Incident response
Ransomware in an SMB: what to do in the first 60 minutes
August 18, 2026· 5 min
In short
Unplug the affected machine from the network without powering it off, cut file shares, rotate administrator credentials, preserve logs, and only then restore. Powering off destroys RAM — often the only place the encryption key still lives.
Do not power off — isolate
Network isolation stops propagation while preserving machine state. A local EDR does it automatically, without waiting for an analyst to log in from home at 3 a.m.
Protect backups before restoring
Attackers target backups first. Verify an offline or immutable copy exists and predates the first sign of compromise, not merely the ransom note.
Document during, not after
Every decision taken in the heat of the moment must be timestamped. That is what convinces the insurer — and what saves you from reconstructing a vague story three weeks later.
On the same topic