An employee just told you they clicked a link they shouldn't have. Your first move is to disconnect that device from the network — unplug the ethernet cable or turn off Wi-Fi — without shutting it down or restarting it, because powering off can erase evidence and, with some ransomware strains, can actually trigger the damage rather than stop it. From there, the response follows a specific order: gather what actually happened, isolate the machine at the network level if you have IT support, escalate to your provider, and reset passwords starting with email, from a different device entirely. None of this is complicated once you know the sequence — the danger is improvising it under pressure.
This guide is built for the moment right after it happens, whether you're the employee who clicked, the manager they told, or the IT person who just got the call. It walks through the first 15 minutes in detail, then the fuller response over the following hours and days: what to check for signs of deeper compromise, what changes if this turns into ransomware, when a click becomes a reportable privacy breach under Canadian law, and how to close the loop afterward without turning your workplace into a place people are afraid to report the next one. If you're trying to determine whether your systems show broader signs of compromise beyond this single click, our is my computer hacked warning signs guide covers the detection side in more depth; if you want the background on how these links get sent in the first place, see our what is phishing guide.
Who wrote this guide
This article was written and reviewed by IT Cares certified technicians based on the emergency calls we field from Canadian businesses in exactly this situation — usually within minutes of the click, sometimes mid-panic. The sequence below is the same one our technicians walk clients through on the phone before we've even remoted in, because the first few minutes matter more than anything a technician can do after the fact.
The First 60 Seconds: What to Do Immediately
Everything that happens in the first minute sets the tone for everything after it, so it's worth being precise about exactly what to do, and just as importantly, what not to do.
Stop clicking
The instinct when something looks wrong is to try to fix it — close the pop-up, click "cancel," try the link again to "see what it actually does." Resist all of that. Every additional click is a fresh opportunity for a malicious page to trigger another action, and closing a fake warning by clicking anywhere on it, including an apparent "X," can itself be the action that starts a download. Stop touching the mouse and keyboard beyond what's needed to disconnect the machine from the network.
Disconnect from the network — physically, if possible
Unplug the ethernet cable if the device is wired in, or turn off Wi-Fi from the network settings if it's wireless. If you're not confident finding the Wi-Fi toggle quickly under pressure, physically switching off the machine's Wi-Fi hardware switch (many laptops have one) or simply putting the device in airplane mode works just as well. The goal is singular: cut off the device's ability to talk to anything else on your network or the internet, immediately, before whatever was triggered has a chance to communicate out, download something further, or spread.
Do NOT shut down or restart the computer — and here's why that matters
This is the step people get wrong most often, because shutting the computer off feels like the obviously safe move. It isn't, for two specific reasons. First, a device's memory (RAM) holds information that vanishes the instant power is cut — running processes, active network connections, and evidence of exactly what a piece of malware was doing at that moment. If a forensic investigation is needed later, that volatile memory is often the single most useful source of truth about what actually happened, and it's gone forever the second the machine powers down. Second, and more urgently, some ransomware strains are specifically engineered to complete or accelerate their file encryption routine when the machine shuts down or during the next startup, precisely because security teams have historically reached for the power button as a first reaction. Disconnecting from the network stops an attacker's ability to communicate with the device; shutting it down does not achieve that, and can make things measurably worse. Leave the machine powered on and disconnected, full stop.
Don't panic-click anything else on the screen
If a warning, a countdown, a "your files have been encrypted" message, or any other prompt is on screen, leave it exactly as it is. Don't try to close it, don't screenshot it by clicking through menus you're unfamiliar with, and don't try to open Task Manager to "kill the process" unless you already know precisely what you're doing — untrained attempts to intervene can trigger exactly the outcome you're trying to prevent. A photo taken with a phone camera of what's on the screen is a safe, useful way to capture what's showing without touching the keyboard further.
📊 IT Cares field note: On nearly every emergency call we take for this exact scenario, the caller's first question is "should I turn it off?" The answer is almost always no, and explaining why — memory evidence, shutdown-triggered encryption routines — is usually the single most useful thing we say in the first thirty seconds of the call, because it's also the thing callers are most likely to do wrong on instinct alone.
Need a technician on this right now?
IT Cares offers emergency remote response for exactly this situation — a certified technician can assess the device and guide your next step within minutes.
If You're IT: Isolating the Machine at the Network Level
Physically disconnecting the device is step one, but if you have any IT support — internal or an MSP — a second layer of isolation at the network level matters too, especially if there's any chance the device reconnects automatically or someone else in the office plugs it back in without knowing why it was unplugged.
Disable the switch port
If the device connects through a managed switch, disable the specific port it's plugged into from your switch's administration interface. This stops the device from rejoining the network even if someone plugs the ethernet cable back in without realizing what happened, which is a more common failure mode than people expect in a busy office.
Remove it from Wi-Fi at the access point or controller
For wireless devices, don't rely solely on the device's own Wi-Fi toggle — block the device's MAC address at your router or wireless controller level, or temporarily change the Wi-Fi password if your environment doesn't support per-device blocking. This closes the gap where a device silently reconnects to Wi-Fi in the background the moment its own radio is turned back on.
Move it into a quarantine VLAN if you have one
Businesses running a segmented network with a quarantine or guest VLAN can drop the affected device into that segment, which isolates it from internal file shares, servers, and other workstations while still allowing controlled remote access for your IT team or MSP to investigate. This is the cleanest option when available, because it lets an investigation proceed without leaving the device completely dark.
Check what else that device could reach
While isolating the device, take stock of what it had access to — shared network drives, cloud storage sync folders, VPN connections, admin credentials saved in a browser or password manager. This isn't about panicking over every possibility; it's about building an accurate list of what needs checking next, so the investigation that follows is targeted rather than a blind guess.
What Information to Gather Immediately
While the device sits safely disconnected, the next priority is capturing what actually happened while it's still fresh in the employee's memory — this becomes the single most useful piece of information for whoever handles the technical response next, whether that's your internal IT person or an outside provider on the phone.
- What was the link or attachment, specifically? The exact text of the email or message if it's still visible in another window, who it appeared to be from, and what it claimed to be (an invoice, a shipping notice, a login alert, a message from a colleague).
- What did the employee actually see happen? A web page loading and asking for a login, a file downloading, a document opening with a security warning, or nothing visible at all — each of these points investigators toward a different likely outcome and a different set of things to check.
- Was anything typed in? A username, a password, a one-time code, payment details — and if so, which account or system that login belongs to. This single detail changes the entire priority order of what happens next.
- Roughly what time did this happen? Even an approximate time helps narrow down which network and system logs matter most when someone starts reviewing them.
- Has anything seemed unusual since? Unexpected pop-ups, the computer running slower, files that won't open, or anything else out of the ordinary in the minutes since the click.
None of this requires technical expertise to gather — it's simply a matter of asking the employee calmly, in plain language, without making them feel like they're being interrogated. The quality of the response that follows depends heavily on how complete and honest this initial account is, which is exactly why the tone of this conversation matters as much as the content.
When to Escalate to Your MSP or IT Provider vs. Handling It Internally
Some clicks genuinely resolve themselves with nothing more than a disconnected device and a quick look-over; others need a professional response immediately. Knowing which is which saves precious time.
Escalate immediately, without trying to resolve it yourself first, if: any credentials were entered on the fake page; a file was downloaded and opened, or a program installation was triggered; you see any indication of ransomware — a ransom note, files that suddenly won't open, or file extensions that have changed; the device has access to shared drives, client data, financial systems, or admin-level accounts; or you simply aren't confident assessing what happened on your own. None of these are situations where "let's just keep an eye on it" is an acceptable response — the cost of escalating and finding out it was minor is trivial compared to the cost of not escalating and finding out it wasn't.
It's reasonable to do a first-pass check internally, with escalation available as a backup, if: the employee is confident a page loaded but they closed it without entering anything or downloading anything; the device has limited access (no shared drives, no saved admin credentials, a standard user account rather than an administrator); and someone with at least basic IT competence can properly check for signs of compromise using the guidance later in this article. Even in this lower-risk case, having your MSP's number ready and being willing to call at the first sign of anything unusual is the right posture — "start cautious, escalate fast" beats "wait and see" every time in this specific situation.
When you do call your MSP or IT provider, come prepared with the information gathered in the previous section — what was clicked, what the employee saw, whether credentials were entered, and roughly when it happened. A provider who receives "someone clicked something, not sure what" spends the first ten minutes of the call just getting to the starting line that a prepared caller reaches instantly.
Password Reset Priorities — From a Different Device, In This Order
If there's any chance credentials were entered, or if you can't be fully sure they weren't, password resets need to happen — but the order and the device you use both matter more than people usually assume.
Always reset from a different, clean device
Never reset a password on the same device that may be compromised. If something was installed that logs keystrokes or captures screen activity, typing a brand-new password on that same device hands the attacker the new password just as easily as the old one. Use a phone, a different computer, or any device you're confident wasn't involved.
Email first
Email is almost always the recovery path for everything else — banking, business applications, cloud storage, other logins — so it's the single highest-priority reset. If an attacker has access to email, they can typically reset nearly every other password themselves using "forgot password" links, which is exactly why email goes first, not last.
Financial and banking systems
Business banking portals, payroll platforms, and accounting software logins come next, given the direct financial exposure if these were compromised. Where possible, also contact your bank directly to flag the account for extra monitoring rather than relying solely on a password change.
Other business systems
CRM, shared drives, cloud storage, VPN access, and any other application the employee's account touches, roughly in order of how sensitive the data behind each one is. Enable multi-factor authentication anywhere it isn't already active as part of this pass, not as a separate later task.
Notify anyone with shared or delegated access
If the compromised account had delegated access to shared mailboxes, calendars, or files, or if other staff use a shared login tied to the same credentials, make sure they know a reset happened and why, so no one is locked out unexpectedly or confused about what changed.
Checking for Signs of Compromise
Whether you're handling this internally or your IT provider is, these are the specific things worth checking on and around the affected device once it's safely isolated, to understand whether the click actually led anywhere or simply loaded a page that did nothing.
Unusual outbound network traffic
Before fully isolating the device, or from firewall and router logs afterward, unusual outbound connections — especially to unfamiliar IP addresses or countries your business has no reason to be communicating with — are one of the clearest signs that something on the device tried to phone home to an attacker's infrastructure.
New scheduled tasks or startup entries
Malware frequently establishes persistence by creating a scheduled task or a startup entry so it survives a restart. Checking Task Scheduler on Windows, or the equivalent startup items and launch agents on a Mac, for anything unfamiliar that wasn't there before is a quick, meaningful check.
New administrator accounts
A new local or domain administrator account that nobody on your team created is a serious red flag, since it typically means an attacker is trying to establish a persistent foothold that survives even a full password reset on the original compromised account.
Unfamiliar processes running
Reviewing Task Manager (Windows) or Activity Monitor (Mac) for processes with unusual names, high and unexplained resource usage, or anything that doesn't match software your business actually uses can surface something running in the background that a casual glance at the desktop would never reveal.
Genuinely, this step is where professional help earns its cost — a trained technician can distinguish a legitimate background process from a disguised malicious one far more reliably than most non-specialists, and a device that "looks fine" on the surface can still be actively compromised underneath. If you want a straight answer rather than a guess, IT Cares can check the device remotely and tell you plainly what was found.
First 15 Minutes — Employee Clicked a Malicious Link Checklist
- Stop clicking anything else on the screen, including "close" or "cancel" buttons on any pop-up.
- Disconnect the device from Wi-Fi or unplug the ethernet cable immediately.
- Do NOT shut down or restart the device — leave it powered on and disconnected.
- Take a photo of anything on screen instead of interacting with it further.
- Write down what was clicked, what appeared, and whether anything was typed in.
- Note roughly when it happened.
- If you have IT support, disable the network switch port or remove the device from Wi-Fi at the router level.
- Call your MSP, IT provider, or an emergency IT line if credentials were entered, a file was opened, or you see ransomware signs.
- From a different, clean device, reset the email password first, then financial systems, then other business logins.
- Do not punish or blame the employee — thank them for reporting it quickly.
Response Timeline by Severity: Three Scenarios Compared
Not every click carries the same weight, and the appropriate response scales with what actually happened. This comparison covers three common scenarios in the order of increasing severity.
| Factor | Link clicked, nothing entered | Credentials entered | File downloaded & executed / ransomware signs |
|---|---|---|---|
| Immediate action | Disconnect device, don't shut down, close the page without entering anything | Disconnect device, don't shut down, note exactly which account's credentials were entered | Disconnect device, don't shut down, isolate at network level immediately, do not touch further |
| Escalation | Internal first-pass check reasonable; escalate if anything looks off | Escalate to MSP/IT provider immediately | Escalate to MSP/IT provider immediately, treat as active incident |
| Password resets | Not usually required, but MFA review is still good practice | Immediate, starting with email, from a different device | Immediate and business-wide once scope is understood, from clean devices only |
| Typical resolution time | Under 1 hour | Same day to 24-48 hours | Days to weeks depending on scope and backup recovery |
| Likely cost range (CAD) | $0 – $200 (internal time or a quick remote check) | $150 – $1,500 (remote response, password resets, monitoring) | $3,000 – $50,000+ (forensics, recovery, possible downtime and ransom-related costs) |
The scenario you're actually in isn't always obvious in the first few minutes, which is exactly why the "disconnect first, ask questions second" approach applies across all three columns — you don't need to correctly diagnose the severity before taking the first protective step, because that step is identical regardless of which column you end up in.
If Files Start Showing Signs of Encryption: The Ransomware Scenario
The response changes in a few specific, important ways the moment you see actual ransomware indicators: a ransom note appearing on screen or as a text file in multiple folders, file extensions suddenly changing to something unfamiliar, or files that were working fine an hour ago that now won't open at all.
Isolate further, immediately
Beyond disconnecting the affected device, check whether any shared drives or network locations that device had access to are showing the same signs, and if so, isolate those systems too. Ransomware often spreads laterally across a network within minutes of the initial compromise, so the isolation boundary may need to expand quickly beyond just the one device.
Do not pay the ransom immediately, if at all
Paying a ransom doesn't guarantee you get a working decryption key, doesn't guarantee the attacker won't come back, and in some cases can create legal exposure if the group behind the attack turns out to be under Canadian or international sanctions. This decision should never be made in the first panicked hour — it should come after consulting with an incident response professional, and ideally your cyber insurance provider if you have one, who can assess the actual situation and options properly.
Contact the Canadian Centre for Cyber Security and law enforcement
The Canadian Centre for Cyber Security (cyber.gc.ca) accepts incident reports from Canadian organizations and can provide guidance for significant incidents; report to your local police as well, particularly if you're considering any ransom payment, since law enforcement involvement is often relevant to how that decision gets handled. Also report the incident to the Canadian Anti-Fraud Centre, which tracks patterns across incidents nationally even when a single case doesn't lead to a direct resolution.
Check for backups before assuming the worst
Before any conversation about ransom payment happens, confirm what backup options actually exist — a recent, tested backup that wasn't itself reachable and encrypted by the ransomware (an offline or immutable backup) can make the entire ransom question moot. This is exactly why testing backups regularly, before an incident, matters so much; discovering during a live ransomware event that your "backup" hadn't actually been restorable in months is a devastating moment to learn that.
Seeing ransomware signs right now?
Stop reading and isolate every system you can, then call for help immediately. IT Cares SOS Emergency response is built for exactly this situation, and our technicians can assess scope and options within minutes rather than hours.
When This Crosses Into a Reportable Privacy Breach (PIPEDA)
Not every clicked link triggers a legal notification obligation, but understanding when it does matters, because Canadian federal privacy law carries real consequences for getting this wrong.
Under the Personal Information Protection and Electronic Documents Act (PIPEDA), a business must notify the Office of the Privacy Commissioner of Canada (OPC) and affected individuals when a breach of security safeguards creates a real risk of significant harm — factors that raise this risk include the sensitivity of the personal information involved (financial details, health information, government identification numbers) and the probability that the information has been or will be misused. A click by itself, with nothing entered and no evidence the compromised account or system ever held or could reach personal information, typically doesn't meet that threshold. It becomes a different question entirely if the compromised email account had access to a customer database, if credentials entered on a fake page belonged to a system holding client financial or health records, or if forensic investigation confirms an attacker actually accessed files containing personal information.
The practical approach is to determine the actual scope of access before concluding either way — this is exactly the kind of question a forensic investigation or a knowledgeable IT provider helps answer, since guessing wrong in either direction carries real cost: under-reporting a genuine breach carries legal and regulatory risk, while over-reporting every minor incident as a formal breach creates unnecessary alarm and administrative burden. If notification is required, PIPEDA doesn't specify an exact number of days but requires notification "as soon as feasible" after determining the breach occurred, and the notification to affected individuals needs to be direct enough that they can meaningfully understand and act on the risk to them — a vague, generic notice generally doesn't satisfy the requirement. Businesses operating in Quebec should also be aware that Quebec's own private sector privacy law (Law 25) has its own breach notification obligations, which run in parallel with PIPEDA and, in some respects, are stricter.
Post-Incident: Company-Wide Rotation and Blame-Free Retraining
Once the immediate crisis is contained, the response isn't finished — what happens over the following days determines whether the organization is genuinely more resilient afterward, or just quietly hoping it doesn't happen again.
Rotate passwords more broadly, not just for the affected account
If there's any uncertainty about how far access spread — a shared password used elsewhere, a saved credential in a browser profile, an admin account with broad reach — a wider password rotation across affected systems is worth the short-term inconvenience. This doesn't need to mean every password in the business, but it should cover everything the compromised account or device could plausibly have touched.
Retrain without blame or shame
This is the single highest-leverage thing a business can do after an incident like this, and it's also the step most commonly skipped or done badly. The goal of any follow-up conversation with the employee who clicked should be entirely forward-looking — what made the message convincing, what would help them (and everyone else) spot the next one, not a recap of what they did wrong. An employee who feels safe reporting a mistake immediately is worth far more to your security than an employee who's afraid to, because the single biggest determinant of how much damage a click causes is how quickly it gets reported — and that speed depends entirely on whether people believe reporting it will get them in trouble.
Document the incident properly, especially if you have a cyber insurance policy
Keep a written record: what happened, when, what actions were taken and when, what the investigation found, and what changed afterward. If your business carries cyber insurance, this documentation is exactly what a claim requires, and building it as the incident unfolds is far easier and more credible than reconstructing it from memory weeks later. Even without a policy, this record is genuinely useful institutional memory — it's what turns "we had an incident once" into "here's specifically what we changed because of it."
Reporting should feel like a win, not a confession
The employee who tells you within two minutes of clicking a bad link should hear "thank you for telling me immediately" before anything else. That single sentence, repeated consistently after every incident, does more to prevent the next serious breach than almost any technical control — because it's what determines whether the next click gets reported in minutes or discovered by accident weeks later.
Three Real Canadian Incident Response Case Studies
The following case studies are composite, illustrative scenarios built from patterns common to Canadian small business incident response calls — names and identifying details are fictional, but the response dynamics and dollar figures reflect realistic outcomes.
Case 1 — Northlight Creative, a marketing agency in Laval, Quebec (16 employees)
An account coordinator clicked a link in what looked like a routine invoice email from a familiar vendor, landing on a fake login page before closing it without entering anything, feeling immediately uneasy. She reported it to her manager within three minutes, who disconnected the laptop from Wi-Fi and called Northlight's IT provider right away. The provider isolated the device from the network via the office router within ten minutes of the call, confirmed no credentials had been entered and no file had been downloaded, and cleared the device after a remote scan found no signs of compromise. Total cost of the response: $185 CAD for the emergency remote assessment, with zero data loss and zero downtime beyond the one laptop being briefly unavailable. The agency's owner credited the fast, blame-free reporting — not any specific technical control — as the reason the incident cost hundreds of dollars instead of tens of thousands.
Case 2 — Harbourview Dental Clinic, Victoria, British Columbia (11 staff)
A front-desk employee received an email that appeared to be an urgent Microsoft 365 security alert and entered her email login credentials on a convincing fake Microsoft page before realizing something was wrong. She told the office manager immediately, who disconnected the workstation and called the clinic's IT provider within four minutes of the click. The provider reset the email password from a separate device, enabled multi-factor authentication on the account (which hadn't been active before), and reviewed the mailbox's sign-in logs, finding one unsuccessful login attempt from an unfamiliar location roughly six minutes after the credentials were entered — the password reset had beaten the attacker to the account by a narrow but decisive margin. Because the clinic handles patient health records, the incident was reviewed against PIPEDA and Law 25 obligations; since no evidence showed the account or any patient data was actually accessed, no formal breach notification was required, though the clinic documented the full timeline in case that changed. Total resolution time: under two hours from click to confirmed containment, at a cost of roughly $340 CAD for the emergency response and account hardening.
Case 3 — Acadia Precision Manufacturing, Moncton, New Brunswick (34 employees)
An employee in the shipping department opened an attachment from what looked like a logistics partner's shipment confirmation, and within roughly twenty minutes, files on a shared production-scheduling drive began showing renamed extensions and a ransom note appeared on a shared server. By the time IT was alerted and the affected systems were isolated, ransomware had encrypted a portion of the shared drive, though the isolation stopped it from reaching the company's separate, offline backup system. Acadia's leadership, on the advice of an incident response firm, chose not to pay the ransom and instead restored the affected systems from the offline backup, a process that took just under three days given the volume of production data involved. Total downtime cost, based on lost production time and rush shipping to catch up with delayed orders, came to approximately $58,000 CAD; the forensic investigation and recovery support cost an additional $14,500. Because the backup held, no ransom was paid and no permanent data loss occurred, but the company's leadership was candid afterward that the backup system's existence — tested only twice in the prior two years — was the single factor that determined whether this became a costly but recoverable week or a business-threatening event.
Budget and Pricing: Incident Response Costs in Canada
Understanding roughly what this costs, in real Canadian dollars, helps take some of the panic out of an already stressful moment and makes it easier to decide how quickly to escalate.
| Service | Typical cost range (CAD) | Notes |
|---|---|---|
| Emergency remote IT response, single device | $150 – $400 | Same-day or immediate response, assessment, and initial cleanup for one affected workstation |
| Emergency response with a support retainer | $0 – $150 | Often included or heavily discounted for businesses with an existing managed IT relationship |
| Digital forensic investigation | $3,000 – $25,000+ | Scope-dependent; determines what was actually accessed and whether notification obligations apply |
| Business-wide incident response (ransomware) | $10,000 – $75,000+ | Includes containment, recovery, forensics, and often legal/regulatory guidance for larger incidents |
| Managed IT / incident response retainer | $75 – $250 per employee, per month | Covers ongoing monitoring plus priority incident response, typically at little to no extra cost when an incident occurs |
The pattern across nearly every case we see is consistent: businesses with an existing managed IT or incident response retainer pay little to nothing extra when something like this happens, because the response is already part of what they're paying for monthly, and their provider already knows their network, their systems, and their normal baseline — which meaningfully speeds up the response itself. Businesses without that relationship pay emergency rates, often at a premium for same-day response, and lose time explaining their environment from scratch to a provider who's never seen it before. Neither approach prevents every incident, but the retainer model consistently produces faster containment and a lower total cost when something does happen, which is worth weighing against the monthly cost the next time it feels like an optional expense rather than a form of insurance in its own right.
Canadian Government and Business Resources
Several Canadian federal resources exist specifically to help businesses respond to and report incidents like this, independent of whatever IT support you already have in place.
- Canadian Centre for Cyber Security (cyber.gc.ca): The federal government's cybersecurity authority, offering incident reporting for Canadian organizations along with practical guidance and alerts on active threats. For significant incidents, reporting here can connect a business with additional guidance beyond what a private IT provider alone can offer.
- Canadian Anti-Fraud Centre (antifraudcentre-centreantifraude.ca): The national body for reporting fraud and cybercrime, including phishing and business email compromise; reporting here helps track patterns nationally even when a single report doesn't lead to a direct resolution for your specific case.
- Office of the Privacy Commissioner of Canada (priv.gc.ca): The authority PIPEDA breach notifications are reported to, with published guidance on when notification is legally required and how to do it properly — the primary reference for the breach-notification questions covered earlier in this guide.
- Business Development Bank of Canada (BDC) and Innovation, Science and Economic Development Canada (ISED): General business support resources that, among broader financing and advisory services, can include support for technology and security improvements following an incident, worth exploring if recovery costs create a genuine budget strain.
None of these resources replace having a direct relationship with an IT provider who can respond immediately when something happens, but they matter for the reporting and regulatory side of a serious incident, particularly one that turns out to involve ransomware or a confirmed breach of personal information. If you want help figuring out where your business currently stands on incident readiness before something like this happens, our cybersecurity services for Canadian businesses and remote virus removal service are built around exactly this kind of response, and SOS Emergency exists specifically for the moment when it already has.
Frequently Asked Questions
Dealing With This Right Now?
IT Cares handles emergency incident response for Canadian businesses — a certified technician can assess the device remotely and tell you plainly what happened and what to do next.
Comments (3)
The "don't shut it down" part is not something I would have known on my own. Genuinely thought powering off was the safe move — glad I read this before it happened, not during.
We went through something close to the Acadia case study last year, minus the offline backup unfortunately. Can't overstate how much that one detail changes the whole outcome.
Printed the 15-minute checklist and taped it near our front desk computer. Hoping we never need it but feels a lot better having it visible than buried in a folder somewhere.
Leave a Comment