Posted on

What to Tell Employees During a Ransomware Attack While Waiting for Help

Tell Employees During a Ransomware Attack

When ransomware is active in your environment, your employees are simultaneously your greatest containment asset and your greatest containment liability. The difference between those two outcomes is determined entirely by what guidance they receive in the first 30 minutes and whether they follow it.

Employees who receive clear, specific, immediate guidance stop using affected systems, avoid actions that spread the ransomware or destroy evidence, and contribute to the response by reporting what they observe. Employees who receive no guidance, vague guidance, or delayed guidance attempt to fix problems themselves, reconnect to systems that should remain isolated, discuss the incident on social media, and make statements to customers that create legal exposure.

The challenge is that delivering clear employee guidance during an active ransomware attack requires using communication channels that may themselves be affected by the incident, reaching employees across locations and time zones, and producing legally sound messaging under maximum time pressure.

This article explains exactly what to communicate to employees during an active ransomware attack, how to deliver it when normal communication channels may not be available, what employees should do and not do, and how to prepare the communication infrastructure before an incident so it executes automatically rather than being built under pressure.

Why Employee Communication Cannot Wait

The instinct during an active ransomware event is to focus entirely on the technical response and treat employee communication as a secondary task. This instinct produces a predictable set of problems.

Employees who are not told what to do will do what seems logical to them. They will try to reconnect to systems that have been isolated for containment. They will attempt to copy files from affected systems to personal devices. They will contact customers before approved messaging exists. They will post about the situation on social media.

Every one of these actions creates additional risk.

Reconnection attempts can extend the infection. File copying may spread ransomware to additional devices. Premature customer communication can create legal exposure. Social media activity can alert attackers to containment efforts.

The employee communication problem is not a soft organizational issue. It is a direct operational issue that affects the success of the technical response.

Organizations with established incident response plans and defined incident response team responsibilities are typically far more effective at managing employee communications during active incidents.

The Communication That Must Happen in the First 30 Minutes

Employee guidance in the first 30 minutes should accomplish three objectives:

  • Stop employees from taking actions that worsen the incident.
  • Channel useful information from employees to the response team.
  • Support business continuity wherever possible.

The message should be short, direct, and actionable.

Recommended First Employee Message

Immediate action required.

We are experiencing a cybersecurity incident affecting some of our systems. Please take the following actions immediately:

  • Stop working on any system showing unusual behavior, inaccessible files, error messages, or payment demands.
  • Do not attempt to fix the problem.
  • Do not shut down affected computers.
  • Do not copy files to USB devices, personal email accounts, or cloud storage.
  • Do not attempt to reconnect to inaccessible drives or systems.
  • If customers or partners ask about service interruptions, use only approved messaging.
  • Report affected systems immediately through the designated emergency contact channel.
  • Use only approved communication channels until further notice.

This message can be delivered through text messages, emergency notification systems, phone calls, or in-person communication.

How to Deliver Employee Communication When Normal Channels May Be Affected

The challenge during ransomware incidents is that email, Microsoft Teams, Slack, and other business communication tools may be unavailable or potentially monitored by attackers.

Organizations should have alternative communication methods prepared in advance.

Personal Mobile Phone Networks

Personal mobile phones are often the fastest and most reliable communication channel during ransomware incidents.

SMS text messages and phone calls do not rely on organizational infrastructure and remain available even if internal systems are unavailable.

This requires maintaining an up-to-date employee emergency contact list outside the production environment.

Emergency Mass Notification Systems

Large organizations benefit from emergency mass notification platforms that can send:

  • SMS messages
  • Voice notifications
  • Mobile application alerts
  • Email notifications to personal accounts

These systems allow rapid communication to an entire workforce regardless of office location.

Overhead Paging and In-Person Communication

For employees physically present in a facility, overhead paging systems and direct communication remain effective.

Designated personnel should conduct floor sweeps when necessary to ensure messages reach everyone.

Out-of-Band Digital Channels

Organizations should establish emergency communication channels before incidents occur.

Examples include:

  • Signal groups
  • WhatsApp groups
  • Personal email distribution lists
  • Dedicated emergency communication platforms

These channels should be tested before they are needed.

What to Tell Different Employee Groups

For All Employees

Every employee should receive the core guidance:

  • Stop using affected systems.
  • Do not shut systems down.
  • Do not copy files externally.
  • Do not communicate externally.
  • Report suspicious activity immediately.

Employees should know exactly who to contact and through which communication channel.

For Customer-Facing Employees

Customer-facing personnel require specific approved messaging.

A recommended response is:

We are aware of a technical issue affecting some of our systems. Our team is actively working to resolve it, and we will provide updates as additional information becomes available.

This message avoids speculation, avoids legal exposure, and maintains consistency.

Organizations should prepare customer communication guidance in advance and ensure it aligns with legal and regulatory requirements.

For IT and Technical Staff

Technical personnel require additional direction.

They should be instructed that no remediation actions are authorized unless directed by the incident response leadership team.

This includes:

  • No wiping systems
  • No restoring backups
  • No malware removal attempts
  • No system rebuilds

Technical staff should report findings and await direction.

Organizations with mature incident response programs and response simulations typically handle this process more effectively.

Ensuring employees receive guidance

For Managers and Team Leaders

Managers should focus on:

  • Ensuring employees receive guidance.
  • Supporting operational continuity.
  • Escalating workforce concerns.
  • Following established response authority structures.

Managers should not direct technical response activities.

For Executives and Leadership

Executives require a separate briefing that includes:

  • Current incident status
  • Business impact
  • Legal and regulatory considerations
  • Insurance coordination
  • Recovery strategy

Leadership communication should occur through secure out-of-band channels whenever possible.

What to Tell Employees About Customer Communication

Customer communication creates one of the largest sources of legal risk during ransomware incidents.

Employees should never speculate about:

  • Whether the company was hacked
  • Whether data was stolen
  • Recovery timelines
  • Customer impact
  • Root causes

Employees should use approved messaging only.

When customers ask additional questions, employees should direct them to designated company representatives.

What to Tell Employees Who Already Took Counterproductive Actions

Some employees will inevitably act before guidance reaches them.

Employees Who Reconnected Systems

Document:

  • What system was accessed
  • When access occurred
  • What actions were taken

This information should be provided immediately to the incident response team.

Employees Who Copied Files

Employees who copied files should:

  • Stop accessing the copied data
  • Preserve the storage device
  • Report the action immediately

The incident response team should evaluate the device for possible compromise.

Employees Who Communicated Externally

Employees should provide:

  • What was communicated
  • Who received the communication
  • When it occurred

Legal counsel may need this information for regulatory or legal review.

The Communication That Continues Through Recovery

Employee communication should continue throughout the incident lifecycle.

Regular updates help prevent speculation and misinformation.

Updates should include:

  • Recovery progress
  • System availability updates
  • Operational changes
  • Future update schedules

Employees do not need every technical detail. They need timely, honest updates.

The Pre-Incident Preparation That Makes This Possible

Effective employee communication depends on preparation completed before the incident.

Organizations should maintain:

  • Current employee mobile contact lists
  • Pre-approved communication templates
  • Out-of-band communication channels
  • Defined communication authority structures
  • Regular security awareness training

Organizations should also maintain strong cybersecurity services, managed IT services, and employee security awareness programs.

Meet Our CEO, Matt Rosenthal

With more than 30 years of experience in business and technology leadership, Matt Rosenthal has helped organizations across healthcare, finance, legal, manufacturing, and defense develop the communication strategies that keep employees informed and productive during cybersecurity incidents. As President and CEO of Mindcore Technologies, Matt leads teams that build incident response programs, communication frameworks, and employee awareness initiatives designed to reduce operational disruption during ransomware attacks.

Matt’s approach emphasizes that employee communication success is determined long before the incident begins. Organizations that prepare communication infrastructure ahead of time consistently perform better during active incidents.

Frequently Asked Questions

How do we handle employees who do not follow the guidance?

First verify that the employee received and understood the guidance. If they did and continue taking counterproductive actions, management intervention may be necessary.

Should we tell employees it is ransomware specifically?

Initial communications can refer to a cybersecurity incident rather than ransomware. The primary goal is directing employee behavior, not explaining technical details.

What if an employee’s personal device may be infected?

The employee should stop using organizational accounts on that device and make the device available for assessment if requested.

How do we communicate with employees in multiple time zones?

Use emergency contact systems immediately rather than waiting for local business hours. Employees must know not to access affected systems when their workday begins.

What should we communicate after recovery is complete?

Post-incident communications should explain what occurred, what improvements are being implemented, and how employees can help reduce future risk.

Build the Communication Infrastructure Before the Incident Requires It

Employee communication during ransomware incidents is only as effective as the preparation behind it.

Organizations that maintain current contact lists, approved messaging templates, out-of-band communication channels, and practiced response procedures consistently communicate faster and more effectively during active incidents.

The investment required is modest. The operational value during a ransomware event is substantial.

Mindcore’s managed IT services and cybersecurity services help organizations across healthcare, finance, legal, manufacturing, and defense build the communication infrastructure, incident response processes, and employee awareness programs necessary to execute effective ransomware response communication when it matters most.

Related Posts

Matt Rosenthal