954-539-5678Free audit
Menu

Cybersecurity · Incident response

Hit by ransomware? What to do in the first 24 hours

A plain-English, hour-by-hour response plan for small businesses: contain the damage, protect your insurance claim, report it and get back to work safely.

Isolate, do not power off

Call your insurer before vendors

Restore only to clean systems

Get your free Technology Health Assessment

30 minutes of data collection, your report the next day, yours to keep with no obligation. Or pick a time now. Or call 954-539-5678.

The short answer

After a ransomware attack, disconnect affected computers from the network without turning them off, then call your IT provider and your cyber insurer before you hire anyone or touch the ransom note. Preserve evidence, switch to phone or text because your email may be compromised, report the attack to the FBI through IC3 and to CISA, and restore only from backups you know are clean onto rebuilt systems.

Do not pay, wipe machines or contact the attackers on your own. Those decisions affect your insurance, your legal obligations and whether you can recover data. This sequence follows CISA’s #StopRansomware Guide and the FBI’s guidance. It is general information, not legal advice; confirm notification duties with your attorney and your insurer.

Hour 0 to 1: contain the damage

  1. Unplug network cables and turn off Wi-Fi on affected machines. If many machines are affected, disconnect the office network from the internet at the switch or firewall.
  2. Do not shut computers down unless you cannot disconnect them. CISA notes that powering off destroys evidence held in memory that investigators may need.
  3. Do not wipe, reinstall or run cleanup tools yet. That can destroy evidence and sometimes the only copy of data that could be recovered.
  4. Disconnect backup drives and pause sync tools like OneDrive or Dropbox so encrypted files do not overwrite good copies.
  5. Photograph the ransom note and any messages on screen. Do not click links in it or reply.

Hour 1 to 4: make the right calls

Move to phone calls and text messages from personal devices. Attackers often have access to email and may be reading your response.

  1. Call your IT provider or internal IT lead and tell them to treat this as an incident, not a support ticket.
  2. Call your cyber insurer’s claims or breach hotline before you hire forensics firms, lawyers or negotiators. Many policies require you to use approved vendors or get consent first, and costs you incur without approval may not be covered.
  3. Call your attorney, or the breach counsel your insurer assigns. Involving counsel early can affect how investigation findings are handled.
  4. Call your bank if there is any chance financial accounts or payment systems were touched.
  5. Decide who speaks for the business to staff, clients and vendors, and tell everyone else not to post about it.

Hour 4 to 12: preserve evidence and find the way in

  • Keep logs from your firewall, Microsoft 365 or Google Workspace, EDR and backup software. Some logs only go back a short time, so export them now.
  • If you must rebuild something, image the affected disk first so investigators can examine it.
  • Look for how the attacker got in: a compromised account, an unpatched VPN or firewall, a phishing email or a remote access tool. CISA’s guide says to check for new or escalated accounts, unusual VPN logins and tampering with backups.
  • Check whether data was copied out. Many attacks now combine encryption with a threat to publish stolen files, which matters for notification.
  • Write a timeline of what was noticed, when and by whom.

Hour 12 to 24: report it

  • File a complaint with the FBI at ic3.gov, or contact your local FBI field office. The FBI asks victims to file a complaint regardless of the amount lost.
  • Report to CISA at cisa.gov/report or 1-844-SAY-CISA. CISA and the FBI may know of a decryptor for your variant.
  • Note notification deadlines. State breach laws, HIPAA, contracts and industry rules can require notice within set periods if personal data was exposed. Your attorney should own this list.

Reporting does not mean losing control of the response. It often gives you access to information about the specific ransomware group.

What to tell staff, clients and vendors

Silence breeds rumors, but saying too much too early can create legal problems. Agree the wording with counsel, then keep messages short and factual.

  • Staff: what happened in one sentence, which systems not to use, how to reach the response lead by phone, and a reminder not to discuss it on social media or with clients until a statement is approved.
  • Clients: that you are dealing with a technical incident, what it means for their work this week, and when they will hear from you next. Avoid guessing about whether their data was affected until the investigation says so.
  • Vendors and banks: warn them that fraudsters sometimes follow an attack with fake payment-change requests, and confirm any request by phone.
  • Everyone: one named contact and a time for the next update. Then meet that time.

Keep a log of who was told what and when. Regulators, insurers and clients may ask for it later.

Want to know how ready you are before it happens? Our free Technology Health Assessment takes about 30 minutes of data collection. The next day you get a plain-language report that rates your cybersecurity and business continuity, including whether your backups and recovery plan would hold up, with next steps in order. It is yours to keep, with no obligation. Book your assessment.

Should you pay the ransom?

This is a business and legal decision to make with counsel and your insurer, never alone. Points to weigh:

  • Paying does not assure you get working decryption or that stolen data is deleted.
  • The U.S. Treasury’s Office of Foreign Assets Control has warned that paying certain sanctioned groups can violate sanctions law, even if you did not know who you were paying.
  • Sophos’s State of Ransomware 2026 survey found 48 percent of organizations whose data was encrypted paid, with a median payment of $769,000 among its respondents of 100 to 5,000 employees. It also found 66 percent recovered using backups.
  • Decryption is often slow and incomplete, so you still need to rebuild and restore.

Recovery: getting back to work safely

  1. Close the entry point first. Patch the vulnerable device or lock the compromised account, or the attacker will come back.
  2. Reset passwords from a known-clean device, starting with admin and service accounts, and re-register MFA where needed.
  3. Rebuild systems from clean images rather than cleaning infected ones, in order of business priority.
  4. Restore data from backups you have checked are from before the compromise, and scan them before reconnecting.
  5. Reconnect gradually and watch for new alerts. CISA says only clean systems should rejoin the network.
  6. Hold a lessons-learned meeting within two weeks and turn the findings into dated tasks.

What to set up now so this goes better

  • A one-page incident plan with phone numbers for IT, insurer, bank and counsel, kept offline.
  • Immutable or offline backups with tested restores. See our backup and disaster recovery guide.
  • EDR on every device, so attacks are spotted before encryption.
  • Your insurer’s hotline and policy number written down somewhere other than your email. Our cyber insurance requirements guide covers what carriers expect.

JLB USA’s cybersecurity services include monitored backups, tested restores and a written recovery plan for businesses with roughly 25 to 100 employees.

Book it now

Pick a time for your 30 minutes

Choose a slot that suits you. We’ll confirm by email, collect the data with you on the call, and send your report the next day. It’s free, and the report is yours to keep with no obligation.

Prefer to talk first? Call 954-539-5678, or send the form and we’ll contact you.

Questions we hear

What is the first thing to do after a ransomware attack?

Disconnect affected computers from the network without powering them off, then call your IT provider and your cyber insurer’s hotline using phone, not email.

Should I turn off my computer if I get ransomware?

Disconnect it from the network instead. CISA advises powering down only as a last resort, because shutting down can destroy evidence held in memory.

Who do I report a ransomware attack to?

Report to the FBI through ic3.gov or your local field office, and to CISA at cisa.gov/report. Your attorney can tell you whether state, HIPAA or contractual notifications also apply.

Should a small business pay a ransomware demand?

Make that decision only with your attorney and insurer. Payment does not assure recovery, and paying certain sanctioned groups can create legal risk under U.S. Treasury rules.

How long does it take to recover from ransomware?

It ranges from days to weeks, depending on how many systems were hit and whether clean, tested backups exist. Businesses with immutable backups and a written plan usually recover much faster.

Related services

Want to know where your business stands?

Pick a time for my free assessmentCall 954-539-5678