Incident readiness

If Ransomware Hits at 4:00 PM on a Friday: The First-24-Hours Small Business Checklist

A small business ransomware readiness recipe for the first 24 hours after a suspected incident.

Last Reviewed: July 2026 | Author: Aaron House

Problem

Small businesses often know backups matter, but they do not always know who can make decisions, who calls insurance, which systems are critical, or what should not be touched.

Why it matters in 2026

Ransomware response windows are short, and bad first-day decisions can destroy evidence, spread impact, or delay recovery.

Who this affects

Step-by-step recipe

  1. Identify who can declare an incident.
  2. Disconnect affected systems without wiping evidence.
  3. Contact insurance, legal, and technical responders as applicable.
  4. Preserve logs, ransom notes, and timestamps.
  5. Verify backup status before restoring.
  6. Track every decision and communication.

Common mistakes

Downloads and next steps

DIY next step

Write down the first five calls your business would make during an incident.

CyberHouse CTA

Want us to handle this for you? CyberHouse can help with Microsoft 365 protection, cyber risk cleanup, ransomware readiness, secure automation, and vendor-ready cyber baseline work.

Visit CyberHouse

Related Recipes