2026-08-10
First-Hour Ransomware Checklist for Small Businesses
As of 08/2026: a small business that sees a ransomware note should disconnect affected devices from the network, preserve evidence, stop cleanup attempts, and verify backups before restoring anything. Rebooting, wiping, or running random antivirus tools can destroy useful logs and spread the incident to backup storage.
What changed?
This guide was added because many Northeast Houston ransomware calls start after someone already rebooted the infected PC, deleted the ransom note, or started restoring files onto a still-infected network. The better move is containment first, recovery second.
What should you do in the first 15 minutes?
Disconnect affected computers from Ethernet and Wi-Fi, but do not wipe them. If a server, NAS, or shared drive is involved, isolate that storage from the rest of the network. Photograph the ransom note, write down the time it appeared, and list which machines were online. Do not contact the attacker and do not enter payment information.
What should you preserve for recovery?
Preserve the infected device, the ransom note, suspicious emails, VPN logs, Microsoft 365 sign-in logs, backup status screenshots, and any file-extension examples created by the ransomware. These details help identify the strain, entry point, and safest recovery path.
First-hour actions and what they prevent
| Action | Why it matters | Mistake to avoid |
|---|---|---|
| Disconnect infected computers | Stops lateral spread | Do not keep browsing or checking email |
| Isolate servers and NAS devices | Protects shared files and backups | Do not run a rebuild or restore yet |
| Photograph ransom notes | Preserves strain and timeline clues | Do not delete notes before review |
| Check backup status from a clean device | Confirms recovery options | Do not connect backup drives to infected PCs |
| Call for incident triage | Sets containment order | Do not run unvetted cleanup tools |
When should a small business call for help?
A small business should call for help immediately if more than one device is affected, shared folders are encrypted, Microsoft 365 accounts show suspicious sign-ins, backups are connected to the network, or business operations are stopped. Virus Pros handles first response for Kingwood, Atascocita, Humble and Northeast Houston businesses.
Frequently asked questions
Should I turn off the infected computer?
Disconnect the infected computer from the network first. Leave the computer powered on unless a responder tells you otherwise because memory and logs may help identify what happened.
Should I restore from backup right away?
No. Confirm the backup is clean and the entry point is contained before restoring. Restoring too early can encrypt the replacement files.
Do you pay ransoms?
No. Virus Pros treats ransom payment as a last-resort legal and insurance decision, not the normal recovery path. The preferred approach is containment, clean backup restoration, and security hardening.
Need incident help now?
Call Virus Pros before rebooting, wiping, restoring, or paying anyone.
Call (936) 251-6130