Disconnect affected computers from the network and Wi-Fi, but leave them powered on and don't wipe anything. Call your IT provider and your cyber insurance carrier before you respond to the attacker.
In the first hour
- Unplug network cables and turn off Wi-Fi on affected machines
- Leave the machines powered on, because evidence in memory can help the investigation
- Don't delete files or reinstall anything yet
- Take a photo of the ransom note and any on-screen message
- Tell staff not to open shared drives until you know how far it has spread
Who to call
Call your IT provider and your cyber insurance carrier first. Many policies require you to notify the insurer before you spend money or contact the attacker, and they may assign an incident response firm.
You can also report the attack to the FBI's Internet Crime Complaint Center. Whether to pay is a decision to make with your insurer and legal counsel, not in a hurry.
Restoring safely
Restore only from backups you know are clean, and only after you know how the attacker got in. Restoring too early can put the same infection back.
Then change every password, starting with email and administrator accounts, and turn on multi-factor authentication.
Before it happens
Recovery goes well when three things are already in place: backups kept apart from the office network, a separate backup of Microsoft 365, and a standby copy of your servers to work from while the originals are cleaned up.
Take the two-minute IT health check to see where your own setup stands, or read more answers.
