If you’re reading this because something is wrong right now — stop reading, unplug the affected computers from the network (don’t power them off), and call us at 480-434-4222. Then come back to this article.
For everyone else, here’s what the first 24 hours of a ransomware incident look like, and what we’d do for a Mesa client.
Hour 0: Contain
The single most important thing is stopping the spread. That means:
- Unplug network cables from affected computers (don’t power them off — volatile memory has forensic value)
- Disable Wi-Fi on affected laptops
- Disconnect any backup drives that are currently plugged in
- Do not log into other computers using admin credentials — you’ll spread the attack
Hour 1–2: Assess
- How many machines are affected?
- Are servers affected, or just workstations?
- Are your backups offline / immutable, or were they reachable from the affected systems?
- Is your email (Microsoft 365, Google Workspace) compromised, or just your local systems?
Hour 2–6: Notify the right people
- Your IT provider or in-house IT lead
- Your cyber insurance carrier — before you make any decisions about paying or rebuilding. Most policies require this.
- Legal counsel, especially if you handle PII, PHI, or financial data
- The FBI’s IC3 portal (ic3.gov) — this is free and useful for any future legal action
What NOT to do
- Don’t pay the ransom on your own initiative. Talk to insurance and counsel first.
- Don’t reinstall over the affected machines yet. Forensics matters.
- Don’t email the attackers from a corporate account.
- Don’t post about it publicly. Communications strategy comes later.
Hour 6–24: Begin recovery
If your backups are good and offline, recovery is straightforward but slow: rebuild affected systems, restore data, validate that the attackers don’t still have access. If your backups are bad or compromised, your options shrink fast and the conversation gets harder.
The honest truth
Most Mesa businesses we help after a ransomware event would have spent a fraction of the recovery cost on prevention. MFA, EDR, immutable backups, and a tested recovery plan would have stopped the attack or limited it to one workstation.
Get prepared before you need us
See our cybersecurity services or call 480-434-4222 to schedule a security review.
