Back to security guides

    2026-08-10

    First-Hour Ransomware Checklist for Small Businesses

    As of 08/2026: a small business that sees a ransomware note should disconnect affected devices from the network, preserve evidence, stop cleanup attempts, and verify backups before restoring anything. Rebooting, wiping, or running random antivirus tools can destroy useful logs and spread the incident to backup storage.

    What changed?

    This guide was added because many Northeast Houston ransomware calls start after someone already rebooted the infected PC, deleted the ransom note, or started restoring files onto a still-infected network. The better move is containment first, recovery second.

    What should you do in the first 15 minutes?

    Disconnect affected computers from Ethernet and Wi-Fi, but do not wipe them. If a server, NAS, or shared drive is involved, isolate that storage from the rest of the network. Photograph the ransom note, write down the time it appeared, and list which machines were online. Do not contact the attacker and do not enter payment information.

    What should you preserve for recovery?

    Preserve the infected device, the ransom note, suspicious emails, VPN logs, Microsoft 365 sign-in logs, backup status screenshots, and any file-extension examples created by the ransomware. These details help identify the strain, entry point, and safest recovery path.

    First-hour actions and what they prevent

    ActionWhy it mattersMistake to avoid
    Disconnect infected computersStops lateral spreadDo not keep browsing or checking email
    Isolate servers and NAS devicesProtects shared files and backupsDo not run a rebuild or restore yet
    Photograph ransom notesPreserves strain and timeline cluesDo not delete notes before review
    Check backup status from a clean deviceConfirms recovery optionsDo not connect backup drives to infected PCs
    Call for incident triageSets containment orderDo not run unvetted cleanup tools

    When should a small business call for help?

    A small business should call for help immediately if more than one device is affected, shared folders are encrypted, Microsoft 365 accounts show suspicious sign-ins, backups are connected to the network, or business operations are stopped. Virus Pros handles first response for Kingwood, Atascocita, Humble and Northeast Houston businesses.

    Frequently asked questions

    Should I turn off the infected computer?

    Disconnect the infected computer from the network first. Leave the computer powered on unless a responder tells you otherwise because memory and logs may help identify what happened.

    Should I restore from backup right away?

    No. Confirm the backup is clean and the entry point is contained before restoring. Restoring too early can encrypt the replacement files.

    Do you pay ransoms?

    No. Virus Pros treats ransom payment as a last-resort legal and insurance decision, not the normal recovery path. The preferred approach is containment, clean backup restoration, and security hardening.

    Need incident help now?

    Call Virus Pros before rebooting, wiping, restoring, or paying anyone.

    Call (936) 251-6130
    Call Now — (936) 251-6130