Your outsourced IT department, serving NJ & NYC small businesses
North Jersey IT Insights

The First 24 Hours of a Ransomware Attack: An NJ Small Business Guide

What you do in the first day determines whether this is a bad week or the end of your business. Save this playbook before you need it.

The call usually comes in before 8 a.m., because ransomware crews like to detonate overnight and on weekends when no one's watching. An office manager turns on her PC and every file ends in a strange extension, with a text file on the desktop explaining how to buy Bitcoin. If that's you right now: breathe, don't pay anything, don't wipe anything, and work through this timeline. Setnom's emergency line is (646) 719-0490, we take these calls from businesses across North Jersey whether or not they're clients.

Hour 0-1: Isolate. Don't investigate, don't reboot.

Ransomware spreads across the network for as long as it can reach other machines, so your first hour is about cutting it off:

  • Disconnect affected machines from the network, pull the Ethernet cable, kill the Wi-Fi. If you can't tell which machines are hit, disconnect the switch or shut off Wi-Fi at the access points.
  • Do not power machines off. This surprises people. Encryption keys and attacker tooling sometimes live only in memory, and forensic teams may need it. Disconnect, don't shut down.
  • Physically unplug backup drives and NAS devices immediately, if the crew hasn't found them yet, this is the single most valuable 60 seconds of your day.
  • Change critical passwords from a clean device (a phone on cellular data works): Microsoft 365 admin, banking, payroll.

Resist the urge to "look around" on infected machines. Every click potentially overwrites evidence your insurer's forensic team will want.

Hour 1-2: Call your insurer first, then your IT provider

The order matters. If you carry cyber insurance, your policy almost certainly has a 24/7 breach hotline, and most policies require you to use the carrier's approved incident response vendors. Businesses that bring in their own help first sometimes find those invoices aren't covered. Call the hotline, get a claim number, and write down what they authorize.

Then call your IT provider. If you have a managed IT partner, they should already know, modern EDR pages the provider when mass encryption starts, which is exactly the scenario it exists for. If your "IT guy" isn't answering at 7 a.m. on a Saturday, that's a lesson for later; we wrote about that pattern in 7 signs you've outgrown your IT guy.

Hour 2-4: Preserve evidence and scope the damage

Photograph the ransom note on screen with your phone. Keep one encrypted machine untouched as evidence. Start an incident log, a simple running note of what happened when and who did what. It feels bureaucratic at the time; it becomes priceless for the insurance claim, for the forensic team, and for New Jersey's notification analysis below.

Meanwhile, scope it: which machines, which servers, which shared drives? Crucially, was data stolen or just encrypted? Most ransomware crews now exfiltrate data before encrypting and threaten to publish it. The answer changes your legal obligations entirely.

Hour 4-8: Assess your backups, honestly

Three questions, in order. Do backups exist for the encrypted data? Are the backups themselves clean, or did the crew encrypt or delete them too (they look for backups first)? And how old is the most recent clean copy? A business with verified, immutable cloud backups answers these in 30 minutes and starts restoring the same day. A business with a USB drive that was plugged into the server is usually discovering, right now, that its backups died with everything else. This is also the moment that determines whether you'll ever face the ransom question at all.

Hour 8-12: Understand your New Jersey legal duties

New Jersey's Identity Theft Prevention Act (N.J.S.A. 56:8-163) requires businesses that hold New Jersey residents' personal information, names combined with Social Security numbers, driver's license numbers, account credentials, and similar identifiers, to notify affected individuals if that data was, or is reasonably believed to have been, accessed by an unauthorized person. Critically, NJ also requires you to report to the Division of State Police before notifying customers. If you have employees, you almost certainly hold covered data (payroll records alone qualify), so "we're just a small shop" doesn't exempt you.

This is the hour to engage a privacy attorney, your cyber policy typically pays for one (a "breach coach"). Don't send any customer communication before counsel reviews it. Notification decisions made casually in hour 8 create liability that outlasts the incident by years.

Hour 12-24: The recovery decision tree

By now you have the facts, and the path forks in three directions:

  • Clean backups exist → rebuild and restore. Wipe or replace infected machines, restore data, reset every credential, and close the entry hole (usually a phished account or an unpatched remote access point) before reconnecting anything. Expect 2-5 days to full operation for a typical small office.
  • Backups are partial → restore what you have, reconstruct what you can from email attachments, accountant copies, and vendor portals. Painful but survivable.
  • No usable backups → now, and only now, does the ransom conversation happen, jointly with your insurer, attorney, and a negotiation firm. Know the honest odds: payment is typically a five-to-six-figure event, decryption tools are slow and buggy, and a meaningful share of payers don't get all their data back. It's a last resort, not a shortcut, and certain payments to sanctioned groups are federally prohibited. Your insurer's team navigates all of this, another reason they were call number one.

The uncomfortable truth: day one is decided years earlier

Every fork in that decision tree is determined by choices made before the attack, whether MFA was enforced, whether backups were immutable and tested, whether EDR caught the encryption at machine three instead of machine thirty. Those happen to be the exact controls insurers now demand, which we walked through in our cyber insurance requirements guide. A prevention-first security stack costs a fraction of one incident's deductible.

We help businesses across Hudson County and all of North Jersey build (and rehearse) this playbook before it's needed. More guides on the Setnom blog, or book a free assessment and we'll pressure-test your ransomware readiness this month, not after.

Before it happens

The five things to have ready today

You can't build any of these during the attack. Every item on this list exists so that your worst day runs off a script instead of panic.

  • A printed contact sheet Insurer breach hotline, IT provider, attorney, and bank, on paper, because your files will be encrypted.
  • Immutable, tested backups Offsite copies ransomware can't touch, with a restore test logged in the last 90 days.
  • EDR with isolation Endpoint protection that can quarantine a machine automatically at 3 a.m.
  • MFA on everything Most ransomware enters through one phished password. MFA breaks that chain.
  • A written response plan This timeline, adapted to your business, with names attached to each step.
Get started

Don't write your ransomware plan during the attack.

Book a free assessment and we'll evaluate your backups, security stack, and response readiness, then fix the gaps while it's still cheap to fix them.

Book Your Free IT Assessment

Tell us a little about your business and we'll be in touch within one business day.

No spam. No sales pressure. Just straight answers about your IT.

Call Now Get My Risk Score