Ransomware remains a serious cybersecurity threat to organisations in Kenya and around the world. Kenya’s National KE-CIRT/CC continues to track ransomware among the cyber threats affecting organisations, while its guidance provides security recommendations specifically relevant to Kenyan businesses and SMEs.
The danger, however, is not limited to sophisticated malware.
Businesses can also make costly decisions when employees or management assume that every ransom demand represents a successful ransomware attack.
A ransom message is evidence of a potential incident—not, by itself, proof of what happened.
A Ransom Demand Does Not Tell the Whole Story
A genuine ransomware incident can involve encrypted files, compromised accounts, stolen information and attackers maintaining access to systems.
Modern ransomware operations can also use double extortion. Attackers steal data before or alongside encrypting systems, then threaten to publish the information unless the victim pays.
That means a business receiving a ransom demand should not immediately jump to payment.
It should first establish:
- Which systems are affected?
- Are files actually encrypted?
- Can employees still access critical applications?
- Is there evidence of unauthorised access?
- Has data actually been stolen?
- Which accounts or devices may have been compromised?
- Is the ransom message genuine?
- Can the incident be independently verified?
These questions can determine whether the company is facing ransomware, data extortion, another form of malware, compromised credentials—or simply a fraudulent ransom demand.
The Fake-Ransom Scenario
Consider a hypothetical Kenyan SME.
Employees arrive on Monday morning and discover an email claiming that the company’s files have been encrypted.
The message demands payment in cryptocurrency.
Management immediately assumes the company has been hit by ransomware.
But the IT administrator checks the systems and discovers that the supposedly encrypted files are accessible, the company’s backups are intact and there is no obvious evidence of encryption.
The ransom demand may still indicate malicious activity, but paying before investigating could be a serious mistake.
It could also mean giving money to an attacker who never had control of the company’s systems in the first place.
This is why incident verification should happen before financial decisions are made.
What Cybersecurity Experts Recommend
The first priority during a suspected ransomware incident should be containment and investigation, not payment.
CISA’s ransomware guidance recommends determining which systems have been affected and isolating them to prevent further spread. It also recommends preserving relevant evidence, investigating the initial compromise and following an established incident-response plan.
The FBI similarly advises organisations to maintain secure backups, keep systems updated and establish business-continuity plans before an incident occurs.
For Kenyan businesses, the National KE-CIRT/CC also provides cybersecurity best-practice resources aimed at improving the security posture of SMEs and other organisations.
The key lesson is simple:
Don’t negotiate with the ransom note before understanding the incident.
Step 1: Isolate Potentially Affected Systems
If ransomware is genuinely suspected, the affected machines should be isolated from the network as quickly as possible.
That can involve disconnecting affected computers from wired networks or Wi-Fi and isolating affected network segments.
The goal is to prevent malware or compromised credentials from moving to additional systems.
CISA specifically recommends immediately isolating impacted systems as part of ransomware response.
Employees should also avoid casually connecting external drives or other devices to machines suspected of being compromised.
Step 2: Preserve Evidence
One of the biggest mistakes a business can make is wiping everything immediately.
Logs, ransom notes, suspicious files, authentication records and other technical evidence may help investigators determine what happened.
The business should preserve relevant evidence before systems are rebuilt or cleaned.
This can help answer critical questions:
How did the attacker get in?
When did the compromise begin?
What systems were accessed?
Was information stolen?
Is the attacker still inside the network?
Without answers to these questions, paying a ransom may simply solve one immediate problem while leaving the underlying compromise untouched.
Step 3: Check Backups Before Considering Payment
A company with reliable, offline or otherwise properly protected backups may have a recovery option that does not involve paying criminals.
But backups should not simply exist on paper.
Businesses need to regularly test whether they can actually restore their systems from those backups.
CISA and the FBI both recommend maintaining and securing backups, including keeping backup copies separated from systems being backed up.
A backup that cannot be restored when the business is under attack is not much of a recovery strategy.
Step 4: Determine Whether Data Was Stolen
Encryption is not the only concern.
Attackers may steal customer databases, financial records, employee information, intellectual property or other sensitive information before demanding payment.
This is one reason modern ransomware incidents can become data-breach investigations as well.
Businesses should therefore determine whether there is evidence that information left their environment.
If sensitive personal information is involved, the company should also consider its legal, regulatory and notification obligations.
Step 5: Bring in Independent Expertise
Small businesses may not have a dedicated security operations team.
That does not mean the CEO, accountant or general IT technician should make a ransom-payment decision alone.
A suspected ransomware incident may require assistance from:
- A qualified incident-response specialist
- A cybersecurity company
- A digital forensics professional
- The company’s legal advisers
- Relevant regulators or authorities
- Cyber-insurance representatives, where applicable
The National KE-CIRT/CC provides a national incident-response channel and coordinates cybersecurity matters in Kenya.
Should Kenyan Businesses Ever Pay a Ransom?
This is one of the most difficult questions in ransomware response.
Paying can sometimes appear to offer the fastest route back to normal operations.
But payment does not guarantee that files will be recovered, and it does not necessarily remove the attacker from the environment.
The FBI says it does not support paying ransomware demands because payment does not guarantee recovery and can encourage further criminal activity.
CISA and its partner agencies similarly discourage ransom payments.
Businesses should therefore treat payment as an exceptional crisis decision requiring appropriate technical, legal and executive assessment—not as the default response to a ransom note.
A Practical Ransomware Response Plan for Kenyan Businesses
Every business should have a simple incident-response procedure before an attack occurs.
If a ransom demand appears:
1. Stop and don’t panic.
Do not immediately transfer money.
2. Isolate affected systems.
Prevent possible malware from spreading.
3. Contact your IT/security team.
Escalate the incident to people capable of investigating it.
4. Preserve evidence.
Keep ransom notes, logs and relevant system information.
5. Verify the incident.
Determine whether files were actually encrypted or data was stolen.
6. Check backups.
Confirm whether clean backups can restore business operations.
7. Identify the initial access point.
Look for compromised accounts, phishing, vulnerable software, exposed remote services or other entry points.
8. Assess the scope.
Determine which systems, accounts and data were affected.
9. Report and seek appropriate assistance.
Kenyan organisations can engage the National KE-CIRT/CC for cyber incident response and coordination.
10. Make any payment decision only after professional assessment.
The company should understand the risks, alternatives and potential consequences before transferring money.
Prevention Is Cheaper Than Crisis Management
The best time to develop a ransomware strategy is before the ransom note appears.
Kenyan businesses should prioritise:
- Multi-factor authentication
- Strong, unique passwords
- Regular software and operating-system updates
- Endpoint protection
- Network segmentation where practical
- Secure and tested backups
- Employee phishing awareness
- Restricted administrator privileges
- Monitoring of suspicious account activity
- Incident-response procedures
- Regular cybersecurity assessments
These are not measures reserved for large banks or multinational corporations.
They are increasingly becoming basic business-continuity controls.
The Biggest Lesson for Kenyan CEOs
Ransomware creates an environment where fear can become an attacker’s most powerful weapon.
When employees cannot access systems and customers are waiting, management may feel enormous pressure to make a quick decision.
But speed without verification can make a cyber incident more expensive.
The better approach is to create a process where the first response is investigation, containment and recovery planning.
A ransom note should trigger an incident-response procedure—not an automatic bank transfer.
For Kenyan businesses, that distinction could mean the difference between a manageable cybersecurity incident and a costly crisis.
As ransomware operations become more sophisticated, organisations need to prepare for more than encryption. They must be ready to identify false claims, investigate genuine compromises, protect backups, understand data exposure and recover without unnecessarily rewarding attackers.
Cybersecurity is ultimately about resilience.
And the most resilient business is not the one that knows how to pay a ransom quickly.
It is the one that knows what happened, contains the damage and has a credible path to recovery.

