
A ransom note, suddenly renamed files, or a shared folder that no one can open is not the moment to “click around and see what happens.” The first goal is to stop possible ransomware from reaching more computers and backups while preserving enough evidence for a safe investigation. For a home office or small business, the most useful rule is simple: isolate first, document second, recover later.
This guide starts at the moment you notice a credible ransomware warning and covers the first 15 minutes. It is deliberately different from a prevention checklist: it tells you what to disconnect, what not to erase, who to call, and when an ordinary-looking file problem should—or should not—be treated as an incident.
The problem: one wrong reaction can spread the damage
Ransomware can encrypt files on the affected computer and may reach attached drives, shared folders, servers, and other networked systems. Some incidents also involve stolen data. A hurried reboot, a test login on another computer, or reconnecting an external backup can make the investigation and recovery harder.
The first-15-minutes rule: disconnect the suspected device from networks without browsing through more files. If you cannot disconnect it from the network, CISA says to power it down to help prevent further spread.
That power-down advice has an important order: network isolation comes first. Pulling power can erase useful memory evidence and can interrupt work an incident responder may need to examine. Use shutdown only when you cannot promptly disconnect the device from Ethernet, Wi-Fi, cellular, or other network access—or when qualified responders direct you to do so.
Who is affected—and who is not
Treat it as a possible ransomware incident if:
- A ransom note appears on a computer, server, NAS, or website.
- Many documents suddenly gain unfamiliar extensions, change names, or refuse to open at the same time.
- Several employees lose access to the same shared data within minutes.
- A security product reports ransomware behavior or mass encryption—not merely one suspicious file.
- A cloud or backup console shows a rapid wave of deletions, overwrites, or encrypted versions tied to one account or device.
- An attacker claims to have stolen data and provides credible samples. Do not open samples on a normal work computer.
It may be something else if:
- Only one old document is corrupt or one application cannot open its normal file type.
- A network share disappeared after a router, VPN, server, or password change.
- A storage device reports a hardware fault, a full volume, or a disconnected cable without mass file changes.
- A browser page claims “your files are encrypted” but the message disappears when the tab is closed and local files still open normally. That may be a scareware page—but the device should still be checked before normal use.
Do not dismiss uncertainty by reconnecting and testing from several computers. If the symptoms could involve shared data, isolate the first suspicious device and ask a qualified person to check from a known-clean administrative system.
The first 15 minutes: an ordered response
Minute 0–2: stop and isolate the suspected device
- Stop using the keyboard and mouse except to isolate the device. Do not open more files, start a scan, reply to the attacker, or search for a decryptor from that computer.
- Disconnect Ethernet. Unplug the network cable from the computer or its dock. Label the cable or port so it is not casually reconnected.
- Disconnect Wi-Fi and cellular networking. Use the hardware wireless switch or airplane mode if it can be done immediately without navigating through suspicious prompts. A desktop can be isolated at the switch port by an administrator working from a clean system.
- Disconnect the affected computer from VPN access. If the VPN cannot be ended locally, an administrator should terminate the session from a clean management console.
- Leave the machine powered on if isolation succeeded. If you cannot disconnect it from the network, power it down. Do not repeatedly restart it.
Safety exception: do not unplug or shut down equipment that supports medical care, physical safety, building controls, manufacturing, or other hazardous processes unless the responsible operator follows the equipment’s emergency procedure. Isolate through the approved network or safety plan and involve the vendor or specialist immediately.
Minute 2–5: protect other systems and backup paths
- Tell people to stop using affected shared folders and not to reconnect the isolated machine.
- From a known-clean administrative device, identify which computer, account, server, share, and cloud-sync location were involved.
- If a backup job is actively copying suspicious changes into a writable backup target, pause that job through its clean management console. Do not delete backup sets, detach immutable copies, or connect an offline backup “to check it.”
- For cloud storage, preserve version history and logs. Suspend the affected sync client or account only through the provider’s trusted administration path. Do not bulk-delete files in an attempt to remove encrypted copies.
- If several systems are changing at once, isolate the affected network segment or switch ports with professional help rather than racing from computer to computer.
Minute 5–10: preserve facts before they disappear
- Photograph the full screen and ransom note with a separate phone. Include the clock if practical.
- Write down when the problem was first noticed, who noticed it, the device name, signed-in username, physical location, network connection, and the last known normal activity.
- Record the ransom-note filename, encrypted-file extension, email address, website, cryptocurrency address, and demand amount without visiting links or contacting the attacker.
- Keep suspicious emails, attachments, text messages, security alerts, and payment instructions. Do not forward a live attachment to coworkers.
- List recently connected USB drives, NAS shares, remote-desktop sessions, VPNs, cloud-sync accounts, and backup targets.
CISA’s response checklist recommends capturing a system image and memory from a sample of affected devices. That is specialist work. Do not install a collection tool on the suspected computer unless your incident responder directs the process; installing or scanning can change evidence.
Minute 10–15: start the right calls
- Call your IT or incident-response contact from a clean phone or computer. Give them the timeline, affected systems, and what has been disconnected.
- Notify the business owner or incident lead. One person should coordinate decisions and keep a written log.
- Contact the cyber-insurance carrier before hiring vendors or negotiating. Coverage may require a specific hotline, counsel, forensic firm, or consent process.
- Report the incident. The FBI’s Internet Crime Complaint Center accepts ransomware complaints and asks for details including the variant if known, encrypted-file extension, attacker contact information, cryptocurrency information, demand, and whether payment occurred.
- Get legal and regulatory advice if sensitive data may have been taken. Notification duties depend on the data, industry, contracts, customers, and jurisdictions; encryption alone does not answer that question.
Do not do these things during the first response
Phone readers: swipe the table left to see the “Better action” column.
| Bad reaction | Why it is risky | Better action |
|---|---|---|
| Restart repeatedly to see whether the note disappears | May trigger more activity, lose memory evidence, or complicate recovery | Isolate, photograph, and wait for guided collection |
| Plug in the offline backup and browse it | Exposes a clean recovery copy to an untrusted device | Keep it offline until a clean recovery environment is ready |
| Run a random “decryptor” from a search result | It may be malware, damage files, or target the wrong variant | Use law-enforcement and reputable responder guidance after the variant is identified |
| Delete the ransom note and encrypted files | Destroys evidence and may remove files that can later be recovered | Preserve the affected storage; restore to separate clean storage later |
| Pay immediately because a timer is counting down | Payment does not guarantee a working decryptor, complete restoration, or deletion of stolen data | Contact incident response, insurer, counsel, and law enforcement |
| Send everyone the suspicious attachment for comparison | Can create more victims | Preserve the original and share indicators through a safe channel |
Two realistic examples
Example 1: one receptionist PC and a shared drive
A receptionist sees hundreds of filenames changing and a ransom note appears. The good response is to unplug that PC’s Ethernet cable, keep it powered on, photograph the screen, and tell staff to stop using the shared folder. An administrator working from a clean device checks whether the server is still changing and pauses any writable backup replication that is copying damaged versions. The bad response is to reboot the receptionist PC, log in from two other workstations, and attach the portable backup to see whether it still works.
Example 2: a fake browser warning
A home user sees a full-screen “ransomware” warning after visiting a website, but local pictures and documents still open and no filenames changed. Disconnecting the computer and closing the browser through a trusted method is reasonable. Do not call the number in the warning or install its “support” tool. A clean security check may determine that the event was browser scareware rather than file encryption. The cautious response is still cheaper than giving a scammer remote access.
Recovery starts only after containment
Do not erase the suspected computer and immediately restore it onto the original network. A recovery plan should first answer:
- Which identities, devices, servers, cloud services, and administrator tools were compromised?
- How did the attacker enter, and has that access been removed?
- Are passwords, tokens, remote-access tools, inbox rules, or privileged accounts still under attacker control?
- Which backup was created before the incident, is isolated from the compromised credentials, and has passed a malware and restore check?
- Which systems must return first for safe business operation?
- How will rebuilt devices be monitored before normal access resumes?
NIST’s current incident-response guidance treats response and recovery as part of broader cybersecurity risk management, not a single cleanup command. NIST’s June 2026 ransomware profile likewise covers governing, identifying, protecting, detecting, responding, and recovering. For a small business, that means the first restored laptop is not proof the incident is over.
Should you pay the ransom?
The FBI says it does not support paying a ransom. Payment does not guarantee that data will be returned, that a decryptor will work, or that stolen information will be deleted. It can also encourage more attacks. The decision can involve legal, insurance, sanctions, safety, and business-continuity issues; do not let an employee negotiate or send cryptocurrency independently. Preserve the demand and involve qualified counsel, the insurer, incident response, and law enforcement.
Frequently asked questions
Should I unplug the power immediately?
Not if you can quickly disconnect all network access. CISA’s checklist says to isolate impacted systems immediately and power them down only when you cannot disconnect them from the network. A powered-on but isolated system may preserve useful memory evidence.
Should I unplug external hard drives?
If an external drive is attached to the affected computer, avoid browsing it. Record that it was connected and ask the responder how to disconnect and preserve it. Keep currently offline backups offline. Never connect a clean backup to the suspected machine.
Can antivirus fix everything?
Security software may detect or remove malware, but removal alone does not establish how the attacker entered, whether data was stolen, whether other systems are compromised, or whether persistence remains. Contain first and investigate the scope before trusting recovery.
What if the files are in OneDrive, Google Drive, or Dropbox?
Cloud version history may help, but first stop the affected device or account from synchronizing more changes. Preserve audit logs and versions. Use a clean administrator account and the provider’s official recovery process; do not bulk-delete encrypted files until scope and retention are understood.
Is my phone affected because it uses the same Wi-Fi?
Sharing Wi-Fi does not automatically mean every device is infected. Risk depends on the ransomware, exposed services, accounts, and network design. Do not use the phone to sign into potentially compromised business accounts until the responder confirms the identity systems are safe.
When can people return to work?
After the incident lead confirms containment, trusted identities and devices are available, required systems have been rebuilt or restored from verified backups, and monitoring is active. “The ransom note is gone” is not a recovery test.
Make the next incident cheaper before today ends
- Print the five-word rule: isolate, document, call, preserve, recover.
- Write down the IT responder, insurer hotline, business owner, attorney, backup owner, and critical vendor contacts.
- Label Ethernet cables and switch ports for the most important computers and servers.
- Confirm that at least one backup copy is offline, immutable, or protected by credentials separate from everyday accounts.
- Perform a controlled restore test rather than trusting a green “backup completed” message.
- Decide who has authority to isolate systems and who communicates with employees, customers, insurers, and law enforcement.
Related The IT Guys guides
- Make a one-page tech emergency sheet before something breaks
- Test one file restore before you trust your backup
- Practical cybersecurity protection for people and small businesses
Official sources
- CISA, FBI, NSA, and MS-ISAC: #StopRansomware Guide and response checklist
- FBI Internet Crime Complaint Center: Ransomware guidance
- FBI Internet Crime Complaint Center: File an Internet crime complaint
- NIST: SP 800-61 Revision 3, Incident Response Recommendations and Considerations
- NIST: IR 8374 Revision 1, Ransomware Risk Management: A Cybersecurity Framework 2.0 Community Profile
This guide provides general technology-response information, not legal advice or a substitute for an incident responder familiar with your systems. Source pages were checked August 3, 2026. The featured image is an original editorial illustration created for The IT Guys; it depicts a generic small-business network environment rather than a real incident or product interface.
