We have ransomware, what do we do?
Disconnect the affected machines from the network and the internet, but leave them powered on so evidence survives. Do not pay anything yet. Work out what is encrypted, then check whether your backups are intact and offline. Call your cyber-insurance carrier before you hire anyone, and report it to the FBI at ic3.gov. Then call me at (214) 612-7080 and I will work the recovery with you.
Answered by Anthony Omini, Cross River Tech, Dallas

Key takeaways
- Isolate first: pull the network cable or turn off Wi-Fi on affected machines, and disconnect backup drives, but leave the machines powered on.
- Do not wipe, reimage or restore anything until you know how far it spread and your cyber-insurance carrier has been told.
- Your backups decide the outcome. Check that they exist, that they are offline or immutable, and that they predate the infection.
- Report the incident to the FBI's Internet Crime Complaint Center at ic3.gov, and involve your insurance carrier before you hire any responder.
- Paying is a last resort, not a shortcut: it funds the crime, it does not undo the data theft, and the decryption tools you get back are often slow and incomplete.
We have ransomware, what do we do right now?
Work through this list in order. Every step protects something the next step needs. This is general guidance for a small business, not incident-response advice tailored to your systems, and if you have a cyber-insurance policy its terms come before anything on this page.
- Isolate the affected machines from the network. Unplug the Ethernet cable. If the machine is on Wi-Fi, turn Wi-Fi off from the physical switch or from Airplane Mode. Do not do this by uninstalling software or changing firewall rules on the machine itself.
- Leave those machines powered on. A running machine holds evidence in memory, sometimes including encryption keys. Pulling the plug throws that away permanently. The exception is a machine you can see actively encrypting new files right now and cannot isolate any other way.
- Disconnect anything that holds a backup. USB drives, NAS boxes, external enclosures. Ransomware hunts for backups first, and an attached backup drive is just another folder to encrypt.
- Suspend cloud sync on the affected machines. OneDrive, SharePoint sync, Google Drive and Dropbox will happily replicate encrypted files up to the cloud and out to everybody else. Pause the client, or isolate the machine before it finishes.
- Stop everybody else from logging in. Tell staff not to touch shared drives and not to log in anywhere until you say so. A clean machine that mounts an infected share can become the next casualty.
- Take a photo of the ransom note with your phone. The note names the strain, the contact channel and the ID your insurer and any responder will ask for.
- Write down a timeline. Who noticed what, at what time, what they clicked, what they had open. Memory fades fast and this timeline saves hours later.
- Call your cyber-insurance carrier. Most policies require notice before you engage anyone. Calling a vendor first can void coverage.
- Report it to law enforcement. File with the FBI's Internet Crime Complaint Center at ic3.gov. It costs you nothing and it is often the first thing an insurer asks whether you did.
- Then check your backups, and only then plan the rebuild. Do not restore, wipe or reimage a single machine until the scope is understood.
Once those ten are done you are in control of the situation instead of reacting to it. Call me at (214) 612-7080 at any point in that list and I will work the rest of it with you on the phone.
Why should you isolate the machines instead of powering them down?
Because isolation stops the spread while powering down destroys the only evidence you have. Those two goals sound the same and are not.
Ransomware spreads across the network, not through the power cord. Unplugging the network cable cuts the spread instantly and completely. Once a machine is off the network it can encrypt only its own local disk, and whatever it has already done there is done.
What a hard shutdown costs you is memory. Some strains keep the encryption key in RAM. Some keep the running process, the command-and-control address and the staging folder there too. Investigators and, in some cases, free decryption tools depend on that. Once the machine is off, none of it comes back. A machine that is off also cannot be examined for how the attacker got in, which means you may rebuild straight into the same hole.
There is one honest exception. If you are standing in front of a machine watching file names change in real time and you cannot reach the network cable, cutting power is better than letting it finish. That is a judgment call about active damage, not a default.
The other thing to leave alone is the firewall and switch configuration. It is tempting to start pulling ports and changing rules. Do not: you will need to know what the network looked like at the moment of the incident, and you will need those devices reachable to rebuild in an orderly way.
How do you find out how far it spread?
Start from what people can and cannot open, and work outward. Scope is the difference between a one-day rebuild of one laptop and a full restore of every server and share you own.
Walk the office and check three things at each desk: can that person open a local document, can they open a file on the shared drive, and does their email still work. Then look at the file server and any NAS. Encrypted files usually have a new extension appended and there is a ransom note dropped into every folder the attacker touched. The pattern of where those notes appear tells you which accounts were used.
| What you are seeing | What it usually means | What that changes |
|---|---|---|
| One PC encrypted, shared drives fine | Local infection that did not have network rights, or was caught early | Rebuild that machine, restore its files, hunt for how it arrived |
| Shared drives encrypted, note in every folder | An account with write access to the share was used | Every device that account touched is suspect; reset that account first |
| Server encrypted and backups also encrypted | The attacker had administrator rights and went for backups deliberately | Assume a full rebuild; offline or immutable copies are now your only path |
| Files fine but a ransom note demanding payment for stolen data | Extortion without encryption, data was copied out | Restoring changes nothing; this is a disclosure and legal question first |
| Microsoft 365 files encrypted in SharePoint or OneDrive | An infected PC synced encrypted versions up | Version history may roll it back; stop sync everywhere before restoring |
| Nothing encrypted, just a scary pop-up in a browser | A scareware page, not ransomware | Close the browser, clear it, and treat it as a phishing incident instead |
That last row happens more often than people expect, and it is a relief when it does. If you are not sure which row you are in, take photos and send them to me rather than clicking anything on the note.
What do you check about your backups before anything else?
Check three things, in this order: that a backup exists, that it was not reachable from the infected network, and that it is older than the infection. A backup that fails any one of those is not a recovery plan.
- Does it exist at all, and where? A backup appliance in the same closet, a cloud backup service, a rotated USB drive in a drawer, a Microsoft 365 backup separate from Microsoft itself. Write down every candidate before you touch any of them.
- Was it online when this happened? A NAS with a mapped drive letter and a shared password is online, and attackers know it. A cloud backup with a separate login the domain admin does not hold, or an immutable copy the vendor will not let anyone delete, is the kind that survives.
- How old is the newest clean copy? Attackers often sit in a network quietly for a while before triggering encryption. The newest backup may already contain their tools. You may have to go back further than you would like.
- Has anyone ever restored from it? An untested backup is a hope. Before you rely on it, restore one folder to a scratch location and open a file.
- Is your cloud data backed up separately? Microsoft and Google keep your tenant running, they do not keep an independent copy of your data for you past their retention windows. This surprises people every time.
If backups turn out to be intact and offline, the rest of the day is work but it is ordinary work. If they are gone, the conversation changes and it changes fast. Getting backups into a shape that survives an attack like this is the whole point of managed backup and disaster recovery, and it is far cheaper to arrange on a quiet Tuesday than during an incident.
Should a small business pay a ransomware demand?
Treat paying as a last resort, taken with your insurer and your attorney, never as a shortcut on day one. It is legal in most circumstances, it is sometimes the only option left, and it is a bad deal almost every time.
Here is what payment actually buys and does not buy. It buys a decryption tool written by criminals. Those tools are frequently slow, they frequently fail on large files, and they restore data one item at a time rather than putting your server back the way it was. Paying does not undo the theft: if data was copied out before encryption, it is copied out whether you pay or not, and a second demand for the stolen copy is a common follow-up. Paying also marks you as a business that pays.
There is a compliance dimension too. Payments to sanctioned entities are prohibited under US Treasury rules, and you cannot always tell who is behind a strain. That is one more reason the decision belongs with your carrier and counsel and not with the person standing at the server.
The honest case for paying is narrow: backups are gone or were encrypted too, the data is irreplaceable, the business cannot function without it, and your carrier supports the decision. Even then a professional negotiator, usually appointed by the insurer, handles the contact. Do not email the attacker yourself.
What I do instead, on almost every job, is spend the first hours proving whether the backups will carry you. If they will, the question of paying never comes up. That is the whole argument for the boring work of testing restores before anything happens.
Who do you need to notify, and how soon?
Notify your cyber-insurance carrier first, law enforcement second, then take advice on who else. The order matters because your policy usually dictates the rest.
- Your cyber-insurance carrier. Most policies have a notification clause and a panel of approved responders. Hiring anyone outside that panel before you call can reduce or void what they pay. Find the policy number before you dial.
- The FBI, through ic3.gov. This is the federal reporting channel for cybercrime. Reporting does not commit you to anything and occasionally produces a decryption key the FBI already holds.
- Your attorney. Whether this is a reportable breach under Texas law or under a contract you signed with a client depends on what data was involved. That is a legal question with real deadlines attached, and it is not one I answer for you.
- Your bank, if any finance workstation was involved or any payment instructions may have been seen.
- Clients and patients, only on advice. A law firm or a dental practice has duties here that go beyond good manners, and the wording matters.
- Your staff. Tell them plainly what happened and what not to do. Silence produces rumours and people quietly working around your instructions.
Keep one written log of every notification with the time and the person you spoke to. Insurers ask for it, and it is easier to keep than to reconstruct.
Who helps with ransomware in Dallas?
For a small Dallas business, help usually comes in three layers, and you may need all three. Your cyber-insurance carrier appoints a breach coach and, often, a forensics firm. Those specialists handle the legal and investigative side. Someone then has to actually rebuild your systems, restore your data and get people working again. That last part is where I come in.
My name is Anthony Omini and I run Cross River Tech, a small, owner-led managed IT company based in Dallas. I have over fifteen years of IT experience across many industries and global organizations, with MCSA and CCNA listed on my LinkedIn. On an incident like this I am the person who isolates the network properly, works out the scope with you, tests the backups, rebuilds the servers and workstations clean, resets identities and gets the office running again, with my team behind me on the rebuild and me coordinating with whoever your carrier has appointed.
You do not need to be an existing client. Emergency work runs through my hourly IT support and break/fix service with no contract: $100 per hour remote and $150 onsite during business hours, $150 remote and $225 onsite after hours, weekends and holidays, with a one-hour minimum. Remote help is available around the clock at the after-hours rate. I do not promise an arrival time, and I would be suspicious of anyone who does during an incident. What I will tell you on the phone is honestly whether this is something I should be doing or something that needs a dedicated forensics firm.
If you would rather have this conversation before something happens, that is the better version of it. Reach me through the contact page or at (214) 612-7080.
How do you stop it happening again?
Rebuild into a different setup than the one that was breached, or you are just resetting the clock. The controls that matter here are unglamorous and mostly cheap.
- Multi-factor authentication on every account, starting with email and remote access. Most incidents I see begin with a stolen password, and MFA stops the majority of that cold.
- Backups that an attacker with your administrator password cannot delete. Offline copies, immutable cloud storage, or a backup service with its own separate credentials.
- Test restores on a schedule and write down the date and what you restored. This is the single check most small offices skip.
- Remove standing administrator rights from daily-use accounts, including yours. Separate admin logins that nobody reads email from.
- Close remote desktop to the open internet. If people need remote access, put it behind a VPN or a proper remote-access tool with MFA.
- Patch on a cadence, operating systems, browsers, and the line-of-business software everybody forgets.
- Filter email and train people gently. Staff who feel safe saying "I think I clicked something" report it in minutes rather than hiding it until Monday.
Those seven are also close to the list a carrier asks about when you renew, which is covered in more detail in what to fix when your cyber-insurance questionnaire comes back short. If the way in was a message someone opened, the follow-up steps are in what to do after someone clicks a phishing email, and the Microsoft side of the hardening work is set out in Microsoft 365 security for a small business. Keeping all of this current is ordinary managed IT work rather than a project.
Questions people ask
Should we turn the infected computers off?
No, isolate them instead. Unplug the network cable or switch off Wi-Fi so the infection cannot spread, but leave the machines running. Memory on a live machine can hold encryption keys and evidence of how the attacker got in, and a hard shutdown destroys all of it. The only exception is a machine you can see actively encrypting files that you cannot isolate any other way.
Can encrypted files be decrypted without paying?
Sometimes. Free decryptors exist for older or broken strains, and law enforcement occasionally releases keys seized from a group. The No More Ransom project maintains a public list worth checking with the ransom note in hand. For current, well-run strains the honest answer is no, which is why an offline backup that predates the infection matters more than any tool.
Will our cyber-insurance policy cover this?
That depends on your policy and on whether you follow its notification terms. Call the carrier before you hire any responder, because most policies require notice first and many restrict you to an approved panel. Have the policy number, the ransom note and your incident timeline ready. Insurers also commonly ask whether you reported to the FBI, so file at ic3.gov early.
How long does recovery from ransomware take?
It depends almost entirely on your backups. A single infected laptop with clean backups can be rebuilt and restored inside a day. A file server with tested offline backups is usually a matter of days rather than weeks. If backups were encrypted too, recovery becomes a rebuild from scratch and can stretch for weeks. Nobody can give you a real number before the scope is known.
Do we have to tell our clients?
Ask your attorney, not your IT person. Whether an incident is legally reportable depends on what data was involved, the notification rules that apply to it, and what your client contracts say. Law firms, dental and medical practices generally have stricter duties than other businesses. Keep a written log of what was accessed so counsel can make that call on facts.
Can you help if we already paid or already wiped machines?
Yes. It makes the investigation harder and it may make some evidence unrecoverable, but the rebuild still has to happen and it still has to be done in an order that does not reinfect you. Tell me plainly what has already been done, including anything you regret, so the plan starts from where you actually are.



