Back to security guides

    2026-08-10

    First-Hour Ransomware Checklist for Small Businesses

    As of 08/2026: a small business that sees a ransomware note should disconnect affected devices from the network, preserve evidence, stop cleanup attempts, and verify backups before restoring anything. Rebooting, wiping, or running random antivirus tools can destroy useful logs and spread the incident to backup storage.

    TL;DR: Contain first, preserve evidence second, and restore only after the entry point is closed. The first hour is about stopping spread, not cleaning the machine as fast as possible.

    Ransomware diagnostic table

    SymptomLikely causeSafe first stepWhen to call
    Ransom note on one computerEndpoint ransomware or support-scam payloadDisconnect that computer from Wi-Fi and EthernetImmediately, before rebooting or cleanup tools
    Shared folders are encryptedLateral movement through file sharesIsolate servers and NAS devicesIf more than one device or shared drive is affected
    Microsoft 365 suspicious sign-insStolen credentials or mailbox compromisePreserve sign-in logs and revoke sessions from a clean admin deviceIf invoice, payroll, or customer email is involved
    Backup drive or NAS was connectedBackups may be encrypted or contaminatedDisconnect backups and check status from a clean deviceBefore restoring anything
    Operations are stoppedBusiness-impacting ransomware incidentPhotograph notes and document affected systemsSame hour for triage and recovery planning

    What changed?

    This guide was added because many Northeast Houston ransomware calls start after someone already rebooted the infected PC, deleted the ransom note, or started restoring files onto a still-infected network. The better move is containment first, recovery second.

    What should you do in the first 15 minutes?

    Disconnect affected computers from Ethernet and Wi-Fi, but do not wipe them. If a server, NAS, or shared drive is involved, isolate that storage from the rest of the network. Photograph the ransom note, write down the time it appeared, and list which machines were online. Do not contact the attacker and do not enter payment information.

    What should you preserve for recovery?

    Preserve the infected device, the ransom note, suspicious emails, VPN logs, Microsoft 365 sign-in logs, backup status screenshots, and any file-extension examples created by the ransomware. These details help identify the strain, entry point, and safest recovery path.

    First-hour actions and what they prevent

    ActionWhy it mattersMistake to avoid
    Disconnect infected computersStops lateral spreadDo not keep browsing or checking email
    Isolate servers and NAS devicesProtects shared files and backupsDo not run a rebuild or restore yet
    Photograph ransom notesPreserves strain and timeline cluesDo not delete notes before review
    Check backup status from a clean deviceConfirms recovery optionsDo not connect backup drives to infected PCs
    Call for incident triageSets containment orderDo not run unvetted cleanup tools

    When should a small business call for help?

    A small business should call for help immediately if more than one device is affected, shared folders are encrypted, Microsoft 365 accounts show suspicious sign-ins, backups are connected to the network, or business operations are stopped. Virus Pros handles first response for Kingwood, Atascocita, Humble and Northeast Houston businesses.

    Frequently asked questions

    Should I turn off the infected computer?

    Disconnect the infected computer from the network first. Leave the computer powered on unless a responder tells you otherwise because memory and logs may help identify what happened.

    Should I restore from backup right away?

    No. Confirm the backup is clean and the entry point is contained before restoring. Restoring too early can encrypt the replacement files.

    Do you pay ransoms?

    No. Virus Pros treats ransom payment as a last-resort legal and insurance decision, not the normal recovery path. The preferred approach is containment, clean backup restoration, and security hardening.

    Common questions

    Should I turn off the infected computer?
    Disconnect it from the network first. Leave it powered on unless a responder tells you otherwise because memory and logs may help identify what happened.
    Should I restore from backup right away?
    No. Confirm the backup is clean and the entry point is contained before restoring, or the replacement files may be encrypted again.
    Do you pay ransoms?
    No. Virus Pros treats ransom payment as a last-resort legal and insurance decision, not the normal recovery path.

    Need incident help now?

    Call Virus Pros before rebooting, wiping, restoring, or paying anyone.

    Call (936) 251-6130
    Call Now — (936) 251-6130