Ransomware on Your Screen? A Recovery Playbook for Small Businesses

Table of Contents

Ransomware on your screen? Stay calm—and start your response plan. An employee cannot open files. A ransom note appears. Several shared folders stop working. For a small business owner, the immediate question is: “What do we do now?”

This practical playbook expands BCS’s guides on what happens during a cyberattack and what happens after a cyberattack. Use it to prepare your team in Austin or Houston before an emergency.

Download the Ransomware Response Checklist (PDF)

Print this one-page guide, fill in your emergency contacts, and keep it accessible when normal systems are unavailable.

Four steps to remember

  1. Disconnect: isolate affected devices.
  2. Call for help: activate your response team.
  3. Protect and investigate: safeguard backups and determine the scope.
  4. Recover: rebuild clean systems and restore verified data.

Do not delete files, wipe computers, or begin restoring on your own.

1. Disconnect affected devices

Remove Ethernet connections and disconnect Wi-Fi. If a device is safely isolated, leave it powered on so responders can preserve evidence. If network isolation is impossible, power it down to limit spread. This distinction matters: “never shut down” is not a safe blanket rule.

Let your response lead coordinate broader network containment. A single workstation may be the first visible symptom, rather than the full extent of the incident.

2. Call your response lead from a clean phone

Contact your internal IT lead or managed service provider using a device you believe is unaffected. Notify the owner or designated incident manager. Follow your cyber insurance policy’s reporting process and involve legal counsel when needed.

Give the response team useful facts: who noticed the problem, when it appeared, which device was involved, and what stopped working. Preserve the ransom note and affected files. Avoid clicking attacker links or experimenting with repair tools.

Example: A receptionist sees a ransom message. Their job is to report it promptly and follow isolation instructions—not to diagnose every server. Clear roles keep a stressful situation manageable.

3. Protect backups and investigate the scope

Your response team should protect backup systems, preserve recovery copies, and investigate affected devices and accounts. Keep backup media away from infected systems.

Cloud file synchronization is not automatically an independent backup. Ask your team to identify protected recovery points and test whether the data can actually be restored.

A useful preparation question is: “Who can change or delete our backups?” Document the answer before an incident, along with who can approve a recovery.

4. Recover into a clean environment

After containment and evidence collection, responders can rebuild clean systems and restore verified backups. Close the entry point and address compromised access before reconnecting systems. Prioritize essential business services and validate them before wider rollout.

Restoring a folder does not prove the incident is over. Business owners should ask for a clear recovery decision: what has been checked, what remains uncertain, and who approved the next step.

What about paying the ransom?

The FBI advises against payment. Paying does not guarantee that your data will be returned. Report ransomware to your local FBI field office or IC3. Leave any discussion of ransom demands to leadership, incident responders, your insurer, and legal counsel.

Practice before an emergency

Build a contact sheet with your IT response lead, insurance carrier, and manager or owner. Keep a copy accessible when normal systems are unavailable.

Run a tabletop exercise: What if files become unavailable on a Friday afternoon? Who makes the call? Who approves downtime? Which service must return first? A short practice session can expose gaps in ownership and communication.

Ransomware readiness for Austin and Houston businesses

Business Communication Solutions helps businesses review cybersecurity gaps, prepare response plans, and practice incident decisions. Explore our cybersecurity services and downloadable guides.

Call BCS before an emergency:
Austin: 512-257-1433
Houston: 281-815-8784

This guide is general information. Follow your incident response plan and coordinate with qualified responders, your insurer, and legal counsel.

Response resources