What to do after a ransomware attack, in order: disconnect affected machines from the network without powering them off, stop all backups from overwriting clean copies, call your cyber insurer's hotline and an incident response team, preserve the ransom note and logs, and only then assess what can be restored. The first day decides whether you recover in days or weeks, and the most damaging mistakes are the fast, instinctive ones: wiping machines, rebooting servers, paying before understanding the situation.
We have walked Treasure Coast businesses through this morning more than once. What follows is the sequence we use, written for the owner or office manager who is staring at a locked screen right now. If that is you, call (772) 794-1194 and keep reading while you wait.
Hour 0 to 1: contain without destroying evidence
- Isolate, do not shut down. Unplug network cables and turn off Wi-Fi on affected computers and servers. Do not power them off; memory contains evidence and encryption keys investigators may need. If you cannot tell which machines are affected, disconnect the office from the internet at the firewall.
- Stop backups and sync. Pause backup jobs, OneDrive and Dropbox sync, and replication so encrypted files do not overwrite the last good copies. This single step saves more businesses than any other.
- Disable remote access at the firewall: VPN, remote desktop, vendor portals. Attackers usually still have a way in.
- Change key passwords from a clean device: domain admin, Microsoft 365 global admin, firewall, backup console, banking. Revoke active sessions.
- Photograph the ransom note and any screens. Do not click links in it yet.
- Tell staff to stop using computers, not to restart anything, and not to discuss the event publicly.
Hour 1 to 4: get the right people on the phone
- Your cyber insurer. Most policies require notification within hours and provide a breach hotline that brings in approved incident responders, forensic firms and legal counsel, often at no cost above the deductible. Using unapproved vendors can void coverage, so call before you hire anyone.
- An incident response team. If you have a managed IT provider, they should already be moving. If not, engage a firm that does this for a living. Our incident response service handles containment, forensics coordination and recovery for businesses across the Treasure Coast.
- Legal counsel with breach experience. Notification obligations under Florida law, HIPAA and other regulations start ticking from discovery, and counsel keeps the investigation privileged.
- Law enforcement. Report to the FBI through its cybercrime channel. It rarely gets data back, but it is expected by insurers and regulators and sometimes provides decryption help.
- Your bank if any financial systems or email accounts used for payments were involved. Business email compromise often precedes ransomware.
Hour 4 to 12: understand the scope
With responders engaged, the work shifts to finding out what happened and what survived.
- Identify the strain. The ransom note and file extensions usually identify the ransomware family, which tells responders whether decryption tools exist and whether data theft is typical for that group.
- Map what is encrypted versus untouched: servers, workstations, cloud files, network storage, and any backups that were reachable from the network.
- Assess backups honestly. Are the offsite or immutable copies intact? What is the most recent clean restore point? How long will a full restore take? This is the moment businesses discover that their backup was a USB drive plugged into the encrypted server.
- Look for data theft. Modern attacks usually steal data before encrypting. Logs from the firewall and cloud services show large outbound transfers. This determines notification obligations.
- Find the entry point. A phished password without MFA, an exposed remote desktop port, an unpatched firewall or a compromised vendor account. Recovery that does not close the door leads to a second attack.
Hour 12 to 24: decide and start recovery
Should you pay the ransom?
It is a business decision made with counsel and the insurer, not an IT one, and there are honest reasons some businesses pay. But consider: payment does not guarantee working decryption, does not retrieve stolen data, may be illegal if the group is sanctioned, and marks you as a payer. If clean backups exist, restoration is almost always faster and cheaper than negotiation. Never contact the attackers yourself; negotiators exist for a reason.
Rebuild, do not clean
Infected machines should be wiped and reinstalled from known-good media, not cleaned. Servers are restored from clean backups onto rebuilt systems. Restore order matters: identity (domain controller or Microsoft 365) first, then core line-of-business systems, then file servers, then workstations.
Keep the business running
Forward phones, switch to paper processes where you can, and communicate with customers and patients through counsel-approved messaging. A medical office can see patients with paper charts for a few days; it cannot if nobody planned for it.
What mistakes destroy your recovery options?
- Powering off or rebooting servers, which can corrupt partially encrypted files and erase evidence
- Letting backup jobs run and overwrite clean copies with encrypted data
- Wiping machines before forensics captures the entry point
- Restoring onto the same compromised network without closing the hole
- Emailing the attackers from a company account
- Delaying the insurance call past the policy window
- Announcing the incident publicly before counsel reviews obligations
What happens after the first day?
Recovery typically runs days to weeks depending on backup quality. Afterward comes the part that prevents a repeat: MFA everywhere, EDR with 24x7 monitoring, immutable offsite backups, patching, and a written incident response plan you rehearse. Our backup and disaster recovery service exists because clean, tested backups are the difference between a bad week and a closed business.
If you are dealing with an active incident, or you want a plan in place before one, MainSail Data is available 24x7x365 at (772) 794-1194. For a calmer conversation, request a free security assessment and we will test your readiness before an attacker does.

