← IncidentReady
Small business ransomware response: the first 15 minutes
For companies whose entire IT department is one person. No SOC, no SIEM assumed. Print this.
The first 15 minutes
- Disconnect, don't shut down. Pull network cables / disable Wi-Fi on affected machines. Powering off can destroy memory evidence and interrupt encryption mid-file — isolate instead.
- Stop the spread: disable the affected user accounts, kill VPN sessions, and if it's moving, isolate the file server (pull its cable — a short outage beats total encryption).
- Protect the backups first. Ransomware crews hunt backups. Disconnect external backup drives; verify your cloud/offsite copy hasn't been touched or deleted; change backup-console passwords from a clean device.
- Start an incident log — time, what you saw, what you did. Your insurer and (possibly) lawyers will need it.
- Call your cyber insurer's 24-hour hotline before anything else public. Most policies require it, and they bring negotiators and forensics you don't have to pay for separately.
- Do not email about it from affected systems — assume the attacker reads that mailbox. Use phones/personal devices.
- Photograph the ransom note (phone camera). Don't click its links, don't reply yet, and don't delete anything.
- Don't pay reflexively. Check nomoreransom.org for free decryptors; the pay/don't-pay call comes later, with your insurer, from a decision framework — not from panic.
The mistakes that make it worse
- Wiping and reinstalling day one — you may destroy the evidence your insurance claim depends on.
- Restoring backups onto a still-compromised network — the ransomware just encrypts them again.
- Announcing publicly before your insurer/counsel weigh in.
- Trusting the decryptor to be the end — the access that let them in is still there until you close it.
This checklist is 1 of 10 runbooks.
The full IncidentReady pack covers ransomware end-to-end (containment → insurer → rebuild order → the ransom-decision framework) plus phishing/BEC, compromised accounts, breach notification, and a tabletop kit to rehearse it — written for businesses of 5–50 people. Editable, $29.
Get the pack — $29 Read the free phishing runbook →
Preparedness templates, not legal advice. © 2026 IncidentReady