Monday morning, everything is encrypted: the response plan for an SME with no IT department
One page to print and keep in the director's drawer, before it happens. Guide published on 13 September 2026.
The scenario, as it happens
8:10 am. The assistant opens a client file: it has an odd extension and will not open. 8:20, it is the whole file server. 8:25, a text file on the desktop explains, in English, that payment in cryptocurrency is required. In 2025 the Swiss Federal Office for Cybersecurity recorded 65,000 reports; the Akira group, specialised in this kind of attack, carried out 26 known attacks on Swiss companies in the second half of the year alone. Large companies are not the target: organisations with sensitive data and no IT department are.
The first hour: what to do, what not to do
- Disconnect from the network the affected PCs and the server: network cable out, Wi-Fi off. Do not power off the machines: memory holds traces useful for analysis and sometimes the keys.
- Do not pay, and do not answer the attackers. Paying guarantees nothing, funds the next attack, and may engage your liability. That decision is taken with your lawyer and your insurer, not alone at 8:30.
- Do not restore anything yet. A backup plugged into a still-infected network is one backup fewer.
- Call, in this order: the IT provider (emergency number, not the usual ticket), management, the insurer if you have cyber insurance (the number is on the policy, and the insurer often imposes its own responder).
- Write everything down: time of discovery, machines affected, message received, people notified. On paper or on a phone, not on the network.
- Tell the team in one sentence: switch nothing on, plug nothing in, open no mail, wait for instructions. The phone is the channel.
The first day: understand before rebuilding
- How did they get in? A phishing mail, an exposed remote access, a reused password, a compromised supplier. Until the door is identified and closed, restoring is pointless: they will come back.
- What did they take? Recent attacks copy data before encrypting it, then threaten to publish. That changes your obligations (see below).
- What is still clean? The offline or off-site backup, untouched PCs, online services (mail, kDrive) that are not on the local network.
- Report: the Federal Office for Cybersecurity (NCSC) takes reports online and advises; for some infrastructures it has been mandatory since 2025. A criminal complaint is filed with the cantonal police.
Restoration: in this order
- Rebuild the affected machines from scratch, on a clean network, with every password changed and two-factor authentication everywhere.
- Restore data from the most recent clean backup, starting with what runs the business (mail, client files, accounting), not everything.
- Check with users, service by service, before reopening access to all.
- Count: a well-prepared 10 to 30 seat SME is back in two to five days; without a tested backup, it is weeks, or never.
Your obligations, in Switzerland
- Data Protection Act, art. 24: if personal data was stolen or exposed and the risk to individuals is high, you must inform the Federal Commissioner (FDPIC) as soon as possible, and sometimes the individuals themselves. A theft of client or patient files almost always qualifies.
- Professional secrecy: lawyers, doctors, notaries also have their professional bodies' rules. Inform your body.
- Clients, donors, banks: a sober message from you the same day beats a press article the following week. Prepare three sentences, have your lawyer read them.
This guide is not legal advice: for notifications, your lawyer and, if you have one, your cyber insurer are the reference.
What makes the difference between three days and three weeks
It is all decided beforehand. A backup on the 3-2-1 rule (three copies, two media, one off-site and offline) actually restored at least twice a year. Two-factor authentication for everyone. No remote access exposed to the internet. A printed list of numbers to call and recovery access in a safe. And this plan, read once a year by the director and by the person who manages the tools.
Frequently asked questions
Should we pay the ransom?
Our position: no, unless decided otherwise with your lawyer and insurer. Paying guarantees neither the key nor the attackers' silence, and funds the next attack. A tested backup makes the question moot.
Our mail and files are with Infomaniak or Microsoft: are they encrypted too?
Usually not, if the ransomware hit the local network: online services remain reachable from a clean PC. One more reason not to keep the file server in the office without an off-site backup.
Is cyber insurance worth it for an SME?
Often yes, for covering emergency response and legal costs, provided you read the exclusions: most require two-factor authentication and tested backups. Without them, the insurer may refuse to pay.