Discovering ransomware is one of the worst moments a small business can have, and the instinct to act fast is right, but acting in the wrong order can make recovery slower or destroy evidence you'll want later. This is a time-ordered checklist, not a replacement for the full recovery guide, which covers the actual restore process in depth.
First 10 minutes: contain it
- Disconnect affected machines from the network immediately, Wi-Fi and Ethernet both. Don't shut them down yet; powering off can destroy evidence useful for understanding what happened.
- Don't try to "clean" files or run removal tools yet. That can overwrite evidence and, in some cases, make files unrecoverable.
- Notify whoever owns IT or security decisions at your business right away, even if you're not fully sure yet what's happening.
First hour: assess scope, don't restore yet
- Identify which systems and shares are affected. Check unaffected systems too; ransomware often spreads before it's noticed.
- Do not pay the ransom, and don't negotiate with an attacker on your own without guidance; involve law enforcement or a security professional in that decision if it comes up.
- Start a simple written timeline: when it was noticed, what's affected, and what actions have been taken. This becomes useful for both recovery and any required incident reporting.
- If you're on Recovery Ready, contact the priority recovery hotline now; a specialist can help plan the restore alongside you rather than after the fact.
Next 24 hours: plan the actual recovery
- Determine how far back you need to roll: version history lets you restore to a point before the attack. See the ransomware recovery guide for how to identify a clean recovery point.
- Rebuild or clean affected machines before restoring data onto them.
- Restore in a controlled order, critical systems first, verifying each one before moving to the next rather than restoring everything at once.
- Change credentials for any accounts that may have been exposed, not just the ones on the affected machines.
After it's resolved: don't skip the review
Once systems are back up, take the time to understand how the attack got in, whether it was phishing, an exposed remote access point, or something else, and close that gap. If you run quarterly recovery drills, this is also worth feeding back into your next one; see running a recovery drill without disrupting your team.
| Timeframe | Priority |
|---|---|
| First 10 minutes | Contain: disconnect affected systems, don't run cleanup tools yet |
| First hour | Assess scope, don't pay, start a timeline, call for help if you're on Recovery Ready |
| Next 24 hours | Identify a clean recovery point, rebuild before restoring, restore in order |
| After | Root-cause review, credential rotation, feed lessons into your next drill |
Want a plan in place before you need one?
Recovery Ready includes version history, a priority hotline, and tested drills. Tell us about your setup in the questionnaire.
Get your quote