What to do if you get ransomware
By Cade Jackman · · 12 min read
If this is happening right now, skip everything else and read the box below. The first decision is the one people most often get wrong, and it is the one that decides how much of your data comes back.
If it is happening right now
- 1
- Disconnect from the network. Do not power anything off. Unplug the ethernet cable and turn off Wi-Fi. Shutting down destroys evidence held in memory that can sometimes be used to recover files.
- 2
- Stop using company email and chat. Assume the attacker is reading them. Switch to phone calls and personal devices.
- 3
- Call your cyber insurance carrier before you do anything else. Most policies require it, and calling late can reduce or void your cover.
- 4
- Do not delete the ransom note, and do not reformat anything. It identifies which strain hit you, which decides whether a free decryptor exists.
- 5
- Write down the time you noticed. If you handle health data, a legal clock started at that moment, not when the investigation ends.
If you would rather have someone on the phone than read further, call us on (801) 562-2300. We will tell you what to do next whether or not you are a client.
The short answer
Ransomware is malicious software that encrypts your files and demands payment for the key. Modern attacks almost always steal a copy of your data first, so an attack is both an outage and a data breach at the same time. The correct first response is to isolate affected machines from the network without powering them down, move all communication off company systems in case the attacker is monitoring them, notify your cyber insurance carrier before engaging anyone else, and preserve the ransom note and affected drives as evidence. Do not pay before understanding the legal exposure: paying a sanctioned group can carry civil penalties in the United States even if you did not know who they were. Most organisations that pay do not get all of their data back.
Step 1: Disconnect the network, but leave the power on
This is the step people get wrong, usually by doing the sensible-seeming thing and holding the power button.
Federal guidance is specific about this. CISA's #StopRansomware Guide, published jointly with the FBI, NSA and MS-ISAC, says to isolate the affected systems and only power a device down if you cannot disconnect it from the network, because powering down loses infection artifacts and potential evidence stored in volatile memory. In plain terms: the encryption key is sometimes still sitting in the computer's memory, and switching off is the one action that guarantees it is gone forever.
So: unplug the network cable, switch off Wi-Fi, and leave the machine running. If several machines or a whole site are affected and unplugging each one is not realistic, disconnect at the switch rather than shutting things down.
Step 2: Assume they can read your email
Attackers commonly sit inside a network for days or weeks before triggering encryption, and they often still have access to mail and chat while you are responding. CISA recommends isolating systems in a coordinated way and using out-of-band communication such as phone calls, so the attacker is not tipped off that they have been spotted.
Practically, that means the incident conversation happens on phones, in person, or on personal accounts on personal devices. Not on company email. Not in the company Teams or Slack. It feels excessive right up until the moment you realise the attacker read your plan for containing them.
Step 3: Call your cyber insurance carrier first
If you carry cyber insurance, the policy almost certainly requires you to notify them promptly and to use their approved incident-response firms. Bringing in your own consultant first, or paying a ransom without telling them, can reduce a claim or void it entirely.
Carriers also have something you do not: a panel of breach counsel and forensics firms already under contract, available immediately. Even when a business dislikes the constraint, that panel is usually faster than anything they could arrange from a standing start on a bad morning.
Do this before engaging anyone, including us.
Step 4: Preserve everything
The instinct to clean up is strong and it is the wrong one. Keep:
- The ransom note. Photograph it and keep the file. It usually identifies the strain, and strain identification is what determines whether a free decryption tool already exists. The No More Ransom project, run by Europol with industry partners, publishes free decryptors for a long list of families.
- The encrypted files. Even unusable ones. If a decryptor is released later, and that does happen, you need the data to decrypt.
- Logs, and the machines themselves. CISA recommends taking a system image and memory capture of affected devices before anything is rebuilt.
Do not reformat, do not restore over the top, and do not let anyone "just reinstall Windows to get us going" on an affected machine until it has been imaged.
Step 5: Report it
Report to the FBI through IC3 and to CISA. Reporting is free, it does not oblige you to do anything, and it occasionally produces a decryption key when law enforcement has seized a group's infrastructure.
Reporting is separate from, and does not satisfy, your obligation to notify affected individuals or regulators. That is covered further down.
Should you pay the ransom?
The FBI advises against it. Beyond the ethics of funding the next attack, three practical points matter more than most people expect.
Paying often does not work
The data is consistently poor. Reporting on Q4 2024 incidents found roughly 84% of organisations that paid failed to fully recover their data, and organisations that pay recover on average only around 60% of it. Decryption tools written by criminals are frequently slow, buggy, or incomplete. You may pay and still be rebuilding.
Paying can be illegal, even unknowingly
This is the part that surprises people. The US Treasury's Office of Foreign Assets Control has warned that facilitating a ransom payment to a sanctioned entity can draw civil penalties on a strict liability basis — meaning you can be penalised even if you did not know, and had no way to know, who was on the other end. This exposure extends to companies that help make the payment on your behalf.
Most businesses now refuse
Refusing has become the norm rather than the brave choice. The 2026 Verizon Data Breach Investigations Report found 69% of victim organisations declined to pay. Where the attackers only stole data and did not encrypt anything, the refusal rate is far higher still.
None of that makes the decision easy at 6am with a business that cannot operate. It is a decision to make with breach counsel and your insurer, not alone, and not in the first hour.
Assume they took a copy
Double extortion — stealing the data before encrypting it, then threatening to publish it — is now standard rather than exotic. It changes the nature of the problem completely.
If the only issue were encryption, a clean backup would end the incident. Because a copy has almost certainly left the building, you also have a data breach, with notification duties attached, and restoring from backup does nothing about that. Businesses that recover quickly and then assume they are finished are the ones that get an unpleasant letter months later.
If you are a pharmacy, clinic or anyone holding health data
This section applies to a lot of our clients, and it contains the single most commonly missed deadline in this whole subject.
Under guidance from the HHS Office for Civil Rights, a ransomware incident affecting electronic protected health information is presumed to be a reportable breach. The reasoning is that encrypting the data is itself an impermissible disclosure. The presumption can be rebutted, but only by carrying out and documenting a formal risk assessment demonstrating a low probability that the information was compromised. Silence is not a rebuttal.
And here is the deadline nobody expects:
The 60-day notification clock starts on the day you discover the incident, not the day your forensic investigation finishes. OCR's settlement with OSF Healthcare, at $552,250, turned on exactly this point, and across its ransomware enforcement actions OCR has treated notification delayed pending an investigation as a compliance failure in its own right.
In practice that means the clock is already running while you are still working out what happened. Notification duties have to be managed in parallel with recovery, not after it — which is precisely why breach counsel gets involved on day one rather than week three.
Utah's own breach notification law runs alongside HIPAA and requires notice in the most expedient time possible without unreasonable delay, allowing for law-enforcement holds and the time needed to establish scope and restore system integrity.
If you run a pharmacy, we have written separately about what pharmacy IT actually has to account for, and about the antivirus exclusions dispensing systems need, which is one of the more common ways protection ends up quietly disabled.
What recovery actually looks like
Recovery is rebuilding, not un-encrypting. The realistic sequence is: contain, image everything, work out how they got in, rebuild clean systems, restore data into them, verify, and only then reconnect.
The step businesses underestimate is finding the entry point. Restoring onto infrastructure that still has the original weakness in it — an exposed remote access service, a stolen password without multi-factor authentication behind it, an unpatched appliance — is how organisations get hit a second time within weeks by the same group.
Cost is significant even when nobody pays a ransom. Industry reporting put the average recovery cost at roughly $1.53 million in 2025, excluding any ransom, down from about $2.73 million the year before. Those are averages across organisations far larger than most small businesses, but the shape holds: the ransom is rarely the expensive part.
The three things that decide how bad this gets
By the time an attack lands, the outcome is already mostly determined by decisions taken months earlier.
- Whether your backups were reachable from the network that got encrypted. This is the whole ballgame. A backup that a compromised administrator account can delete is not a backup. Offline or immutable copies are what separate a bad week from an existential event.
- Whether multi-factor authentication was on email and remote access. Stolen credentials remain among the most common ways in, and MFA removes most of that value.
- Whether anyone was watching. Attackers are typically inside for days before triggering. Monitored endpoint protection catches that window; unmonitored antivirus reports it to nobody at 2am.
Our small business cybersecurity checklist covers these in the order that removes the most risk for the least effort.
How we handle it
If you are a client, ring us and we start immediately — containment first, then insurer and counsel, then the rebuild. If you are not a client and you are in the middle of this, call anyway. We will tell you what to do in the first hour regardless, because the first hour matters more than who is paying for it.
Common questions
Should I turn the computer off if I see a ransom note?
No. Disconnect it from the network instead — unplug the cable and switch off Wi-Fi — and leave it powered on. Federal guidance is to power a device down only if you cannot disconnect it, because shutting down destroys evidence held in memory that can occasionally be used to recover files.
Can I get my files back without paying?
Sometimes. It depends on whether you have a backup the attacker could not reach, and on which strain hit you — free decryptors exist for many families and are published by the No More Ransom project. That is why keeping the ransom note matters: it identifies the strain.
Is it illegal to pay a ransom?
Not automatically, but it carries real legal risk. The US Treasury's sanctions office has warned that paying a sanctioned group can bring civil penalties on a strict liability basis, meaning you can be penalised even if you had no way of knowing who you were paying. Take the decision with breach counsel and your insurer, never alone.
Do I have to tell anyone we were attacked?
Usually yes. If personal data was involved, state breach notification law applies, and if health data was involved, HIPAA almost certainly does. Restoring from backup does not remove the duty, because the data was copied before it was encrypted.
How long does recovery take?
It depends almost entirely on your backups. With tested, offline backups and a known entry point, days. Without them, weeks, and sometimes the honest answer is that some data does not come back at all.
We are a pharmacy. Does a ransomware attack count as a HIPAA breach?
It is presumed to be one. Federal guidance treats encryption of protected health information as an impermissible disclosure, and that presumption can only be rebutted by a documented risk assessment showing a low probability of compromise. The 60-day notification clock starts when you discover the incident, not when the investigation concludes.
Find out what's actually wrong - before you commit to anything.
A free IT check-up gives you a written picture of your computers, network, backups and security. No obligation, and it's yours to keep even if you never hire us.
Not ready? See how pricing works or read the FAQ.