← IncidentReady

Small business ransomware response: the first 15 minutes

For companies whose entire IT department is one person. No SOC, no SIEM assumed. Print this.

The first 15 minutes

  1. Disconnect, don't shut down. Pull network cables / disable Wi-Fi on affected machines. Powering off can destroy memory evidence and interrupt encryption mid-file — isolate instead.
  2. Stop the spread: disable the affected user accounts, kill VPN sessions, and if it's moving, isolate the file server (pull its cable — a short outage beats total encryption).
  3. Protect the backups first. Ransomware crews hunt backups. Disconnect external backup drives; verify your cloud/offsite copy hasn't been touched or deleted; change backup-console passwords from a clean device.
  4. Start an incident log — time, what you saw, what you did. Your insurer and (possibly) lawyers will need it.
  5. Call your cyber insurer's 24-hour hotline before anything else public. Most policies require it, and they bring negotiators and forensics you don't have to pay for separately.
  6. Do not email about it from affected systems — assume the attacker reads that mailbox. Use phones/personal devices.
  7. Photograph the ransom note (phone camera). Don't click its links, don't reply yet, and don't delete anything.
  8. Don't pay reflexively. Check nomoreransom.org for free decryptors; the pay/don't-pay call comes later, with your insurer, from a decision framework — not from panic.

The mistakes that make it worse

This checklist is 1 of 10 runbooks.

The full IncidentReady pack covers ransomware end-to-end (containment → insurer → rebuild order → the ransom-decision framework) plus phishing/BEC, compromised accounts, breach notification, and a tabletop kit to rehearse it — written for businesses of 5–50 people. Editable, $29.

Get the pack — $29   Read the free phishing runbook →

Preparedness templates, not legal advice. © 2026 IncidentReady