Ransomware on screen, the server down, or a director's email account sending out invoices no one recognises - in the first hour, what you do (and don't do) has a real effect on how bad the outcome ends up being.
Do This First
- Isolate, don't shut down. If a machine is showing signs of ransomware or active compromise, disconnect it from the network (unplug the cable, turn off WiFi) rather than powering it off. Shutting down can sometimes erase evidence or memory-resident indicators that matter for recovery.
- Stop the spread. Disconnect other obviously affected machines from the network too, particularly anything on the same switch or subnet as the first sign of trouble.
- Call for help immediately - don't wait to "see if it gets worse." The gap between detection and response is the single biggest factor in how much damage ransomware or a compromised account causes.
- Preserve what you can. Take photos of ransom notes or error screens with your phone before anyone touches the keyboard again. Don't reboot a system that's actively showing signs of compromise.
Don't Do This
- Don't pay a ransom demand on the spot. There's no guarantee of decryption, and payment doesn't resolve how the attacker got in. Get advice first.
- Don't try to "fix it quietly" without telling anyone. Especially with a compromised email account - the longer it goes unreported, the more damage (fraudulent invoices, data exposure) it can cause.
- Don't restore from backup before assessing scope. If you don't know how the attacker got in, restoring blindly can mean they simply get back in the same way.
- Don't assume it's contained. What looks like one affected machine is often wider than it first appears - proper assessment matters before declaring it resolved.
Who to Call, and in What Order
- Your IT provider or internal IT team - for technical containment and assessment, immediately.
- Your bank - if any payment has already been made or redirected as part of a Business Email Compromise incident, speed matters here more than almost anything else.
- Your cyber insurer, if you have a policy - many require notification within a specific window, and some mandate using their panel of incident response providers.
- ReportCyber - for a formal record, which can matter for insurance claims and law enforcement follow-up.
Why Having a Plan Before It Happens Matters
Every one of these steps is far easier to execute calmly when it's already written down somewhere, rather than being figured out in the moment under pressure. Running a simple incident response drill in advance is what turns this from a panicked scramble into a process your team already knows how to follow.
Where to Start
If you don't currently have a documented incident response process, or you're not sure who on your team would know what to do in the first ten minutes of an outage or attack, that's the gap worth closing before you need it.
Frequently Asked Questions
Should I shut down a computer showing signs of ransomware?
No, disconnect it from the network instead of powering it off. Unplugging the network cable or turning off WiFi stops the spread while preserving evidence that a full shutdown can sometimes destroy, which matters for both recovery and any later investigation.
Should we pay the ransom if we get hit?
Not on the spot, and not without advice first. There's no guarantee paying gets your data back, and it does nothing to fix how the attacker got in, so getting proper guidance before making that call matters more than acting fast for the sake of it.
Is it okay to restore from backup straight away after an incident?
Not before the scope of the incident is understood. If you don't know how the attacker got in and restore blindly, there's a real risk they simply get back in the same way, so a proper assessment should come before a full restore.
Do we need to notify our cyber insurer during the first hour?
It's worth checking your policy as part of your incident response plan, since many insurers require notification within a specific window and some require you to use their approved incident response providers. This is worth confirming directly with your insurer or broker ahead of time, not figured out mid-incident.
We provide priority emergency IT support for Perth businesses - ransomware, outages, and compromised accounts.
Emergency IT Support →In the middle of an IT emergency right now?
Call 0433 087 091 immediately for priority response.
Get Help Now