The First Hour of a Ransomware Attack

The First Hour of a Ransomware Attack: What You Do (and Why Most Businesses Don’t Have a Plan)

Ransomware doesn’t announce itself with a warning shot. It shows up as a locked screen, a ransom note where your files used to be, or a call from an employee saying nothing will open. What you do in the first sixty minutes determines whether this is a bad day or the end of your business. Most Minnesota small businesses have never written this plan down — here’s what it needs to say.

1. Disconnect before you diagnose

The first move isn’t to figure out what happened — it’s to stop it from spreading. Pull the network cable or disable Wi-Fi on the affected machine immediately. Ransomware moves laterally across a network in minutes; isolating one infected device fast is the difference between one workstation and every server you own.

2. Know who you’re calling before you need to call them

In the moment, businesses waste their first critical hour searching for a phone number. Your plan should already have three numbers on it: your IT support provider, your cyber insurance carrier’s incident hotline, and, if customer or patient data is involved, legal counsel. If you don’t have all three written down somewhere everyone can find, you don’t have an incident response plan, you have good intentions. This is usually the same gap we see in businesses that have outgrown ad hoc IT support without realizing it: nobody owns the plan because nobody was ever assigned to own it.

3. Don’t touch the ransom note, and don’t assume you have to pay it

Paying doesn’t guarantee you get your data back, and it marks you as a payer for the next attempt. The businesses that recover fastest are the ones who can restore from a clean backup instead of negotiating with criminals. This is the whole case for verified, regularly tested backups: they’re not a checkbox, they’re your leverage.

4. Preserve evidence, don’t wipe and rebuild out of panic

It’s tempting to nuke the infected machine and move on. Don’t, until whoever is handling the incident (internally or your IT partner) has had a chance to capture what happened. That evidence matters for insurance claims, for any legal or compliance exposure if customer data was involved, and for closing the actual hole the attacker used, so it doesn’t happen again in three months.

5. Notify internally before word spreads externally

Employees talking on social media or to customers before you’ve confirmed what’s actually affected creates a second mess on top of the first. A short, calm internal message, “we’re aware of an issue, IT is on it, don’t discuss it externally yet,” buys the time to actually understand the scope before the story gets ahead of the facts.

The uncomfortable truth

None of this works if it’s the first time you’re thinking about it during the actual attack. An incident response plan is only useful written down, in advance, tested, not improvised at 2pm on a Tuesday while your point-of-sale system is locked. That’s the difference between a security-first IT partner and a “call someone when it breaks” arrangement.

If you couldn’t answer “who do we call and what do we do first” without reading this article, that’s worth fixing before you need it. Book a consultation and let’s build your incident response plan now, while it’s still a hypothetical.


Comments

Leave a Reply

Your email address will not be published. Required fields are marked *