If you’re reading this because something is wrong right now — stop reading, unplug the affected computers from the network (don’t power them off), and call us at 480-434-4222. Then come back to this article.

For everyone else, here’s what the first 24 hours of a ransomware incident look like, and what we’d do for a Mesa client.

Hour 0: Contain

The single most important thing is stopping the spread. That means:

Hour 1–2: Assess

Hour 2–6: Notify the right people

What NOT to do

Hour 6–24: Begin recovery

If your backups are good and offline, recovery is straightforward but slow: rebuild affected systems, restore data, validate that the attackers don’t still have access. If your backups are bad or compromised, your options shrink fast and the conversation gets harder.

The honest truth

Most Mesa businesses we help after a ransomware event would have spent a fraction of the recovery cost on prevention. MFA, EDR, immutable backups, and a tested recovery plan would have stopped the attack or limited it to one workstation.

Get prepared before you need us

See our cybersecurity services or call 480-434-4222 to schedule a security review.