Monday morning. Someone on your team tries to open a file and gets an error. Then another error. Then a message on the screen demanding payment to get your files back.
Ransomware has arrived, and right now, you’re not thinking about statistics or industry reports. You’re thinking about your payroll, your client data, your ability to operate today.
At Sirius, we’ve helped businesses walk through ransomware recovery. It’s never simple, and the next 72 hours are the most critical. Most business owners have no idea what that process actually looks like until they’re in it. This post walks through what really happens, what decisions you’ll face, and how preparation changes the outcome.
The First Hour: Contain First, Panic Later
When ransomware hits, the instinct is to start calling people and trying to figure out what happened. That’s understandable, but the most important thing in the first hour is containment.
Immediate steps:
- Isolate affected systems. Disconnect infected machines from the network immediately. Pull the ethernet cable, disable Wi-Fi, or shut the machine off if you have to. Ransomware spreads laterally across networks and the faster you isolate, the less damage it can do.
- Don’t turn off every machine. This is counterintuitive, but powered-off machines can destroy forensic evidence needed to understand what happened and how far the infection spread. Work with your IT team on which systems to isolate versus power down.
- Contact your IT provider immediately. If you’re working with a managed services provider, this is exactly the moment you call them. If you don’t have one, you’ll need to find an incident response specialist quickly.
- Don’t pay anything yet. Paying the ransom should be a last resort after every other option has been exhausted. We’ll cover why below.
📋 Ransomware First-Response Checklist
Print this and keep it somewhere accessible before you need it.
| # | Action | Who |
|---|---|---|
| 1 | Isolate infected machines from the network (unplug ethernet, disable Wi-Fi) | IT / On-call |
| 2 | Do NOT power off all machines. Preserve forensic evidence on running systems. | IT |
| 3 | Call your IT provider or incident response specialist immediately | Management |
| 4 | Notify your cyber insurance carrier before making any recovery decisions | Management |
| 5 | Check nomoreransom.org for free decryption tools for your specific variant before considering payment | IT |
| 6 | Do not pay the ransom until all other options are exhausted. Consult legal counsel first. | Management + Legal |
| 7 | Report to FBI IC3 at ic3.gov. Not required, but strongly recommended | Management |
| 8 | Assess Arizona breach notification obligations and any industry-specific requirements | Legal counsel |
The businesses that fare best in ransomware incidents are the ones that respond fast and have someone competent directing the containment. Time spent panicking or waiting to see if the problem resolves itself is time the malware uses to encrypt more files.
The Investigation: What Happened and How Bad Is It?
Once containment is underway, the investigation begins. This is where your cybersecurity team works to understand the scope of the attack.
Key questions being answered:
- How did the ransomware get in? (Phishing email, exposed RDP, compromised credentials, unpatched vulnerability?)
- Which systems were affected and what data was encrypted?
- Was data exfiltrated before encryption? (Many modern ransomware attacks steal data before locking it to increase leverage)
- Is the ransomware variant known? Some variants have publicly available decryption keys.
- Are the attackers still in the environment?
This last point matters more than most people realize. In many attacks, criminals have been inside the network for days or weeks before they trigger the ransomware. If you simply restore from backup without finding and removing the attacker, you may find yourself encrypted again within hours.
The Recovery Decision: Pay, Restore, or Both?
This is the part nobody wants to face, but it’s the central decision in a ransomware incident: how do you get your data back?
Option 1: Restore from backup
If you have clean, tested, recent backups stored in a location the ransomware couldn’t reach, this is almost always the right path. Recovery from backup typically means:
- Rebuilding affected systems from scratch (reimaging)
- Restoring data from the most recent clean backup
- Validating that restored systems are clean before reconnecting to the network
- Addressing the entry point so the same attack can’t repeat
The critical variables are: how recent is the backup, how long will restoration take, and how much data was created between the last backup and the attack? Businesses with robust backup and disaster recovery plans (ideally with multiple recovery points) can often recover without paying anything.
Option 2: Pay the ransom
This path is chosen when there are no viable backups, the data is critical, and the cost of losing it exceeds the ransom demand. Before going down this road, understand:
- Payment doesn’t guarantee decryption. Roughly one in four businesses that pay the ransom don’t fully recover their data. Criminals are criminals.
- You may be paying to receive a broken decryption tool. Even when it works, decryption can be slow and incomplete.
- Paying marks you as a target who pays. Some attackers come back.
- There may be legal implications, particularly if the attackers are on government sanctions lists.
Ransom payments should be handled in consultation with legal counsel and, in some cases, law enforcement. The FBI and CISA advise against paying, though they acknowledge businesses sometimes feel they have no choice.
Option 3: Decryption tools
For some known ransomware variants, decryption tools exist and are available for free through resources like No More Ransom (nomoreransom.org). Your IT team should check whether the variant you’ve been hit with has a known solution before considering payment.
Notifying the Right People
A ransomware attack is not just a technical problem. Depending on the data involved, you may have legal notification obligations.
Who may need to be notified:
- Customers and clients: If personal data was compromised, many states (including Arizona) have breach notification laws requiring you to notify affected individuals
- Law enforcement: Reporting to the FBI’s Internet Crime Complaint Center (IC3) is not required but strongly recommended. It contributes to broader investigations and may help in recovery
- Your cyber insurance carrier: If you have cyber insurance, notify them immediately. They often have incident response resources and will need to be involved before major recovery decisions are made
- Regulators: If you operate in a regulated industry (healthcare, finance), there may be mandatory reporting timelines
Arizona’s data breach notification law requires businesses to notify affected residents “in the most expedient time possible.” Getting legal counsel involved early helps you navigate these requirements without creating additional liability.
The Recovery Phase: Getting Back to Normal
Once the immediate crisis is managed, the longer work of recovery begins. This phase is often underestimated. It’s not just about restoring files. It includes:
- Rebuilding compromised systems from verified clean images
- Restoring data in priority order (most critical business functions first)
- Verifying that restored systems are clean before connecting them to the broader network
- Patching or remediating the vulnerability that allowed the attack
- Rotating all credentials, not just the ones you think were compromised
- Testing business operations as systems come back online
Recovery time varies widely. A business with good backups, a solid recovery plan, and a managed IT partner can be substantially back online in 24 to 72 hours. A business without those things may face days or weeks of disruption, with some data permanently lost.
Businesses we work with in the Phoenix area through our managed IT services have documented recovery plans in place before any incident happens. When something does go wrong, the response is faster and the decisions are already made in advance. That difference is measured in hours and dollars.
How Preparation Changes the Outcome
| With a DR Plan | Without a DR Plan | |
|---|---|---|
| Recovery time | 24–72 hours in most cases | Days to weeks, or longer |
| Data loss | Minimal: restore from recent backup | High, potentially permanent |
| Ransom payment | Usually avoidable | Often the only option |
| Decision-making | Pre-documented: clear steps, no chaos | Reactive, stressful, costly mistakes |
| Total cost impact | Contained: IT recovery and limited downtime | Ransom + recovery + legal + reputational damage |
| Re-infection risk | Low: attacker removed before restore | High: attacker may still be present |
The Hard Lesson: Preparation Changes Everything
The single biggest factor in how a ransomware incident plays out is what you had in place before it happened. The businesses that recover quickly share some common characteristics:
- Tested, off-site backups with multiple recovery points
- Endpoint detection tools that can identify and isolate infected systems automatically
- A documented incident response plan that removes ambiguity under pressure
- An IT partner with incident response experience available around the clock
- Cyber insurance that covers ransomware events
None of this is complicated to put in place. It just requires doing it before you need it.
Our cybersecurity services include backup and disaster recovery planning, endpoint detection, and incident response preparation. We work with businesses across the Phoenix metro, including Scottsdale and Glendale, to make sure they have what they need before an attack happens.
Don’t Wait to Find Out How Prepared You Are
Nobody wants to learn their backup strategy didn’t work in the middle of a ransomware recovery. Nobody wants to make a six-figure ransom payment decision without a plan or legal counsel.
The best time to address this is now, before anything happens.
Contact Sirius today to review your backup and disaster recovery plan. We’ll help you identify the gaps and put the right protections in place so that if the worst happens, you’re ready to respond and recover without losing everything.

