August 12, 2026
Ransomware Response for Small Business: First 24 Hours

A ransomware note on an employee’s screen is not the time to start deciding who is responsible. Ransomware response for small business depends on fast, calm decisions made in the first few hours - and on knowing who will investigate the threat while your team keeps the business moving.
The immediate goal is not to fix every affected computer. It is to stop the attack from spreading, protect evidence, preserve recovery options, and communicate clearly. A rushed response can make a contained incident far worse. For example, reconnecting a device too soon, deleting suspicious files, or restoring data before the attacker is removed can give ransomware another path into your environment.
The first rule: isolate, do not investigate alone
If a computer displays a ransom note, suddenly cannot open files, shows unfamiliar file extensions, or triggers suspicious security alerts, disconnect it from the network immediately. Unplug the network cable or turn off Wi-Fi. Do not turn the computer back on and off repeatedly, and do not let the employee keep working from it.
Isolation limits the ransomware’s ability to reach shared folders, connected drives, other endpoints, and cloud-synced files. It also gives a security professional a better chance to determine what happened without losing useful evidence.
If the affected device is a server, shared workstation, or computer used for accounting, scheduling, or line-of-business applications, the decision may affect more people. That is why an incident plan should identify who can authorize isolation and who contacts your IT provider, security provider, leadership team, and insurance carrier.
Do not assume one visible ransom note means only one computer is involved. Ransomware operators often gain access, move through an environment, disable defenses, and steal data before encryption begins. The device that shows the note may be the first sign you see, not the first device affected.
What ransomware response for small business should look like
A useful response is an operational process, not a document that sits in a folder. It needs clear ownership from detection through recovery.
1. Confirm the scope
Security professionals should review endpoint activity, user accounts, remote access tools, file activity, and signs of lateral movement. They need to answer practical questions: Which devices are affected? Is the attacker still active? Were administrative credentials used? Are shared files or backups at risk? Was data likely copied out of the business?
This is where standalone antivirus can fall short. A product may block a known file or display an alert, but an alert does not tell you whether the threat is contained. Someone still has to investigate what happened and decide what action comes next.
2. Contain the threat
Containment may include isolating additional endpoints, disabling compromised user accounts, revoking active sessions, blocking malicious connections, and restricting access to shared resources. The exact actions depend on the incident.
There are trade-offs. Shutting down every system may limit spread, but it can also disrupt operations and destroy volatile evidence. Leaving everything connected may preserve access for investigators, but it can expose more systems. A managed security team can make those decisions based on observed activity rather than panic.
3. Preserve evidence and document decisions
Keep a timeline from the moment the issue is reported. Record who noticed it, when the affected device was isolated, what messages appeared, what accounts were involved, and every action taken afterward. Save screenshots of ransom notes and suspicious emails if they are available.
Avoid wiping devices or deleting files until the threat has been assessed. Those actions can remove evidence needed for forensic review, insurance reporting, legal advice, or law enforcement engagement. Your cyber insurance policy may also require specific notification steps before recovery work begins.
4. Notify the right people early
An incident is easier to manage when communication has an owner. Your response plan should name a business decision-maker, a technical contact, an outside IT provider if you have one, a managed security provider, and your insurance contact.
Employees need simple instructions, not speculation. Tell them which systems are unavailable, where to report suspicious activity, and whether they should use alternate communication methods. Ask them not to forward ransom notes, plug in external drives, or attempt their own fixes.
Customers and partners may need notification if services are interrupted or sensitive information may have been exposed. The timing and wording depend on the facts, contractual obligations, and legal guidance. Be accurate. Do not promise a recovery date until the scope is understood.
5. Eradicate before restoring
Restoring files is not the same as removing an attacker. Before bringing systems back online, investigators should identify the likely entry point and close it. Common paths include stolen passwords, exposed remote access, unpatched software, malicious email attachments, and compromised administrator accounts.
Remediation can involve resetting credentials, enforcing multifactor authentication, removing persistence mechanisms, patching systems, rebuilding compromised devices, and reviewing access permissions. If the attacker used a privileged account, assume that account and any systems it could access need close review.
Only restore from backups that are known to be clean and available. Test the restore process before relying on it during an emergency. Backups should be protected from ordinary user credentials and, where possible, kept separate from the primary environment. A backup that ransomware can encrypt or delete is not a recovery plan.
Should a small business pay the ransom?
There is no universal answer, and the decision should not be made by the person who first sees the ransom note. Payment does not guarantee that you will receive a working decryption tool, that all files will be recovered, or that stolen data will be deleted. It can also create legal, insurance, and reputational considerations.
The better question is whether the business can restore safely, how long recovery will take, whether data was exfiltrated, and what advice your insurer and legal counsel provide. Even when payment is considered, containment and investigation still matter. Paying without removing the attacker’s access can lead to another incident.
Build the response before you need it
The strongest ransomware response begins long before an employee reports encrypted files. Small businesses do not need an enterprise security operations center, but they do need a defined chain of action.
Start by making sure every endpoint is covered by professionally managed endpoint detection and response. Detection matters, but so does having security professionals who actively investigate alerts, isolate confirmed threats, and follow through on remediation. PC Vax provides that focused security layer while allowing clients to keep their existing IT provider for help desk, applications, networks, and broader technology support.
Patch management also deserves attention. Ransomware groups frequently exploit known weaknesses that were never corrected. Keeping operating systems and common applications current reduces the number of easy entry points, though patching alone will not stop attacks based on stolen credentials or convincing phishing messages.
Your plan should also cover multifactor authentication, protected backups, employee awareness training, asset inventory, and access controls. For cyber insurance, these controls are increasingly part of the application and renewal conversation. More importantly, they give your business more recovery options when an incident occurs.
A simple tabletop exercise reveals gaps
Set aside 30 minutes with the people who would handle an incident. Ask one question: an employee reports a ransom note at 10:15 a.m. What happens next?
Walk through who isolates the computer, who checks other systems, who contacts security and IT support, who calls the insurer, and who communicates with employees. Then ask what happens if the affected employee is an administrator, a shared drive is unavailable, or the backup cannot be restored immediately.
The purpose is not to predict every attack. It is to find unanswered questions while the business is calm. A clear response plan, tested backups, current systems, and people who are accountable for security turn a frightening event into a problem your business can work through.
PC Vax provides cybersecurity services, not insurance or legal advice. Cyber insurance requirements and incident obligations vary by carrier, policy, and applicant, and PC Vax does not guarantee insurance eligibility, approval, coverage, or premiums.
Professional Cybersecurity. Made Simple.