Contain affected systems
Disconnect suspected devices from the network without wiping them so evidence and recovery options remain intact.
Incident checklist
The first hours of a ransomware event are confusing. A checklist helps the business contain damage, preserve evidence, and avoid destroying recovery options.
Disconnect suspected devices from the network without wiping them so evidence and recovery options remain intact.
Identify decision makers, legal/compliance contacts, cyber insurance contacts, and the technical response lead.
Verify backup access and isolate backup systems before attackers or malware can damage recovery data.
Decide which systems must return first based on revenue, safety, customers, and operational dependency.
Keep notes on ransom messages, affected devices, timestamps, accounts used, and recovery actions.
After restoration, review MFA, patching, remote access, endpoint protection, segmentation, and user reporting.
Checklist
FAQ
That decision requires legal, insurance, and executive guidance. The technical priority is containment, evidence preservation, and restore-path validation.
Yes. That is why backup access, immutability, segmentation, and restore testing matter before an incident.
Yes. We can help stabilize systems, coordinate recovery, validate backups, and build a hardening roadmap after the immediate crisis.
Free Network Assessment
Velocity reviews users, devices, Microsoft 365, backups, network gear, vendors, and support readiness for Phoenix and East Valley SMBs.