomware attack, and a ransom message pops up — what do you do?
Does this look familiar?
- Disconnect from the network immediately (unplug the cable / turn off Wi-Fi) so the attack doesn't spread to shared drives and colleagues.
- Don't switch off the computer in a panic. Leave it running — but offline — so IT can preserve evidence and possibly your files; a hard shutdown can make the damage worse.
- Never pay the ransom. It funds the criminals and rarely gets your files back.
- Call IT immediately — speed limits the damage.
Remember
What the research says
Ransomware appeared in ~44% of data breaches in 2025 (up from 32%), and stolen credentials (~22%) are the most common entry point — often harvested via phishing and reused against organisations without MFAMulti-factor authentication (MFA/2FA): an extra step beyond your password — such as a code or a tap on your phone — so a thief can't log in with the password alone.. That's why MFA is the single measure with the biggest impact against ransomware.
Question 1 of 3
Your screen suddenly shows a ransom message, and your files won't open. What's the FIRST thing you do?
✓ Correct!
Without a network connection, the attack can't spread to your colleagues' machines — but don't switch off the computer: that would destroy evidence IT needs. Call straight away; minutes matter.
Question 2 of 3
You accidentally opened the .zip file from an unexpected "invoice" email. The computer seems completely normal. What do you do?
✓ Correct!
Malicious programs often work silently for days or weeks, and a scan won't catch everything. Only IT can check it properly — and the sooner, the less damage.
Question 3 of 3
Your computer wants to restart to install an update — right in the middle of your busiest week. What do you do?
✓ Correct!
Updates close exactly the gaps that attacks exploit — every day you delay is an open door. Five minutes during your break is a small price to pay.
Well done!
You've completed one of the foundation courses — the ones everyone gets for free.
With a free login:
- Your points, progress and course certificate are saved.
- You get courses tailored to your role — not just the foundation courses.
- We send training exactly when you need it — for example, as a follow-up to a phishing test.