Aller au contenu

Incident response

Ransomware in an SMB: what to do in the first 60 minutes

August 18, 2026· 5 min

In short

Unplug the affected machine from the network without powering it off, cut file shares, rotate administrator credentials, preserve logs, and only then restore. Powering off destroys RAM — often the only place the encryption key still lives.

Do not power off — isolate

Network isolation stops propagation while preserving machine state. A local EDR does it automatically, without waiting for an analyst to log in from home at 3 a.m.

Protect backups before restoring

Attackers target backups first. Verify an offline or immutable copy exists and predates the first sign of compromise, not merely the ransom note.

Document during, not after

Every decision taken in the heat of the moment must be timestamped. That is what convinces the insurer — and what saves you from reconstructing a vague story three weeks later.