When ransomware or another serious cyber incident is suspected, the first few decisions matter. The goal is to limit further damage, preserve useful evidence, protect accounts and backups, and restore business operations in a controlled way.
This is not a substitute for legal, insurance, regulatory, or law-enforcement guidance. Every incident is different, and businesses with regulated data may have specific notification and preservation requirements. The steps below are a practical starting point for containing a suspected attack.
1. Disconnect affected computers from the network
If a workstation or server is actively encrypting files, showing a ransom note, or behaving suspiciously, isolate it from wired and wireless networks. Disconnecting network access can help prevent the device from reaching shared folders, other computers, or additional systems.
Do not immediately wipe or reinstall the machine. Depending on the incident, logs and other evidence may be important for determining what happened.
2. Do not assume only one computer is affected
Ransomware incidents can involve compromised accounts, remote-access tools, email, servers, cloud services, or multiple endpoints. If one machine shows obvious symptoms, other systems may still be compromised without displaying a ransom note.
Review authentication activity, administrative accounts, endpoint alerts, remote-management systems, email access, firewall logs, and other available telemetry.
3. Protect your backups before restoring anything
Backups are extremely important, but restoring too early can make recovery harder. First confirm that backup systems have not been altered, deleted, encrypted, or accessed by the attacker.
Keep known-good backup copies isolated until the environment is understood. If possible, preserve multiple recovery points rather than overwriting older backups during the incident.
4. Reset compromised credentials from a clean device
If account compromise is suspected, reset passwords using a device you believe is clean. Prioritize administrative accounts, email, remote access, cloud services, backup systems, domain administrators, and accounts with access to sensitive data.
Enable or enforce multi-factor authentication where available. Review active sessions and revoke sessions or tokens when the platform allows it.
5. Contact the right people early
Depending on the organization and the type of data involved, that may include your IT provider, cybersecurity provider, cyber-insurance carrier, attorney, executive leadership, law enforcement, or regulatory contacts.
Many cyber-insurance policies have specific incident-response requirements. Contacting the carrier before making major remediation decisions can help avoid conflicts with coverage requirements.
6. Preserve information about what happened
Document when the issue was first noticed, which systems were affected, what users observed, ransom-note details, suspicious emails, login alerts, file changes, and actions already taken. Preserve relevant logs where possible.
A clear timeline helps the response team understand the scope of the incident and prevents important details from being lost during a stressful recovery.
7. Determine the entry point and scope before rebuilding
Simply reinstalling the visibly affected computer does not fix the original weakness. The attacker may have entered through stolen credentials, exposed remote access, phishing, unpatched software, a vulnerable service, or another compromised system.
Before returning systems to production, identify and close the likely access path, review privileged accounts, update vulnerable systems, and verify security controls.
8. Restore in a controlled order
Recovery usually starts with the systems the organization needs most. Restore known-good infrastructure and data, validate it, monitor for suspicious behavior, and then reconnect additional systems in stages.
Do not reconnect everything at once just to get the office operating faster. A staged recovery makes it easier to detect a remaining compromised device or account.
How can a business reduce ransomware risk before an incident?
- Use managed endpoint protection and active threat monitoring.
- Require multi-factor authentication for important accounts.
- Keep operating systems and applications patched.
- Maintain tested backups with protected or offline recovery copies.
- Limit administrative privileges.
- Secure remote access and remove unused services.
- Train users to recognize suspicious email and login requests.
- Maintain current documentation for networks, systems, vendors, and recovery procedures.
Prepare before you need the plan
Incident response is much easier when the business already knows who to call, where backups are located, how accounts are protected, and which systems are most important.
CyberTek Solutions provides managed endpoint protection, network security, and managed IT support for organizations across Southern Tennessee. If you believe your business is currently experiencing a cyber incident, use our urgent support email or contact CyberTek.