← IncidentReady
Small business ransomware response: the first 15 minutes
For companies whose entire IT department is one person. No SOC, no SIEM assumed. Print this.
The first 15 minutes
- Disconnect, don't shut down. Pull network cables / disable Wi-Fi on affected machines. Powering off can destroy memory evidence and interrupt encryption mid-file — isolate instead.
- Stop the spread: disable the affected user accounts, kill VPN sessions, and if it's moving, isolate the file server (pull its cable — a short outage beats total encryption).
- Protect the backups first. Ransomware crews hunt backups. Disconnect external backup drives; verify your cloud/offsite copy hasn't been touched or deleted; change backup-console passwords from a clean device.
- Start an incident log — time, what you saw, what you did. Your insurer and (possibly) lawyers will need it.
- Call your cyber insurer's 24-hour hotline before anything else public. Most policies require it, and they bring negotiators and forensics you don't have to pay for separately.
- Do not email about it from affected systems — assume the attacker reads that mailbox. Use phones/personal devices.
- Photograph the ransom note (phone camera). Don't click its links, don't reply yet, and don't delete anything.
- Don't pay reflexively. Check nomoreransom.org for free decryptors; the pay/don't-pay call comes later, with your insurer, from a decision framework — not from panic.
The mistakes that make it worse
- Wiping and reinstalling day one — you may destroy the evidence your insurance claim depends on.
- Restoring backups onto a still-compromised network — the ransomware just encrypts them again.
- Announcing publicly before your insurer/counsel weigh in.
- Trusting the decryptor to be the end — the access that let them in is still there until you close it.
Preparedness templates, not legal advice. © 2026 IncidentReady