Security — The first hour after ransomware hits a small company
Photo: NOIRLab/NSF/AURA/T. Slovinský, CC BY 4.0
Security

The first hour after ransomware hits a small company

Ransomware locks your files or systems until a ransom is paid. What you do in the first hour decides how bad the rest of the week will be. This is the order of steps, not a list to work through in any order you like.

Stay calm and write things down

Don't try to fix anything yet. Get a notebook (pen and paper, not a shared drive) and write down the time you noticed the problem, which machines are affected, and what's on the screen: error messages, a ransom note, anything unusual.

Don't delete files or try to "clean" a machine yourself. Anything you do on an infected computer can destroy evidence and make recovery harder for whoever handles this next.

Isolate the infected machines

The goal right now is to stop it spreading. Unplug the network cable or turn off Wi-Fi on every affected machine. If you can't isolate a machine that way, turn it off completely as the fallback.

Don't reboot machines unless you need to in order to isolate them. Some ransomware is built to do more damage on restart.

Get the right people involved

Tell your IT provider or security contact and the person in charge, straight away. Agree who is making decisions and who is talking to staff, so people aren't given conflicting instructions while the technical work happens.

Do not contact the attackers and do not pay before you've had legal and technical advice. Use a phone or a computer that isn't on the office network to talk to anyone outside the building, in case the network itself isn't safe to use yet.

Check your backups before you touch anything

Confirm your backups aren't reachable from the infected machines. If they are, treat them as possibly compromised too, and don't start restoring until someone qualified has confirmed the backup files are clean.

While you wait for the restore to begin, work out which systems (payroll, customer records, stock) are actually affected, and change the passwords on your most important accounts, email, banking, cloud storage, from a device you know is clean.

Before you go back online

Find out how the attacker got in and close that hole before restoring anything. Restoring your data onto the same weak password or unpatched software just invites a second attack.

Get advice on whether you have any legal duty to notify customers or an authority, since that depends on what was affected and where you operate.

The best time to write an incident response plan is now, before the next attack, so everyone already knows who to call and what to do in the first hour.

Get started

Have a problem
nobody can solve?

Tell us what you're trying to build or automate.We'll scope it and get it shipped.