
If screens lock and files become .encrypted spaghetti, the first hour decides whether you recover in a day or a month. Panic reinstalls and “just pay them” texts to the CEO are how bad situations get worse.
First hour checklist
- Disconnect affected devices from Wi‑Fi and Ethernet (do not wipe yet)
- Preserve evidence—photograph ransom notes; do not delete logs casually
- Call your IT partner / incident contact before negotiating anything
- Identify what is offline vs still clean; stop lateral movement
- Check backup integrity from a safe system—do not log into backup consoles from infected machines
What not to do
- Do not power-wash every drive before someone scopes the blast radius
- Do not pay from a personal card because “it is only Bitcoin”
- Do not reuse the same passwords after recovery without a reset plan
After the dust settles
- Rotate credentials and review MFA enrollments
- Patch the initial access hole (VPN, email, RDP, vendor account)
- Document timeline for insurance and leadership
- Schedule a restore test so the next incident is shorter
CISA’s ransomware response resources: StopRansomware. FBI IC3 for reporting: ic3.gov.
If you need hands-on help in the Hudson Valley, contact SabatAge or call (845) 475-8468. Also review backups before you need them.
Need help putting this into practice for your business? Contact SabatAge or call (845) 475-8468. We support Hudson Valley and Orange County businesses with practical security and managed IT.
First-hour leadership checklist
Leaders should decide who speaks externally, who authorizes network isolation, and who contacts insurance or law enforcement. Technical staff should preserve evidence when possible while stopping spread. Write this before you need it.
- Name an incident lead and a communications lead
- List critical systems and restore priorities (billing, email, production)
- Have ISP, MSP, and insurance contacts offline as well as online
- Practice the first hour once a year with a tabletop scenario
If you want this handled end-to-end—not as another checklist on a shelf—talk to SabatAge Fully Managed IT or call (845) 475-8468. We support Hudson Valley and Orange County businesses with monitoring, security, and practical guidance.
After the first hour
Once spread is stopped, shift to restore order, credential resets, and a written timeline. Schedule a blameless review within two weeks: what worked, what slowed you down, and which backup or MFA gap to fix first. Incidents become training only if you capture lessons.

No responses yet