Problem
Small businesses often know backups matter, but they do not always know who can make decisions, who calls insurance, which systems are critical, or what should not be touched.
Why it matters in 2026
Ransomware response windows are short, and bad first-day decisions can destroy evidence, spread impact, or delay recovery.
Who this affects
- Owners without a formal incident response plan.
- Lean teams responsible for critical systems.
- Businesses with cyber insurance or vendor obligations.
Step-by-step recipe
- Identify who can declare an incident.
- Disconnect affected systems without wiping evidence.
- Contact insurance, legal, and technical responders as applicable.
- Preserve logs, ransom notes, and timestamps.
- Verify backup status before restoring.
- Track every decision and communication.
Common mistakes
- Rebooting or wiping systems too early.
- Restoring from backups before understanding entry points.
- Letting one person hold all response knowledge.
Downloads and next steps
Printable PDFDownload Ransomware First 24 Hours ChecklistCompanion ProductRansomware First-24-Hours KitRelated RecipesContinue learningCyberHouse AssessmentGet implementation help
DIY next step
Write down the first five calls your business would make during an incident.
CyberHouse CTA
Want us to handle this for you? CyberHouse can help with Microsoft 365 protection, cyber risk cleanup, ransomware readiness, secure automation, and vendor-ready cyber baseline work.
Visit CyberHouseRelated Recipes
30-Point Cyber Risk ChecklistA practical cyber risk checklist for small businesses reviewing Microsoft 365, email security, vendors, backups, ransomware readiness, and AI use.Virginia B2B Contractor Vendor Assessment GuideA practical readiness guide for Virginia B2B contractors preparing for customer vendor cyber assessments in 2026.SPF, DKIM, and DMARC Audit RecipeA practical recipe for auditing outbound email authentication across SPF, DKIM, and DMARC.
