It’s every business owner’s worst nightmare: a screen full of red text demanding payment, files you can no longer open, and a team standing around not knowing what to do next. If this is happening to you right now, the decisions you make in the next 30 minutes matter more than almost any other moment in your business.

Here’s what to do, in order.

1. Disconnect the Infected Device โ€” Immediately

Unplug the ethernet cable or turn off Wi-Fi on the affected computer. Do not shut it down yet โ€” just get it off the network. Ransomware spreads across shared drives and connected systems, so isolating the device is your first line of defense against it spreading further.

2. Alert Your Team โ€” Don’t Touch Anything Else

Tell everyone in the office to stop working immediately and avoid clicking anything, opening files, or restarting computers. Panic-driven actions (like restarting a machine hoping it “fixes itself”) can actually make recovery harder.

3. Do Not Pay the Ransom Yet

It’s tempting to just make the problem go away, but paying doesn’t guarantee you’ll get your data back, and it can mark you as an easy target for future attacks. Get a professional assessment first.

4. Call Your IT Provider or a Cybersecurity Response Team

This is the moment a managed IT partner earns their keep. A qualified team can assess the scope of the attack, determine whether clean backups are available, and begin containment โ€” often within the hour if you already have monitoring in place.

5. Document Everything

Take photos of the ransom message, note the time you discovered it, and write down what actions were taken and when. This documentation matters for insurance claims and any required legal or compliance reporting.

6. Check If You’re Required to Report It

Depending on your industry (healthcare, finance, legal), you may have HIPAA, SEC, or other regulatory reporting obligations. This is another reason having a Hudson Valley IT partner who understands local business compliance requirements matters.

The Real Lesson: Prevention Beats Response

Every business we’ve helped through a ransomware incident has said the same thing afterward: they wish they’d had 24/7 monitoring and a tested backup system in place before it happened. If your current setup doesn’t include:

  • 24/7/365 network monitoring
  • Managed endpoint detection and response (EDR)
  • Regularly tested data backups
  • Employee phishing awareness training

…you’re more exposed than you might think.

If you’re dealing with an active incident right now, call us immediately. If you want to make sure this never happens to your business, we offer free security assessments for Poughkeepsie and Hudson Valley businesses.

๐Ÿ“ž (845) 367-7300