Discovering ransomware on your network is a gut-punch: files locked, a ransom note on the screen, and your business at a standstill. What you do in the first 24 hours has an enormous effect on how much you lose and how fast you recover. This is a practical, plain-English guide to those critical first hours, written for Boston business owners, not IT specialists.
First, Don’t Panic, and Don’t Pay Yet
Paying the ransom should never be the first move. It funds criminals, doesn’t guarantee you’ll get your data back, and may not even be legal depending on who the attacker is. The first priority is containment, not negotiation. Take a breath and work the steps below, ideally with your IT provider on the phone.
The First Hour: Contain the Spread
1. Isolate, don’t shut down
Disconnect affected devices from the network, unplug the ethernet cable, disable Wi-Fi, and isolate them. But avoid powering machines off if you can, since that can destroy forensic evidence and, in some cases, data still in memory that aids recovery. Disconnect, don’t wipe.
2. Stop it jumping to backups and cloud
Ransomware actively hunts for backups and connected cloud storage. Disconnect backup drives and, if possible, suspend sync to cloud file services so encrypted files don’t overwrite good copies.
3. Call your IT provider and start a log
This is what a managed IT partner is for. Get them engaged immediately. Start writing down what you see and when, the timeline matters for both recovery and insurance.
The First Few Hours: Assess and Notify
4. Call your cyber insurance carrier
If you have a cyber insurance policy, contact them early. Most have a 24/7 incident hotline and a panel of approved forensics and legal experts, and acting outside their process can jeopardize your claim.
5. Figure out the scope
Which systems are hit? What data is involved? Is it just files, or are servers and backups affected? This shapes every decision that follows.
6. Consider your legal and notification duties
If personal information was accessed, Massachusetts law (201 CMR 17.00 and the state breach-notification statute) and possibly HIPAA may require you to notify affected individuals and regulators. Loop in legal counsel, often coordinated through your insurer.
The First Day: Recovery Begins
With containment done and experts engaged, recovery focuses on eradicating the malware, confirming your backups are clean and uncompromised, and restoring systems in priority order. This is where having a tested disaster recovery plan pays off enormously, businesses that have rehearsed restores recover in hours or days; those that haven’t can be down for weeks.
The Best First 24 Hours Happen Before the Attack
The uncomfortable truth is that your outcome is mostly determined before ransomware ever hits, by whether you have offline, immutable backups, endpoint detection, MFA, and a written response plan. Prevention and preparation are dramatically cheaper than recovery. Our cybersecurity services are built to keep you out of this situation, and to get you out fast if it happens.
Be Ready Before You Need to Be
If you’re reading this during an active incident, disconnect affected devices and call for help now. If you’re reading it to prepare, that’s the smart move. Request a consultation and Boston Networks will assess your ransomware readiness and build the response plan you hope you never need.
