What to Do If Ransomware Hits Your Small Business

Posted by:

|

On:

|

Small-Business Security Guide

Practical first steps when ransomware is suspected

Ransomware is a business interruption, not just a computer problem. A calm, documented response can protect more systems, preserve recovery options, and help your team make better decisions.

If files suddenly cannot be opened, a ransom note appears, or several users report the same unusual behavior, act promptly. Do not assume a single reboot will fix it, and do not rush into payment or cleanup before you know what happened.

The best response starts before ransomware strikes

No single product can guarantee protection, but the damage from ransomware is far easier to limit when basic safeguards and a recovery plan are already in place. The goal is to prevent common entry points, limit spread if something gets through, and recover without relying on an attacker.

  • Multi-factor authentication, strong account controls, and limited administrator access
  • Managed security updates and endpoint protection for computers and servers
  • Tested backups with a protected copy that ransomware cannot easily reach
  • Network and access controls that reduce unnecessary exposure
  • A simple incident-response plan: who to call, how to isolate systems, and how to communicate

The first hour: contain and document

  1. Disconnect affected devices from the network by unplugging Ethernet or turning off Wi-Fi. Do not reconnect them until they have been reviewed.
  2. Leave the device powered on unless your IT or incident-response provider tells you otherwise; running systems can contain useful evidence.
  3. Record what you see: screenshots or photos of the note, the time, affected systems, and any user activity before the incident.
  4. Contact your IT provider, cyber insurer, and appropriate leadership using known contact information—not addresses or numbers supplied in a ransom note.

Protect what may still be safe

Ransomware can spread through shared folders, saved passwords, remote-access tools, and compromised accounts. Your response should include a controlled review of servers, workstations, Microsoft 365 accounts, network equipment, and backup systems. Do not attach backup drives or start broad restores until the scope is understood.

Do not destroy the evidence

A wiped device or deleted ransom note can make it harder to determine how the incident started and which information was affected. Preserve relevant messages, ransom notes, filenames, and timestamps. Your IT provider, insurer, legal counsel, or incident-response team may need them for technical recovery, reporting, or claim requirements.

Assess the business impact

Make a short list of the services the business cannot operate without: email, accounting, line-of-business software, file shares, phones, customer records, and payment systems. This helps prioritize recovery and provides a clear update for staff, clients, and vendors if communication is needed.

Recovery is more than restoring files

Good backups are valuable, but successful recovery also requires confirming that restored systems are clean, accounts are secure, and the original access path has been closed. Restoring data too early can reintroduce the problem. A methodical recovery plan should include password and MFA review, security updates, endpoint review, validation of backups, and staged restoration.

About ransom demands

Do not make a payment decision in isolation or under time pressure. Payment does not guarantee data recovery, deletion of copied data, or that the attacker will not return. Involve your cyber insurer, legal counsel, and qualified response professionals so that business, legal, and technical factors are considered together.

Need help assessing the situation?

RD Computer Solutions helps South Sound small businesses evaluate affected systems, Microsoft 365 accounts, backups, and practical recovery priorities.

Contact RD Computer Solutions

Frequently asked questions

Should we shut down every computer?

Disconnect affected systems quickly, then get guidance before taking broad action. Shutting down or rebooting every system without a plan can make investigation and recovery harder.

Can we restore from backup immediately?

First confirm that backups are intact and that the environment is safe to restore into. A response plan should prevent the same compromise from affecting restored systems.

Will antivirus alone prevent ransomware?

Security software is important, but it works best alongside managed updates, multi-factor authentication, limited access, tested backups, user awareness, and a practiced response plan.

Posted by

in

Leave a Reply

Your email address will not be published. Required fields are marked *