Ransomware

A ransomware recovery plan you can write this week.

The businesses that recover fastest aren’t the ones with the most expensive tools. They’re the ones that decided in advance who does what. Here’s a one-page plan, built on CISA’s guidance.

Built on CISA’s guidance One page, written in advance Veteran-owned, founder-led since 2020

The hard part

Why plans get skipped

Deciding who to call is hardest when every screen is showing a ransom note.

  1. What it costs you

    Every hour of confusion is an hour the business isn’t running.

  2. What it feels like

    It feels like something that happens to bigger companies.

  3. Why it shouldn’t be this way

    A useful plan fits on one page and takes an afternoon to write.

Before it happens

Prepare these now

  1. Backups an attacker can’t reach.

    Keep a copy separated from your network, and test a restore on a schedule.

  2. MFA on everything important.

    Email, remote access and admin accounts first.

  3. A printed contact list.

    Your insurer’s claims line, your IT partner, your bank and key staff. On paper, because your computers may not be available.

  4. One person who decides.

    Name who makes the calls, and who stands in if they’re away.

The first hour

Right now, whatever the hour

  1. Right away

    Disconnect affected computers from the network. Don’t turn them off, and don’t wipe anything.

    Why Stops the spread and keeps the evidence.

  2. Right away

    Call your insurer’s claims line.

    Why Many policies require prompt notice and name the responders you can use.

  3. Next

    Call your IT partner.

    Why To start containment and check your backups.

  4. Next

    Report it to the FBI at ic3.gov.

    Why CISA and the FBI recommend reporting, and it can help recovery.

  5. Before paying anything

    Talk to your insurer and responders.

    Why Paying doesn’t guarantee your data back.

This follows CISA’s Ransomware Response Checklist and #StopRansomware Guide.

After the first hour

Getting back to work

Restore from a backup you know is clean. Reset passwords, starting with admin accounts. Find out how the attacker got in and close that gap before bringing everything back online, or it can happen again.

Who we are

Where we fit

During business hours, we contain the damage, restore from tested backups and close the gap that let the attacker in. Before any of that is needed, we set up the backups, MFA and plan that make recovery possible.

Backups that restore

Separated and tested on a schedule.

A plan on paper

Written with you, kept current.

Containment

Stopping the spread first.

The gap closed

So it doesn’t happen twice.

Where to start

Where to start

The choice is yours.

What success looks like

A bad day, not a lost month.

Because you decided in advance.

  • Everyone knows who to call.
  • The backups are tested and out of reach.
  • The business is back to work quickly.

Questions about ransomware

What should we do first if we’re hit by ransomware?

Disconnect affected computers from the network without turning them off, then call your insurer.

Should we pay the ransom?

Talk to your insurer and responders first. Paying doesn’t guarantee your data back, and CISA and the FBI advise against it.

Do we need to report it?

CISA and the FBI recommend reporting at ic3.gov.

Will our backups save us?

Only if the attacker can’t reach them and a restore has been tested.

What’s in a ransomware plan?

Who decides, who you call, where your backups are, and what to do in the first hour.

Can you help after hours?

Our hours are Mon–Fri, 8 to 5 Mountain, and your insurer’s responders are the first call at any hour. Clients’ response commitments are written into their agreement.

Want a plan you can print?

Book a free IT risk review and we’ll check your backups and help you write the one page. Or start with a few questions about your tech.