In the event an infection takes place, not panicking is the most important advice to remember. The machine in question should be immediately shut down and taken off line. If you can get a screen shot of the actual ransomware notice, great! Any document immediately being worked on should be considered lost, but any earlier versions that have been backed up should be safe. The workstation itself should be restarted only when you have a boot disk and software immediately available to reboot it directly into an anti-virus removal tool like Hit Man Pro, Malwarebytes, or MS Security Essentials Removal Tool, etc. If caught early, a lot of the more prevalent ransomware (there can be more than just one kind on your computer) can be removed and the computer cleaned before everything is “locked”.
Depending on the malware/ransomware itself, the workstation and the files on it may, or may not be salvageable. In the worst case scenario, the device gets wiped and everything gets reinstalled from your backups.
Backups and antivirus software are critical components of good computer security.