Cybersecurity · Incident response
A plain-English, hour-by-hour response plan for small businesses: contain the damage, protect your insurance claim, report it and get back to work safely.
Isolate, do not power off
Call your insurer before vendors
Restore only to clean systems
30 minutes of data collection, your report the next day, yours to keep with no obligation. Or pick a time now. Or call 954-539-5678.
After a ransomware attack, disconnect affected computers from the network without turning them off, then call your IT provider and your cyber insurer before you hire anyone or touch the ransom note. Preserve evidence, switch to phone or text because your email may be compromised, report the attack to the FBI through IC3 and to CISA, and restore only from backups you know are clean onto rebuilt systems.
Do not pay, wipe machines or contact the attackers on your own. Those decisions affect your insurance, your legal obligations and whether you can recover data. This sequence follows CISA’s #StopRansomware Guide and the FBI’s guidance. It is general information, not legal advice; confirm notification duties with your attorney and your insurer.
Move to phone calls and text messages from personal devices. Attackers often have access to email and may be reading your response.
Reporting does not mean losing control of the response. It often gives you access to information about the specific ransomware group.
Silence breeds rumors, but saying too much too early can create legal problems. Agree the wording with counsel, then keep messages short and factual.
Keep a log of who was told what and when. Regulators, insurers and clients may ask for it later.
Want to know how ready you are before it happens? Our free Technology Health Assessment takes about 30 minutes of data collection. The next day you get a plain-language report that rates your cybersecurity and business continuity, including whether your backups and recovery plan would hold up, with next steps in order. It is yours to keep, with no obligation. Book your assessment.
This is a business and legal decision to make with counsel and your insurer, never alone. Points to weigh:
JLB USA’s cybersecurity services include monitored backups, tested restores and a written recovery plan for businesses with roughly 25 to 100 employees.
Book it now
Choose a slot that suits you. We’ll confirm by email, collect the data with you on the call, and send your report the next day. It’s free, and the report is yours to keep with no obligation.
Prefer to talk first? Call 954-539-5678, or send the form and we’ll contact you.
Disconnect affected computers from the network without powering them off, then call your IT provider and your cyber insurer’s hotline using phone, not email.
Disconnect it from the network instead. CISA advises powering down only as a last resort, because shutting down can destroy evidence held in memory.
Report to the FBI through ic3.gov or your local field office, and to CISA at cisa.gov/report. Your attorney can tell you whether state, HIPAA or contractual notifications also apply.
Make that decision only with your attorney and insurer. Payment does not assure recovery, and paying certain sanctioned groups can create legal risk under U.S. Treasury rules.
It ranges from days to weeks, depending on how many systems were hit and whether clean, tested backups exist. Businesses with immutable backups and a written plan usually recover much faster.