The first hours after a ransomware attack shape how quickly and safely a business recovers. Containment, evidence preservation, and coordinated communication matter more than speed alone.
Key takeaways
What to know before you act
- Isolate affected systems quickly, but avoid wiping or rebooting them before evidence is preserved.
- Bring in your incident response provider, cyber insurer, and legal counsel early.
- Restore only from backups confirmed to be clean, and fix the entry point before reconnecting.
Why it matters
What business leaders should understand
Rushed actions—wiping systems, restoring infected backups, or contacting attackers without guidance—can make recovery slower and riskier. A calm, ordered response reduces damage.
The right response should reflect your environment, data, vendors, risk, and operational priorities. Use this guide as a practical starting point, then validate important decisions with the people responsible for your technology, cybersecurity, legal obligations, and insurance coverage.
Learn how Meta IT Pro can help with backup and disaster recovery, business continuity planning, and incident response services.
Related reading: What is ransomware? and Incident response and remediation guide.
The first hours
CISA's #StopRansomware Guide provides a detailed response checklist. For a small business, the immediate priorities are to stop the spread, preserve evidence, and get the right help involved.
- Disconnect affected devices from the network and disable Wi-Fi; do not power them off unless advised.
- If many systems are affected, consider disconnecting the internet connection.
- Contact your IT or incident response provider and your cyber insurer—many policies require approved vendors.
- Engage legal counsel to guide notification and privilege considerations.
- Report the incident to the FBI through IC3 or a local field office, and to CISA.
- Use out-of-band communication if email or Teams may be compromised.
Investigation and recovery
Determine how the attackers got in, which systems and data were affected, and whether data was stolen. That information drives notification decisions and ensures the same entry point is closed before recovery.
Reset credentials, especially administrator and service accounts, and rebuild or clean affected systems. Restore from backups that predate the compromise and verify them before reconnecting. Recover systems in business-priority order and monitor closely for signs of the attacker returning.
About paying a ransom
The FBI does not support paying ransoms, which does not guarantee recovery and may fund further crime. Payments can also raise legal issues, such as sanctions restrictions. Any decision should involve leadership, counsel, the insurer, and experienced incident responders.
Practical action plan
Steps your business can take
Disconnect affected systems from the network without powering them off.
Contact your IT or incident response provider, cyber insurer, and legal counsel.
Preserve logs and evidence and report the incident to law enforcement.
Restore from clean, verified backups in business-priority order.
Recommended next steps
Continue from this article.
These pages expand the specific risks and decisions covered in this guide. Use them to move from general understanding to the service, tool, or related topic that best matches your next question.
Related guide
What is ransomware?
Understand how attacks unfold.
Explore nextRelated guide
Incident response and remediation guide
Coordinate roles and decisions during recovery.
Explore nextRelated guide
RTO vs. RPO explained
Set recovery priorities in advance.
Explore nextPlanning tool
Cyber-insurance readiness
Confirm insurer contacts and requirements.
Explore nextWarning signs
Do not ignore these indicators
- Files renamed with unfamiliar extensions or ransom notes
- Security tools disabled or backups deleted
- Unusual administrator activity outside business hours
Frequently asked questions
Common questions, answered.
What should I do first after a ransomware attack?
Isolate affected systems, preserve evidence, and contact your incident response provider, cyber insurer, and counsel.
Should infected computers be turned off?
Disconnect them from the network but avoid powering them off unless responders advise it, to preserve evidence.
Who should we report ransomware to?
Report it to the FBI through IC3 or a local field office, and to CISA.
How Meta IT Pro can help
Related services and practical next steps
Explore the services connected to this topic. These links provide more detail about scope, safeguards, support, and how to start a conversation with our team.
Authoritative references
Sources and further reading
These primary sources support the guidance in this article and provide additional technical or consumer information.
Cybersecurity and Infrastructure Security Agency
#StopRansomware Guide
Preparation, prevention, response, and recovery guidance for ransomware and data-extortion incidents.
Federal Bureau of Investigation
Internet Crime Complaint Center (IC3)
The FBI's portal for reporting internet crime, including business email compromise and wire fraud.
National Institute of Standards and Technology
NIST SP 800-61 Rev. 3: Incident Response Recommendations
Current NIST guidance for integrating incident response into cybersecurity risk management.
Federal Trade Commission
Data Breach Response: A Guide for Business
Steps for securing operations, fixing vulnerabilities, and notifying appropriate parties after a breach.
Need help with your IT solution?
Get practical guidance from a local IT and cybersecurity team.
Meta IT Pro helps Massachusetts and Rhode Island businesses improve support, security, Microsoft 365, Google Workspace, networks, backup, recovery, and compliance readiness. Tell us what is not working - or what you want to improve - and we will help identify a sensible next step.
