IT emergency: what to do in the first 30 minutes
It is urgent — this way
Call rather than write. During an ongoing incident a phone call saves more time than any description by email.
In an IT emergency the first minutes decide the damage. One rule applies in all four cases: disconnect affected devices from the network, but do not switch them off and do not delete anything — memory and logs hold the traces needed for recovery and for any report. Then get help. We are reachable on working days on the number below and usually begin by remote maintenance within minutes.
This page is for acting, not for reading. Find your case below and work through the steps in order. Everything else — cause analysis, recovery, notification duties — comes afterwards. We are explicitly reachable even if you are not a client of ours; an acute emergency is the wrong moment for a contract question.
Files are encrypted (ransomware)
Files no longer open, have new extensions, or there is a text file with a ransom demand in the folder.
The first steps
- Disconnect affected computers and servers from the network at once — pull the cable or switch off Wi-Fi. Do not power off.
- Check all other devices on the same network: are files affected there too? When in doubt, disconnect them as well.
- Physically disconnect the backup immediately if it is attached to the network — otherwise it gets encrypted too.
- Photograph the screen: ransom note, file extensions, time. That is evidence and helps with attribution.
- Get help and report the incident — where personal data is involved, a 72-hour deadline for notifying the data protection authority starts running.
What not to do now
- Do not pay before somebody has checked the backup — in most cases recovery is possible.
- Do not run decryption tools from the internet; a large share of them is malware itself.
- Do not reinstall the affected devices before the cause is known — otherwise it happens again.
The server has failed
Nobody can reach the data, the ERP system will not start, network drives have disappeared.
The first steps
- Establish the scope: does it affect all workstations or only one? Is the network as a whole affected?
- Look at the server without changing anything: is it running? Are fault lights on? Is there a message on the screen?
- Check power and network connection — surprisingly often it is a plug or the uninterruptible power supply.
- Do not restart anything before somebody has seen the state. A restart can clear error messages needed for diagnosis.
- Get help and in parallel work out which work can continue without the server for now.
What not to do now
- Do not swap or pull out drives — in a RAID set that can destroy the last intact state.
- Do not restart repeatedly; with failing hardware that makes the damage worse.
- Do not start a restore without first checking how old the backup is.
A mailbox has been taken over
Mail goes out from your address that nobody wrote, or clients report strange messages with you as sender.
The first steps
- Change the password of the affected account at once — from another, clean device.
- End all signed-in sessions (one click in Microsoft 365 and Google Workspace).
- Enable two-factor sign-in if it is not already on. Without it the new password is gone just as quickly next time.
- Check forwarding and mailbox rules: attackers almost always create an inconspicuous rule that quietly redirects replies.
- Warn recipients who may have received affected messages — especially where invoices carry changed bank details.
What not to do now
- Do not simply delete the account — that also removes the logs showing what happened.
- Do not reply to the fraudulent messages or open links in them.
- Do not release any payment arising from that correspondence before it is confirmed by phone.
A laptop or phone is gone
A device with company data has been lost or stolen — on a train, in a car, on a building site.
The first steps
- Check whether the device is managed: then it can be locked and wiped remotely. That is the most important step and takes minutes.
- Change the passwords of the accounts that were signed in on the device — email first, then everything attached to it.
- End that device's signed-in sessions in all services.
- Record what was on the device: client data, personnel data, credentials. Whether a notification duty applies depends on it.
- In case of theft file a police report and document the incident internally, with time and affected data.
What not to do now
- Do not wait to see whether it turns up — a lock can be undone, lost time cannot.
- Do not assume a login password is enough: without disk encryption it is bypassed in minutes.
- Do not leave the incident unreported where personal data is involved.
What comes afterwards
Once the business is running again, the second part begins: establish the cause, close the gap, document the incident. Exactly this part is skipped most often — with the result that the same incident recurs months later. An IT security check with a written report costs €490 and ends with a list sorted by urgency. If you want ongoing support afterwards: from €29 per workstation and month, monitored backups from €49 per month.
Guide prices, net plus VAT. As of: September 2026 · All prices at a glance
Frequently asked questions
Should we pay in a ransomware case?
Not before somebody has checked the backup. In most cases where a separately kept backup exists, recovery gets you there faster and more safely than a payment. A payment guarantees neither decryption nor that the data will not be published anyway — and it funds the next wave. The decision is yours; we provide the basis for it.
Do we have to report an incident?
Where personal data is affected, the GDPR provides for notifying the supervisory authority within 72 hours of becoming aware of the incident. Whether a duty applies and how it is worded should be settled with legal advice. What we supply are the technical findings: what was affected, when, and which data was reachable.
How quickly can you be there in an emergency?
By remote maintenance we usually begin within minutes of the call on working days — there is no travel, and that is exactly the difference in an emergency. Where somebody has to be on site, we cover a radius of roughly an hour's drive around Lenzing; the driving time to individual towns is on our regional pages.
We have no backup. Is everything lost?
Not necessarily, but it becomes laborious. Depending on the case, data can be reconstructed from shadow copies, cloud recycle bins or directly from the drives — with an uncertain outcome and considerably more effort. That is precisely why a verified backup is the cheapest insurance there is in IT.
We will get back to you within 24 hours.