Nobody expects the MSP with three people and a shared Google Drive to run a corporate-style incident response. You can't. But ransomware doesn't care about org charts — it cares about your backups, your open RDP ports, and how long you stay frozen.
This is the checklist I hand to small IT teams. Print it. Tape it inside the server room door. When it happens, you will not think clearly, and this is what thinking clearly looks like on paper.
Minute 0–5: Stop the bleeding
- Do not power off the infected machine yet. RAM holds the ransom note, the process list, and sometimes the attacker's next hop. Pull the network cable instead (or drop the VLAN/port on the switch). Containment first, forensics second.
- Check three machines, not one. Ransomware with lateral movement rarely stops at the first host. Ask: can the domain controller still authenticate? Is the file server's wallpaper changed? Is anyone's OneDrive syncing gibberish?
- Announce the freeze. One message to the whole team: "Do not log into anything, do not reboot anything, do not pay anyone." People making well-meaning changes destroy evidence and restart encryption.
Minute 5–15: Answer the only three questions that matter
- Are the backups intact and OFFLINE? Not "we have backups" — are they immutable or vaulted somewhere the encryptor couldn't reach? If your only backup is a USB drive still plugged in, assume it's encrypted too. Mount the backup target read-only and verify a random file from last week actually opens.
- What strain is it? Rename one encrypted file's extension and search it (ID Ransomware, or a VirusTotal search). The strain tells you: whether a free decryptor exists, whether the group leaks data, and how the crew negotiates. Two minutes here saves weeks.
- Did data leave the building? Check egress: unusual uploads to cloud storage, new SMTP relay traffic, or logs that just stop. Exfiltration changes the conversation from "restore" to "restore AND disclose."
Minute 15–30: Decide with a script, not adrenaline
- Write down the decision owner. One person decides restore-vs-negotiate, and they write it in the ticket with the timestamp. At 2am, five people agreeing in a group chat is not a decision.
- Start the restore on hardware you control. Clean host, patched OS, backups mounted, restore in a sandboxed VLAN. Never restore onto the machines that were just encrypted — you don't yet know the persistence mechanism.
- Open the disclosure clock consciously. If employee or customer data was exfiltrated, breach-notification windows (GDPR: 72 hours; state laws: as little as 30 days) started ticking. Legal gets told at minute 30, not day 30.
The part everyone skips
- The same door will be used again. Ransomware doesn't invent access — it uses the VPN with no MFA, the server with the 2016 RDP exposure, the vendor account with the password on a sticky note. If you restore without closing the front door, buy the same team lunch for next quarter, because they'll be back.
I put the full version of this — the 12-point audit that finds the front door before the attackers do, plus the templates for steps 4–10 — into a fixed-fee kit for small teams and the MSPs who serve them. No retainer, no per-seat math, flat price:
The full 12-point security audit + incident response templates →
The audit is the same one I run before touching a client's network. It's boring, it's checklists all the way down, and it works precisely because nobody skips a box when the box is a checkbox and not a feeling.
Top comments (0)