Cybersecurity

Ransomware Readiness: Your First-Hour Playbook

July 23, 2026 10 min read
Ransomware Readiness: Your First-Hour Playbook

The ransom note appears on a screen. Then another. Then a third. Within minutes, file names are scrambling, shared drives are locking up, and your team is frozen in place, unsure whether to unplug everything or keep working. This is not a hypothetical — it is a scenario playing out in professional services offices across the Tampa Bay area with increasing regularity.

The difference between a business that recovers in 48 hours and one that never fully recovers almost always comes down to preparation and the decisions made in that first critical hour. This post walks through exactly what to do — minute by minute — and explains why having fractional CTO-level guidance baked into your IT strategy before an incident is the single most important investment a Tampa Bay business can make.


Why the First Hour Is Everything

Ransomware is designed to spread. Modern strains move laterally across networks at machine speed, encrypting not just the infected endpoint but every mapped drive, shared folder, and connected backup it can reach. The attackers behind these campaigns have refined their tools to maximize damage before a human being can even register what is happening.

This is why the first sixty minutes are so disproportionately important. Every minute of inaction is another minute the encryption process runs. Every minute a device stays connected to the network is another potential vector for lateral spread. The organizations that contain damage quickly are the ones that had a plan — and practiced it — before the attack ever happened.

For professional services firms in St. Petersburg, Tampa, and the broader Tampa Bay area, the stakes are especially high. Law firms hold sensitive client records. Healthcare practices carry protected health information subject to HIPAA. Financial services firms manage data covered by the FTC Safeguards Rule. A ransomware incident is not just a technology problem — it is a regulatory, legal, and reputational crisis that unfolds simultaneously.

Having a fractional CTO who has mapped your environment, documented your critical systems, and built an incident response framework means your team has clear instructions before the chaos starts — not after.


Minutes 0–10: Contain First, Investigate Later

The single most important principle in the opening minutes of a ransomware attack is containment over curiosity. Every instinct will tell people to figure out what happened, to check which files are affected, to call the boss. Resist all of it. The priority is stopping the spread.

Isolate Infected Machines Immediately

The moment ransomware is suspected on a device, that device needs to be physically disconnected from the network. Pull the ethernet cable. Disable Wi-Fi. Do not simply log off or shut down — some ransomware strains are designed to accelerate encryption when a shutdown is detected. Isolation without shutdown is the safest first move until your IT team provides specific guidance.

For businesses running a managed IT environment, this is the moment to call your provider. A managed services provider with 24/7 monitoring should already be seeing anomalous activity in your environment. At EasyWayIT, for example, AI-driven threat detection is continuously watching for behavioral patterns consistent with ransomware — unusual file rename rates, mass encryption activity, and lateral movement attempts. That monitoring shortens the window between infection and detection dramatically.

Disable Network Shares and Remote Access

If your IT team or managed service provider can be reached immediately, the next action is disabling VPN access and remote desktop connections at the firewall level. Ransomware frequently uses these pathways to spread to additional systems or to allow the attacker to maintain access. Cutting remote pathways limits the blast radius.

For businesses without a managed IT provider on call, this step requires someone who knows the network architecture — which is exactly why a fractional CTO who has documented your environment and knows where the kill switches are makes such a difference in a crisis.

Do Not Pay — Yet

The ransom note will typically include a countdown timer and instructions for payment in cryptocurrency. Do not engage with the payment process in the first hour. Payment does not guarantee decryption, and paying too quickly without understanding the scope of the attack can actually complicate recovery. More importantly, payment may not even be necessary if your backups are intact — which you will not know until containment is complete.


Minutes 10–25: Assess the Scope Without Making It Worse

Once infected machines are isolated and remote access is locked down, the next phase is understanding what you are dealing with — carefully.

Identify the Strain

If you can safely access a non-infected machine, screenshot or photograph (with a phone) the ransom note. The wording, file extension changes, and any identifiers in the note can help your IT team or incident response specialists identify the specific ransomware strain. Different strains have different behaviors, different encryption methods, and sometimes available decryption tools. Sites like No More Ransom (nomoreransom.org), a legitimate public resource operated in partnership with law enforcement agencies, maintain a database of decryptors for certain known strains — though no single resource covers every variant, and a decryptor may not exist for the strain you encounter.

Take Stock of What Is Encrypted — and What Is Not

Work with your IT team to identify which systems appear affected and which do not. Prioritize understanding the status of your backups. This is the moment your backup and disaster recovery solution either becomes your hero or your nightmare.

Businesses using an immutable, air-gapped backup solution — such as those built on the Datto platform — are in a fundamentally different position than businesses whose backups were also mapped as network drives. Datto's architecture is specifically designed to make backups highly resistant to ransomware running on the production network, significantly reducing the risk that backup data will be compromised. If your backups are intact, recovery is a matter of time and process, not ransom.

Preserve Forensic Evidence

As tempting as it is to start wiping and rebuilding immediately, preserve what you can. Do not delete logs, do not reformat drives, and do not clear event viewer records on affected machines. Law enforcement, cyber insurance carriers, and incident response forensics teams will need this data. Taking photographs of ransom notes and affected screens before any remediation begins is a simple but important step.


Minutes 25–45: Notify the Right People

This phase runs in parallel with technical containment — while your IT team is working the technical side, leadership needs to be activating the human response chain.

Internal Notification

All staff need to be informed immediately — not with panic-inducing detail, but with clear instructions: do not open any new emails, do not connect any personal devices to the network, do not attempt to access shared files, and report any unusual activity on their workstations to IT immediately. A brief, calm all-staff message sent via a channel that does not rely on your potentially-compromised network (a group text, for example) is appropriate.

Cyber Insurance

If your business carries cyber liability insurance — and every professional services firm in Tampa Bay should — call your carrier or broker in the first hour. Most cyber insurance policies have specific notification requirements with time windows. Missing those windows can complicate or even void a claim. Your carrier may also have a panel of preferred incident response firms that you are required to use for coverage to apply.

A fractional CTO who has worked through your IT security posture and compliance requirements will have already mapped your cyber insurance requirements and built them into your incident response plan. This is not a detail to figure out during a crisis.

Regulatory Obligations

Depending on your industry, a ransomware incident may trigger notification obligations. Healthcare practices operating under HIPAA, financial firms subject to the FTC Safeguards Rule, and businesses holding Florida residents' personal data under FIPA may all have reporting requirements with specific timing and trigger conditions. Get your legal counsel on the phone as early as possible. Whether and when notification is required is a legal determination — not an IT one — and the specific rules, triggers, and deadlines should not be assumed without qualified legal advice tailored to your situation.


Minutes 45–60: Begin Controlled Recovery Planning

By the end of the first hour, containment should be largely in place, the scope should be partially understood, and the right people should be notified. Now the work of recovery planning begins.

Prioritize Critical Systems

Not everything needs to come back online simultaneously. Work with your IT team to identify which systems are mission-critical and sequence recovery accordingly. For a law firm, this might be the practice management system and email. For a medical practice, it might be the EHR and scheduling system. Recovery sequencing should be documented in your incident response plan before an attack, not improvised during one.

Determine Clean Restore Points

With backup integrity confirmed, your IT team will identify the most recent clean restore point — the last backup taken before the ransomware began encrypting files. Depending on your backup frequency, this could mean losing minutes of data or hours. Businesses with continuous or near-continuous backup solutions lose far less than those running nightly backups.

An Illustrative Scenario (Hypothetical)

To make the playbook concrete, consider this entirely hypothetical example — it does not represent any real client or actual event. Imagine a professional services firm that experiences a ransomware attack on a Tuesday morning. Because they had invested in managed IT services with 24/7 monitoring, anomalous activity was flagged shortly after the first encryption event. Their managed IT provider remotely isolated the affected endpoints before the ransomware could reach the file server. Their immutable backup was intact. By following a pre-built incident response plan — including prompt cyber insurance notification and early engagement of legal counsel on regulatory questions — they were able to begin restoring critical systems without paying a ransom. This scenario is purely illustrative. Actual recovery timelines, data exposure determinations, and regulatory obligations vary with every incident and depend on facts and legal analysis specific to each situation. No particular outcome can be guaranteed.


Building Ransomware Readiness Before You Need It

Everything described in this playbook works better — often dramatically better — when it has been planned, documented, and tested in advance. That is the core value of fractional CTO services for professional services firms that are not large enough to employ a full-time CISO or CTO but are absolutely large enough to face serious cyber risk.

A fractional CTO brings enterprise-grade strategic thinking to your technology environment at a fraction of the cost of a full-time hire. At EasyWayIT, fractional CTO engagements include building technology roadmaps, conducting IT security assessments mapped to your cyber insurance requirements, supporting compliance with HIPAA, FTC Safeguards, and FIPA, and creating the incident response documentation that makes the difference when a ransomware attack hits.

Beyond strategic planning, the combination of 24/7 AI-driven monitoring, immutable backup and disaster recovery, endpoint protection, dark web monitoring, and security-awareness training for your staff creates layers of defense that make ransomware both harder to execute and faster to contain when it does occur.

The businesses in Tampa Bay that will fare best in the ransomware landscape are not the ones with the biggest IT budgets — they are the ones that have made deliberate, well-guided investments in preparation. That preparation starts with understanding where you stand today, which is exactly what a professional IT security assessment is designed to reveal. If you are not certain your business could execute this playbook right now, the smartest next step you can take is to Get your free IT security assessment.

Written with AI assistance, directed and reviewed by Gino Laitano for EasyWayIT.
Share:
ransomwarecybersecurityincident responsefractional CTOmanaged ITTampa Baybackup and recoveryHIPAAcyber insurance