Your screen shows a ransom note demanding bitcoin. Files won't open. Employees are calling you. What you do in the next 60 minutes determines whether this costs you a weekend or your business. Here's the playbook we use when Miami clients call us at 2am.
Step 1: Unplug network cables (right now)
The single most important action: physically disconnect the affected machines from the network. Yank the ethernet cable, turn off the Wi-Fi. This stops the malware from spreading to other machines, file shares, and backups. Do NOT turn off the computer — some forensic evidence is in volatile memory.
Step 2: Take photos of the ransom note
Use your phone. Photograph:
- The ransom screen with the wallet address
- Any file extensions on encrypted files (e.g., .locky, .conti, .lockbit) — these tell us which strain
- The Bitcoin amount demanded
- The countdown timer if any
Step 3: Call us, not the FBI yet
Counter-intuitive but: call your incident response team first. We can be on a call within 15 minutes, on-site within 90, and we know which strains have free decryptors (some do). Once we have a handle on the situation, we'll help you decide whether/when to involve law enforcement, your insurance, and your customers.
Our 24/7 emergency line: (786) 422-0705
Step 4: Do NOT
- Do not pay the ransom immediately. Many strains have free decryption tools available. Paying funds the criminal economy and only 65% of payers get their data back.
- Do not restart the affected machines. Volatile memory may contain the encryption key.
- Do not delete the ransom note. It identifies the strain.
- Do not tell employees on Slack/Teams. Assume the attacker is listening; use phone calls and text only.
- Do not negotiate directly with the attacker. Use a professional negotiator if it comes to that.
Step 5: Inventory what you can
Make a list of:
- Machines affected vs unaffected
- What server shares were mounted
- When you last verified backups worked
- Customer/regulatory data potentially exposed (HIPAA, PCI-DSS, etc.)
What we do when we arrive
- Identify the ransomware strain and check for a free decryptor
- Determine the entry point (was it phishing, RDP, an exposed VPN?)
- Isolate and image affected machines for forensics
- Validate the backups are clean and restorable
- Restore from the last clean backup, not from infected machines
- Harden the network so reinfection doesn't happen Monday morning
- Help you with breach notification if regulated data was exposed
Average recovery time
- With current, tested backups: 24-48 hours
- With backups but never tested: 3-5 days
- No backups: a week or more, with significant data loss
That's why we test backups monthly for managed clients.
Right now: if you're reading this because you're under attack, call (786) 422-0705. We'll be on a video call within 15 minutes. If you're reading this proactively, take our free Ransomware Risk Score to see how vulnerable you'd be.