Ransomware
A ransomware recovery plan you can write this week.
The businesses that recover fastest aren’t the ones with the most expensive tools. They’re the ones that decided in advance who does what. Here’s a one-page plan, built on CISA’s guidance.
The hard part
Why plans get skipped
Deciding who to call is hardest when every screen is showing a ransom note.
-
What it costs you
Every hour of confusion is an hour the business isn’t running.
-
What it feels like
It feels like something that happens to bigger companies.
-
Why it shouldn’t be this way
A useful plan fits on one page and takes an afternoon to write.
Before it happens
Prepare these now
-
Backups an attacker can’t reach.
Keep a copy separated from your network, and test a restore on a schedule.
-
MFA on everything important.
Email, remote access and admin accounts first.
-
A printed contact list.
Your insurer’s claims line, your IT partner, your bank and key staff. On paper, because your computers may not be available.
-
One person who decides.
Name who makes the calls, and who stands in if they’re away.
The first hour
Right now, whatever the hour
-
Right away
Disconnect affected computers from the network. Don’t turn them off, and don’t wipe anything.
Why Stops the spread and keeps the evidence.
-
Right away
Call your insurer’s claims line.
Why Many policies require prompt notice and name the responders you can use.
-
Next
Call your IT partner.
Why To start containment and check your backups.
-
Next
Report it to the FBI at ic3.gov.
Why CISA and the FBI recommend reporting, and it can help recovery.
-
Before paying anything
Talk to your insurer and responders.
Why Paying doesn’t guarantee your data back.
This follows CISA’s Ransomware Response Checklist and #StopRansomware Guide.
After the first hour
Getting back to work
Restore from a backup you know is clean. Reset passwords, starting with admin accounts. Find out how the attacker got in and close that gap before bringing everything back online, or it can happen again.
Who we are
Where we fit
During business hours, we contain the damage, restore from tested backups and close the gap that let the attacker in. Before any of that is needed, we set up the backups, MFA and plan that make recovery possible.
Backups that restore
Separated and tested on a schedule.
A plan on paper
Written with you, kept current.
Containment
Stopping the spread first.
The gap closed
So it doesn’t happen twice.
Where to start
Where to start
The choice is yours.
- Want your backups checked and the plan written with you? Book my free IT risk review →
- A team of 15 to 70 who want IT fully handled. Our Fully Managed IT Support Program →
- A small team, mostly in the cloud. IT Essentials →
What success looks like
A bad day, not a lost month.
Because you decided in advance.
- Everyone knows who to call.
- The backups are tested and out of reach.
- The business is back to work quickly.
Questions about ransomware
What should we do first if we’re hit by ransomware?
Disconnect affected computers from the network without turning them off, then call your insurer.
Should we pay the ransom?
Talk to your insurer and responders first. Paying doesn’t guarantee your data back, and CISA and the FBI advise against it.
Do we need to report it?
CISA and the FBI recommend reporting at ic3.gov.
Will our backups save us?
Only if the attacker can’t reach them and a restore has been tested.
What’s in a ransomware plan?
Who decides, who you call, where your backups are, and what to do in the first hour.
Can you help after hours?
Our hours are Mon–Fri, 8 to 5 Mountain, and your insurer’s responders are the first call at any hour. Clients’ response commitments are written into their agreement.
Want a plan you can print?
Book a free IT risk review and we’ll check your backups and help you write the one page. Or start with a few questions about your tech.