The first 24 hours after discovering ransomware determine how much of the damage becomes permanent. Disconnect affected machines from the network immediately without powering them off, resist the urge to wipe and reimage before evidence is preserved, and call people in a specific order: your IT provider or managed service provider first, your cyber insurance carrier second (before any negotiation or payment decision), legal counsel third, then law enforcement and the Canadian Centre for Cyber Security. Businesses that follow this order consistently recover faster, keep more of their insurance coverage intact, and avoid the costliest mistake of all — destroying the evidence and backup integrity they need before they've even confirmed what happened.
This guide walks through that first day hour by hour, in the order decisions actually need to be made, not in the order a textbook might present them. It's written for the owner or manager of a Canadian small or mid-sized business who has just found a ransom note on a shared drive or a wave of files renamed with a strange extension, and who has maybe twenty minutes before the adrenaline wears off and the real decisions start. We've built this from patterns we see repeatedly working incident response for Canadian SMBs — the mistakes are remarkably consistent, and so are the moves that actually help.
One pattern worth naming up front: the businesses that come out of a ransomware incident in the best shape are almost never the ones with the biggest IT budget or the most sophisticated security stack going in. They're the ones who had even a rough plan for the first few hours, knew who to call and in what order, and — critically — had someone in the room willing to slow down rather than immediately "fix" the visible symptom. A modest business with a tested backup and a calm first hour routinely outperforms a much larger one that panics and starts making irreversible decisions before anyone outside the building has been consulted.
It's also worth being honest about what this article can and can't do. It cannot replace a real incident response retainer, a relationship with a cyber insurance broker who actually understands your business, or legal counsel who knows privacy law. What it can do is make sure that in the disorienting first hour, when adrenaline is high and the instinct to do something — anything — is strongest, you're reaching for the right first three or four moves instead of the ones that feel most urgent but do the most damage.
Who wrote this guide
This article was written and reviewed by IT Cares certified technicians who have supported Canadian small and mid-sized businesses through active ransomware incidents, from the first panicked phone call through containment, recovery, and post-incident hardening. We're not a law firm, an insurance brokerage, or a forensics lab — for an active, in-progress incident, please treat this as a structured starting point and involve those specialists directly and quickly, in the order laid out below.
What Ransomware Looks Like the Moment You Discover It
It rarely announces itself politely. Most businesses discover ransomware one of three ways: an employee reports that files won't open and have a strange new extension appended to the filename, a ransom note appears as a text file or desktop wallpaper change demanding payment in cryptocurrency, or an IT monitoring alert fires because of unusual file-encryption activity across a server or shared drive. Sometimes it's all three within the same ten minutes, spreading visibly across a network share while people are actively working in it.
The single most important instinct to resist in that moment is panic — specifically, panic in either of its two most common and most damaging forms. The first is the panic-shutdown: yanking power cords and turning off every machine in the building, which can trigger destructive behaviour in some ransomware variants and destroys memory-resident evidence a forensics team would otherwise use to identify the strain and the entry point. The second is the panic-pay: immediately trying to contact the attacker and pay whatever is demanded just to make the problem go away, before you've even confirmed whether clean backups exist, before your insurer has been notified, and before anyone has verified you're dealing with a decryption-capable ransom rather than a wiper disguised as one. Both instincts are understandable. Both make the situation measurably worse in the vast majority of cases we've seen.
What actually helps in that first moment is slower and less dramatic than either instinct suggests: isolate what's affected, get the right people on the phone in the right order, and make no irreversible decisions until you have more information than you do in minute one. The rest of this guide is that process, broken into the blocks of time where different decisions actually need to get made.
In the middle of an active incident?
Our certified technicians can help you triage and contain right now, and talk you through the next call to make.
The Hour-by-Hour Timeline
Ransomware response doesn't happen in one clean sweep — it happens in overlapping blocks of time where different priorities dominate. Here's how those 24 hours should generally break down for a small or mid-sized business without a dedicated in-house security operations team.
Minute 0-15: Isolate, don't shut down
Disconnect every affected device from the network immediately — pull the ethernet cable, disable Wi-Fi, or if it's a server, isolate its network segment or VLAN. If you have a managed switch, disabling the affected port is often faster than physically chasing cables. Do this for every device showing signs of encryption or displaying a ransom note, and for any device on the same network segment as a strong precaution, since ransomware frequently spreads laterally before its presence becomes visible on any single machine.
Resist powering machines off completely if you can avoid it. A live, isolated machine preserves RAM-resident data — active processes, network connections, sometimes even encryption keys momentarily in memory — that a forensics team can use to identify the ransomware family and how it got in. Isolation from the network achieves the containment goal without sacrificing that evidence.
If you use cloud-connected productivity tools like Microsoft 365 or Google Workspace, this is also the moment to consider whether sync clients on affected machines need to be paused, since some ransomware variants specifically target locally synced folders to propagate encrypted files up into cloud storage, potentially corrupting the cloud copy along with the local one. Pausing sync (not deleting the cloud copy) buys time to assess before that spread happens.
Hour 1: Assess scope and notify internally
Get a fast, rough picture of scope: which machines, which shared drives, which servers appear affected. You don't need precision yet — you need enough information to brief leadership and your IT contact intelligently. Notify company leadership immediately, even if the picture is incomplete; decisions in the next few hours (particularly around insurance and legal) need to be made with executive awareness, not discovered after the fact.
This is also the moment to start a simple incident log — a notepad or shared document noting what was discovered, when, by whom, and every action taken from this point forward with a timestamp. It feels unnecessary in the moment. It becomes extremely valuable during the insurance claims process and any forensic review, where a clear timeline materially speeds up both.
Keep the circle of people who know the details deliberately small during this hour — not out of secrecy for its own sake, but because unclear or half-informed information spreading through the team tends to generate panic, rumour, and sometimes well-meaning but damaging independent action (like the reimaging mistake covered further down). A short, calm message to staff along the lines of "we're dealing with a technical issue, please don't use your workstation until you hear otherwise, more information soon" buys the time needed to actually assess the situation properly.
Hours 2-4: Make the calls, in this order
This is the block of time where the order of phone calls matters more than almost anything else in the entire response. We cover the full reasoning in the dedicated section below, but the short version: internal IT or your MSP first to begin technical containment, your cyber insurance carrier second — before you engage any forensics firm, negotiator, or make any payment decision — legal counsel third, and law enforcement plus the Canadian Centre for Cyber Security fourth.
If your business doesn't have cyber insurance at all, this block looks slightly different: IT/MSP first, then legal counsel (who can often refer a forensics contact and advise on notification obligations even without an insurer coordinating the process), then law enforcement. This is also usually the point where the absence of a policy becomes acutely, expensively clear — worth revisiting once the immediate incident is resolved, covered further in the budget section below.
Hours 4-12: Contain, preserve, do not reimage yet
With the immediate fires contained and the right people looped in, this block is about deepening containment (segmenting the network further, disabling compromised accounts, rotating credentials for anything that may have been exposed) while explicitly preserving evidence rather than cleaning up. Save the ransom note exactly as it appears — screenshot it and copy the text file if possible. Preserve logs from firewalls, servers, and endpoint security tools rather than letting them roll over or get cleared. Resist the urge to reimage or wipe affected systems during this window, even though it's often technically the fastest way to "fix" a visibly broken machine — that decision should wait until your insurer or a forensics contact has weighed in, ideally within this same window.
This window is also when a realistic assessment of business impact starts to take shape — which processes are down, which can run manually or on paper in the interim (many retail and service businesses have a surprisingly workable manual fallback for a day or two), and which absolutely cannot function without the affected systems. Being honest about this now, rather than assuming everything will be back within hours, shapes better decisions about staffing, customer communication, and whether emergency alternative arrangements (a temporary point-of-sale workaround, a backup phone line) are worth setting up.
Hours 12-24: Assess backups, decide the recovery path, start the breach review
By this point you should have IT, insurance, and likely legal counsel involved, and containment should be holding. Now the focus shifts to recovery planning: test backup integrity on an isolated, disconnected system (never restore directly onto the still-compromised network), confirm how recent the last clean backup actually is, and start building a realistic recovery timeline based on what that backup actually covers. In parallel, begin a preliminary assessment of whether personal information about customers, employees, or clients may have been accessed or exfiltrated, since that determines your PIPEDA breach notification obligations, discussed further in the government resources section below.
By hour 24, most businesses have enough information to sketch a rough recovery timeline, even if it's still uncertain — "we expect email and file access back within 48 hours, point-of-sale within a week" is far more useful to staff, customers, and your own planning than either false reassurance or open-ended uncertainty. This is also a reasonable point to schedule a short internal check-in, ideally at the 24-hour mark itself, to formally hand off from "emergency response mode" into "structured recovery mode" for the days ahead.
The mistake we see most often in this window
Someone on the team, often with good intentions, starts reimaging machines to "get people working again" before backup integrity has been confirmed and before the insurer has signed off. This can void coverage outright under many policies, and worse, if the backup being restored from was itself silently compromised before the ransomware was noticed, it reintroduces the same vulnerability within days. Slow down here specifically — it's the single highest-leverage moment in the whole 24 hours.
What to Do vs. What NOT to Do in the First 24 Hours
| Situation | Do | Don't |
|---|---|---|
| Affected devices | Disconnect from network (cable/Wi-Fi/switch port) | Power off completely if avoidable — destroys forensic evidence |
| Ransom note | Screenshot and preserve exactly as found | Delete it or click any embedded link "just to see" |
| First phone call | Internal IT / MSP to begin containment | The attacker, before insurance and legal are looped in |
| Insurance | Call before hiring any forensics/negotiation vendor | Engage third-party vendors first and hope insurer reimburses later |
| Backups | Test integrity on an isolated, disconnected system | Restore directly onto the still-compromised network |
| Affected systems | Preserve as-is until insurer/forensics has weighed in | Wipe or reimage in the first few hours to "get back online" |
| Staff communication | Brief a small, trusted circle with clear instructions | Let rumours spread or have staff post about it on social media |
| Passwords/credentials | Rotate from a separate, clean device once scope is known | Reuse the same compromised network to change every password immediately |
Ransomware First 24 Hours Checklist
Printable First 24 Hours Checklist
- ☐ Disconnect all affected devices from the network (cable/Wi-Fi/switch port)
- ☐ Leave devices powered ON if possible — isolate, don't shut down
- ☐ Screenshot and preserve the ransom note exactly as found
- ☐ Start a written incident log with timestamps for every action taken
- ☐ Notify company leadership with a clear, honest scope summary
- ☐ Call internal IT / your MSP to begin technical containment
- ☐ Call your cyber insurance carrier before engaging any third-party vendor
- ☐ Call legal counsel to understand notification obligations
- ☐ Report to the Canadian Centre for Cyber Security and, if appropriate, police
- ☐ Preserve firewall, server, and endpoint security logs — do not let them roll over
- ☐ Segment the network further to contain any lateral spread
- ☐ Do NOT wipe or reimage any system yet
- ☐ Test backup integrity on an isolated, disconnected system only
- ☐ Begin assessing whether personal information was exposed (PIPEDA)
- ☐ Hold a same-day internal debrief to plan hours 24-72
Who to Call First and Why
The order of these calls isn't arbitrary — each one changes what the next conversation can accomplish, and getting the order wrong has real financial and legal consequences.
1. Internal IT or your managed service provider
They begin technical containment immediately: confirming isolation, checking for lateral spread, identifying which backups exist and where. This call needs to happen within the first hour, because every additional hour of active spread increases the eventual scope and cost of recovery.
2. Your cyber insurance carrier
This is the call most businesses get wrong by either skipping it or making it too late. Most cyber insurance policies require the insurer's approval before you hire a forensics firm, a ransomware negotiator, or make a payment — and if you engage vendors first and submit the bill afterward, many insurers will refuse to reimburse those costs, sometimes even denying the broader claim if policy conditions around insurer notification weren't met. Your insurer typically also has a panel of pre-approved forensics and legal vendors they work with regularly, which usually means faster, better-coordinated help than finding your own from scratch under pressure.
3. Legal counsel
Legal counsel — ideally one with breach/privacy experience, which your insurer may also help you access — advises on notification obligations, communication strategy, and whether attorney-client privilege should shape how the forensic investigation and its findings are documented. This matters more than it might seem: findings framed correctly from the start can affect legal exposure later.
4. Law enforcement and the Canadian Centre for Cyber Security
Report to your local police (or the RCMP for larger or cross-jurisdictional incidents) and to the Canadian Centre for Cyber Security. Neither will typically resolve your incident directly, but reporting contributes to national threat tracking, can occasionally provide useful intelligence about the specific ransomware strain or group involved, and demonstrates good-faith diligence that can matter for both insurance and regulatory purposes later.
Why the insurance call has to come before any payment decision
Beyond the reimbursement risk, insurers often have direct relationships with reputable ransomware negotiation firms and access to threat intelligence about whether a specific attacker group has a track record of actually providing working decryption keys after payment. Skipping this call and negotiating independently means going in blind on exactly the information that would most improve your odds of a good outcome, if payment even ends up being the right call at all.
Should You Pay the Ransom?
Canadian authorities, including the Canadian Centre for Cyber Security, generally discourage paying ransoms, and the reasoning holds up under scrutiny. Payment doesn't guarantee a working decryption key — some attacker groups simply don't deliver, or deliver a key that only partially works, and there's no meaningful recourse when that happens since you're transacting with a criminal enterprise with no accountability. Payment also directly funds further criminal activity, including the development of more capable ransomware and the targeting of the next victim. And data consistently shows that organizations known to have paid once are frequently targeted again, sometimes by the same group testing whether the door is still open, sometimes by others who've noted the business as a "payer" through shared criminal intelligence.
That said, this is ultimately framed as a business decision, not a purely moral one, and it's a decision made together with your insurer, legal counsel, and often a professional ransomware negotiation firm — not alone, and not in the first few panicked hours. The honest calculation weighs the realistic cost and time of alternative recovery (how good are your backups, really) against the cost, uncertainty, and risk of payment. For a business with solid, tested, offline backups, that calculation usually favours recovery without payment. For a business discovering in hour six that its backups are eight months stale or were encrypted along with everything else, the calculation gets much harder, and having insurance and a negotiator involved by that point genuinely matters.
Three Canadian SMB Ransomware Case Studies
Case Study 1: Manufacturing shop, Sudbury, Ontario
A 34-employee precision parts manufacturer discovered ransomware on a Tuesday morning when the shift lead couldn't open the production scheduling files. The team followed a version of the isolation steps above within 20 minutes, but had never involved their insurance broker in advance and spent nearly four hours trying to figure out if their general liability policy covered any of this (it didn't — cyber coverage is typically a separate policy or rider). By the time a standalone cyber policy question was resolved and a proper incident response process began, almost a full business day had passed. Total downtime reached 6 days, with an estimated $164,000 CAD in lost production and rush-order penalties, plus $38,000 in forensics and recovery costs. Backups existed but were 11 days stale, meaning nearly two weeks of order data had to be manually reconstructed from paper records and supplier confirmations. Lesson: confirming what your policy actually covers, before an incident, saves the most valuable resource you have in hour one — time.
Case Study 2: Law firm, Moncton, New Brunswick
A 12-lawyer firm found a ransom note on their document management server late on a Friday afternoon. The office manager, who had read a version of an incident checklist months earlier during a CPD session, isolated the server within 10 minutes and called their MSP immediately, followed by their cyber insurer within the hour. The insurer's panel forensics firm confirmed the backup (an immutable cloud copy taken six hours earlier) was clean and untouched by the attacker. The firm restored client files from that backup over the weekend and was fully operational by Monday morning, with total direct costs of approximately $19,500 CAD — almost entirely forensics and insurer deductible, no ransom paid, no meaningful data loss. The firm's managing partner has since said the insurance call within the first hour was "the best-executed panic" the firm ever had.
Case Study 3: Retailer, Kelowna, British Columbia
A regional home goods retailer with an e-commerce arm discovered encrypted point-of-sale and inventory files across three store locations simultaneously, indicating the attacker had been inside the network for some time before triggering encryption. In the panic, an assistant manager powered off two affected registers completely before IT could isolate them, and a well-meaning staff member began reimaging one affected laptop before the MSP arrived on scene, destroying evidence on both machines. The remaining investigation took longer and cost more as a result — roughly $61,000 CAD in total forensics, recovery, and PIPEDA-related legal review, against an estimated $22,000-$30,000 had those two devices been left intact. E-commerce operations were down for 9 days during the peak back-to-school shopping period, with an estimated $210,000 CAD in lost online revenue. The retailer has since built and laminated a one-page "do not touch" first-response card, now posted at every register and back-office workstation.
Budget & Pricing: What Ransomware Response Actually Costs
Concrete numbers help ground planning before an incident happens, when decisions can be made calmly rather than under pressure.
- Incident response / digital forensics consultants: typically $150-$350 CAD per hour, or $5,000-$25,000 CAD as a flat engagement for a small business incident of moderate complexity; larger or multi-site incidents can run well beyond that
- Ransomware negotiation firms: often billed as a percentage of any negotiated reduction or a flat fee in the $5,000-$15,000 CAD range, usually engaged through or alongside your insurer
- Data recovery / system restoration labour: highly variable, but budget $2,000-$15,000 CAD for a small business restoring from backup across multiple servers and workstations, more if backups are partial or stale
- Cyber insurance deductibles: commonly $2,500-$25,000 CAD depending on policy size and business revenue, due before coverage kicks in
- Legal counsel (breach/privacy specialist): $250-$500 CAD per hour typically, often partially covered under a cyber policy's legal expense provision
- IT Cares initial remote emergency assessment: a general starting range for an initial remote triage and assessment call typically falls in the $99-$199 CAD range for a small business — the exact scope depends on the incident, and larger engagements are quoted separately after the initial assessment
These numbers make the case for prevention fairly bluntly: a properly configured MFA rollout, tested immutable backups, and basic endpoint detection typically cost a fraction of even the low end of a single incident response engagement, spread across an entire year rather than absorbed in one emergency week.
Canadian Government Resources
Several federal resources exist specifically for this situation, and knowing them before an incident saves valuable time during one.
- Canadian Centre for Cyber Security (cyber.gc.ca): Canada's national authority for cyber security guidance and incident reporting. They accept ransomware incident reports from organizations of any size and publish practical, regularly updated guidance on ransomware prevention and response specifically written for a non-technical audience.
- Office of the Privacy Commissioner of Canada (priv.gc.ca): administers PIPEDA's mandatory breach notification requirements. If personal information was or may have been accessed and the breach creates a real risk of significant harm, you're legally required to notify both the OPC and affected individuals, and to keep records of every breach regardless of size or notification threshold.
- Innovation, Science and Economic Development Canada (ISED, ised-isde.canada.ca): publishes broader digital security and business resilience guidance for Canadian SMBs, including resources on evaluating IT vendors and understanding baseline security expectations.
- BDC — Business Development Bank of Canada (bdc.ca): offers cybersecurity guidance and, in some cases, financing specifically aimed at helping Canadian SMBs invest in security upgrades like backups, MFA, and endpoint protection before an incident occurs, rather than only reacting after one.
Frequently Asked Questions
If you're building your defenses before an incident rather than responding to one already underway, our ransomware removal service guide and security audit checklist are good next reads, and our cybersecurity services team can help assess where your current setup has gaps before they turn into a 2 a.m. phone call.
Want a Second Set of Eyes Before — or During — an Incident?
Whether you're actively dealing with ransomware right now or want to shore up defenses before it happens, IT Cares can help assess your setup and talk through next steps.
Comments (3)
Wish we'd read this before our incident last year. We wasted hours figuring out our policy didn't cover it before someone thought to just call the broker directly. Confirm your coverage BEFORE anything happens.
The part about not reimaging immediately hit home. We had a staff member do exactly that out of panic and it made the whole investigation slower. Printing the checklist for our break room.
Calling insurance before anyone else got involved is genuinely the best advice in here. Our claim went smoothly specifically because we didn't hire anyone before they signed off.
Leave a Comment