Ransomware Hit Your Business: The First 24 Hours

Updated August 25, 2026

A server rack with status lights in a dark room

Ransomware attacks on small businesses rose 68% in 2025, and average demands now exceed $120,000 before you count downtime. The grim number is this: 43% of small businesses that pay, or fail to recover, close within six months. The first hours decide a great deal.

Hour one

  1. Disconnect, do not power off. Pull network cables and turn off Wi-Fi on affected machines. Shutting down can destroy evidence held in memory and, on some variants, corrupt files that were mid-encryption and still recoverable.
  2. Isolate the backups first. Modern ransomware hunts for backups deliberately. If your backup drive is plugged in or your backup account is reachable from an infected machine, disconnect it before anything else.
  3. Stop using the shared drive. One machine still writing to it keeps the spread going.
  4. Write down the time you noticed and what you saw. You will need this for insurance and possibly for police.

Do not pay yet

Paying is a business decision, not a technical one, and it should never be the first move. Payment does not guarantee a working decryption key, it marks you as someone who pays, and depending on who is behind the attack it can carry legal exposure. Establish what you can restore before you even open that conversation.

What decides recovery

Almost entirely: whether you have a backup the ransomware could not reach. That means a copy that is offline, or on a service with versioning the attacker's credentials cannot delete. A backup drive left permanently plugged in is usually encrypted along with everything else.

Then, the entry point

Most ransomware starts with a person: a phishing email, a fake invoice, or — the fastest-growing route — a phone call to whoever handles IT, impersonating a member of staff to get a password reset. Restoring without finding the way in usually means being encrypted again within weeks.

Prevention worth its cost

  • One backup that is offline or immutable, tested by actually restoring something.
  • Two-factor authentication on email and any remote access. This alone blocks most credential attacks.
  • Staff who know that a request to change bank details always gets a phone call.
  • Updates applied, particularly to anything reachable from the internet.

If any of this is beyond where you want to go on your own, a Koadi technician can take it from here — remotely anywhere in the US, or on-site in New Jersey, New York and Pennsylvania. Describe the problem in your own words and someone who does this every day will pick it up.

Still stuck?

Post this problem on Koadi — a vetted technician picks it up in minutes, and you don't pay until it's fixed.

Get a tech on it
← All fix-it guides