If you're reading this right now because your business just got hit with ransomware, take a breath. I know this is one of the worst moments you'll experience as a business owner. But panicking makes it worse, and every minute counts.
I'm going to walk you through exactly what to do in the first 24 hours. Step by step. No fluff. If you need immediate help, call us at (404) 990-4540 right now. We help businesses across Lawrenceville, Gwinnett County, and metro Atlanta recover from ransomware attacks.
If you're reading this proactively to prepare, even better. Having a ransomware recovery plan before you need one is worth its weight in gold.
You've Been Hit. Now What?
You see the screen. There's a ransom note demanding payment in cryptocurrency. Files are encrypted. Maybe your whole network is locked down. Here's what you do right now:
1. Disconnect the infected machine from the network immediately. Unplug the ethernet cable. Turn off Wi-Fi. If it's a laptop, put it in airplane mode. Do NOT turn off the computer. There may be forensic evidence in memory that you'll need later.
2. Do not pay the ransom. I know it's tempting, especially when you see that timer counting down. But the FBI and CISA both strongly advise against paying. Only about 8% of businesses that pay actually get all their data back. And paying marks you as a target for future attacks.
3. Document everything. Take photos of the ransom note with your phone. Write down the exact time you noticed the attack. Note which systems are affected and which seem fine. This information will be critical for your IT team, law enforcement, and your insurance company.
4. Call your IT provider. If you have a managed IT services provider, call them immediately. If you don't have one, call an incident response team. This is not a DIY situation.
The First 24 Hours: Hour by Hour
Here's what a structured ransomware recovery timeline looks like. The faster you move through these steps, the better your chances of a full recovery.
First Hour: Contain and Isolate
- Disconnect all infected devices from the network
- Isolate network segments if possible (disconnect switches, disable Wi-Fi access points)
- Disable remote access (VPN, RDP, remote desktop tools)
- Preserve the infected machines. Do not wipe, reboot, or run antivirus scans yet
- Contact your IT provider or incident response team
- Begin documenting: what was affected, when, and what actions were taken
Hours 1-4: Assess the Damage
- Determine which systems, files, and data are encrypted
- Check if the ransomware is still actively spreading
- Identify the ransomware variant (your IT team can often identify it from the ransom note or file extensions)
- Check if a free decryption tool exists (sites like No More Ransom have free decryptors for some variants)
- Verify the status of your backups. Are they intact? Are they also encrypted?
- Determine the entry point if possible (usually a phishing email, compromised RDP, or unpatched vulnerability)
Hours 4-12: Notify and Plan
- Notify leadership and key stakeholders
- Contact your cyber insurance provider (if you have a policy)
- File a report with the FBI's Internet Crime Complaint Center (IC3)
- Consult legal counsel, especially if client or employee data may be exposed
- Develop a recovery plan with your IT team: restore from backup, rebuild, or negotiate
- Set up a temporary communication channel (your email may be compromised)
Hours 12-24: Begin Recovery
- Start restoring systems from clean backups (if available and verified)
- Rebuild critical systems from scratch if backups aren't available
- Reset ALL passwords across the organization. Every single one
- Patch the vulnerability that allowed the attack
- Enable multi-factor authentication on everything
- Monitor for signs the attacker is still in your network
- Begin notifying affected clients or partners if required by law or contract
Who to Notify
This is the part people forget about in the chaos. But notifications are legally required in many cases, and delays can make things worse.
- FBI IC3 (ic3.gov). File a complaint. They track ransomware operations and sometimes recover ransom payments.
- Your cyber insurance carrier. Most policies require notification within 24-72 hours. Delaying could void your coverage.
- Legal counsel. You need to know your breach notification obligations under state and federal law. Georgia requires notification within a "reasonable" timeframe.
- Affected clients and partners. If personal data, financial data, or protected health information was exposed, you have a legal obligation to notify the affected individuals.
- Your bank. If the attackers had access to financial systems, alert your bank immediately to prevent unauthorized transfers.
- CISA (cisa.gov/stopransomware). They offer free resources and can sometimes assist with recovery.
Your notification obligations get stricter if you handle sensitive client data. We cover the specifics for two of the highest-risk fields in our law firm cybersecurity checklist and our insurance agency data security guide.
Recovery Options
Once you've contained the attack and assessed the damage, you have three paths forward. Here's the honest breakdown of each.
Option 1: Restore From Backup (Best Case)
If you have recent, tested, clean backups, this is your best option. A solid backup strategy is the single most important defense against ransomware.
The key word here is "tested." I've seen businesses that thought they had backups, only to find out the backups hadn't been running properly for months. Or the backups were stored on the same network and got encrypted too.
Recovery time: 24-72 hours for most small businesses with good backups.
Cost: Primarily your IT team's time. Minimal compared to the alternatives.
Option 2: Negotiate and Pay (Risky)
I don't recommend this, but I want to be honest about it. Some businesses end up paying because they have no backups, no other options, and the data is worth more than the ransom.
If you go this route, involve a professional negotiator (many cyber insurance policies cover this). Never negotiate directly with the attackers yourself.
The risks: No guarantee you'll get your data back. You're funding criminal activity. Attackers may leave backdoors for future attacks. The decryption tools they provide may not work properly, corrupting your data further.
Average ransom paid by small businesses: $50,000 to $200,000 according to recent industry reports.
Option 3: Rebuild From Scratch (Painful but Clean)
If you don't have backups and refuse to pay, you'll need to rebuild. This means wiping all affected systems, reinstalling operating systems and applications, and starting fresh.
Any data that wasn't backed up is gone. That's the hard truth.
Recovery time: 1-4 weeks depending on complexity.
Cost: Significant in labor and lost productivity, but you'll have a clean environment.
Need Help Right Now?
If you're dealing with a ransomware attack, call us at (404) 990-4540 or book a call. We help businesses across Gwinnett County and metro Atlanta respond to and recover from cyber attacks.
Get Emergency IT HelpHow Managed IT Services Help Prevent and Recover From Ransomware
Here's the thing: ransomware recovery is brutal. But ransomware prevention is straightforward. This is where having a managed cybersecurity provider makes all the difference.
A good managed IT provider does the work that prevents ransomware from getting in and limits the damage if it does:
- 24/7 endpoint monitoring. Ransomware often triggers alerts before files are encrypted. Catching it in the first minutes can stop the spread.
- Regular patching and updates. Many ransomware variants exploit known vulnerabilities that already have patches available. Staying current closes those doors.
- Email filtering and threat detection. Most ransomware starts with a phishing email. Advanced email filtering catches the majority of these before they reach your inbox.
- Backup management and testing. We don't just set up backups. We test them regularly to make sure they actually work when you need them. We wrote a full guide on building a backup strategy that covers the 3-2-1 rule and more.
- Incident response planning. Having a disaster recovery plan documented and tested before an attack means faster response and less chaos when it matters most.
- Dark web monitoring. Compromised credentials often show up on the dark web before they're used in an attack. Our free dark web scan can show you if your business email addresses have been exposed.
- Security awareness training. Your employees are your first line of defense. Training them to recognize phishing and social engineering dramatically reduces your risk.
The Real Cost of Ransomware
The ransom itself is just the tip of the iceberg. Here's what ransomware actually costs a small business, according to data from the Verizon Data Breach Investigations Report and other industry sources:
- Average ransom payment (SMBs): $50,000 - $200,000
- Average total recovery cost: $1.85 million (includes downtime, lost business, recovery labor, legal fees)
- Average downtime: 22 days
- Lost business: 60% of small businesses that experience a major cyber attack go out of business within 6 months
- Reputation damage: Hard to quantify, but clients and partners will think twice before trusting you with their data again
- Regulatory fines: If protected data was exposed and you didn't have proper safeguards in place, fines can be substantial
Compare those numbers to the cost of managed IT security. For a small business, managed cybersecurity typically runs a few hundred dollars per user per month. That includes monitoring, patching, email security, backup management, and incident response planning.
The math is pretty clear.
Ransomware Prevention Checklist
Whether you're recovering from an attack or want to make sure you never have to, here's what needs to be in place:
- Backup strategy. Follow the 3-2-1 rule: 3 copies of your data, on 2 different types of media, with 1 copy stored offsite or in the cloud. Test your restores monthly. Our data backup guide breaks this down in detail.
- Multi-factor authentication (MFA). Enable MFA on every account that supports it, especially email, VPN, and cloud services. This single step blocks the majority of credential-based attacks. Here's our complete MFA guide.
- Endpoint protection. Every device needs next-gen endpoint protection, not just basic antivirus. Look for EDR (Endpoint Detection and Response) capabilities.
- Email security. Advanced email filtering that scans attachments and URLs in real time. Most ransomware arrives through email.
- Patch management. Keep all operating systems, applications, and firmware up to date. Automate this so it doesn't depend on someone remembering to do it.
- Employee training. Run regular security awareness training and phishing simulations. Your team needs to recognize social engineering attempts.
- Network segmentation. Don't let one infected machine take down your entire network. Segment critical systems so ransomware can't spread freely.
- Incident response plan. Document who does what when an attack happens. Practice it. A disaster recovery plan that sits in a drawer is better than nothing, but one that's been tested is actually useful.
- Limit user privileges. Not everyone needs admin access. The principle of least privilege limits how much damage an attacker can do with a single compromised account.
- Dark web monitoring. Know when your credentials are compromised before the attackers use them. Run our free dark web scan to see if your business is exposed right now.
The Bottom Line
Ransomware is scary, and the first 24 hours after an attack are critical. But with the right steps, most businesses can recover. The best time to prepare was yesterday. The second best time is today.
If you're reading this because you're in crisis mode right now, call us at (404) 990-4540. We'll help you get through it.
If you're reading this proactively, good on you. Book a discovery call and let's make sure your business has the backups, monitoring, and incident response plan it needs so you never have to use the timeline above.