This is a first-hour checklist, not a recovery plan.
If you see a ransom note, locked files, a bank alert, or a mailbox you can't open, slow down, write down what you see, and call for help.
It's for businesses of about 5–50 people. CISA (the Cybersecurity and Infrastructure Security Agency) publishes the #StopRansomware Guide with a response checklist. NIST (the National Institute of Standards and Technology) SP 800-61 Rev. 3, Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile (April 2025) supersedes Rev. 2 (August 2012) under a new title. This page covers the first hour only. It is not legal advice, insurance advice, or a promise that files or money come back.
What should a small business do in the first 60 minutes after a suspected cyber incident? Write it down, isolate without wiping, call by phone, keep the logs, lock admin and bank accounts from a clean device, and report.
Minute 0–5: Write down what you see
What do I write down first? The time, the device, and the words on the screen.
Stop clicking. Don't open more files, and don't run a cleanup tool you found in a search.
Capture the facts
On paper, write the time, the computer or phone, who was signed in, and the screen text, including any ransom note or new payee at the bank. Note if others see the same thing. The CISA guide starts by naming which systems were impacted. Leave blanks as unknown.
Photograph the screen
Use a personal phone, and catch the on-screen clock if it shows. Don't send the photo over company email or chat.
- Time, device, and screen text written down
- Screen photographed on a personal phone
- Photo kept off company email and chat
- No extra clicks on the affected machine
Minute 5–15: Isolate the device and keep the evidence
How do I limit spread without destroying evidence? Unplug the network cable or turn off Wi-Fi, leave the machine on, and don't wipe or reimage it.
Disconnect from the network
Unplug ethernet or turn off Wi-Fi on every machine showing the same note. If several systems look affected, the #StopRansomware Guide says to take the network offline at the switch. Do that only if you know which cable to pull. Otherwise, call your IT provider. Unplugging one PC does nothing about a cloud admin account.
Leave the power on
By default, don't wipe, reimage, or power off. CISA says to shut a device down only if you can't disconnect it, because shutting down loses evidence in memory. Also shut down if your IT provider or responder tells you to, and write down why. Don't delete the note, emails, or files.
- Ethernet unplugged or Wi-Fi off
- Devices left powered on
- No wipe, reimage, or factory reset
- Notes, emails, and files still there
- Any shutdown written down, with the reason
Minute 15–30: Call on a phone, not on company email
Who do I call, and from where? From your phone, or from a computer that wasn't on the affected network. Skip company email and chat.
The guide says to use out-of-band methods such as phone calls. Read them your notes, and if their instructions differ from this page, follow theirs.
Who to call
- Your IT provider. Tell them what you unplugged or powered off, and ask them to take over. Question 7 on the IT-host renewal card covers this call on a calm day.
- Your cyber insurer, if you have a policy. Use the hotline and follow any steps the policy lists. This page doesn't describe coverage and doesn't tell you to file a claim.
- Your bank, if money moved or a payment changed. Don't wait on the affected mailbox.
- Your counsel, if you have one. Follow counsel, the insurer, or law enforcement where they instruct you. This is not legal advice.
Do not answer the attacker
Don't pay, reply, or negotiate. A reply tells them a person is there. Keep the note. If it says a copy of your data was taken, deleting local files won't undo that.
The Internet Crime Complaint Center (IC3) says it doesn't work with outside firms to recover money and won't contact you to demand payment. If a stranger asks for a fee, stop.
- Calls by phone, not company email or chat
- IT provider called, or an after-hours message left
- Insurer hotline used if a policy exists
- Bank called if money or payees changed
- No payment, reply, or negotiation
Minute 30–60: Lock critical accounts and report
What do I change, and what do I leave alone? From a clean device, change email-admin and banking passwords, confirm multi-factor methods weren't swapped, sign out other sessions, and leave logs in place.
MFA (multi-factor authentication) means a password plus a second step, such as an authenticator app or a security key.
Use a clean device
Use a phone browser or a computer that wasn't on the office network. Change the email admin (Microsoft 365 or Google Workspace), bank, payroll, and password-manager admin passwords there, not on the machine with the note.
Look for a new MFA method, phone number, recovery email, forwarding rule, or unknown session. Sign other sessions out. Don't turn MFA off. If you're locked out, call your IT provider and stop there.
The guide saves the full password reset for after cleanup and rebuild. This hour is about admin and money, and if your IT provider says to wait, wait.
Keep the record
Don't clear logs, mail, or backups, and don't restore onto the office network this hour. The 15-minute backup test is for a calm day.
File the report
Report to CISA, your local FBI field office, or the FBI's IC3. The guide also lists U.S. Secret Service field offices. CISA's Report Ransomware page says one report notifies the other agencies. Use the live forms, since this page isn't a filing instruction. IC3 says to call 911 if a person is in immediate danger, and to file when you're unsure. Write the confirmation number below.
- Admin and bank passwords changed on a clean device
- MFA methods and recovery info checked
- Other sessions signed out
- Logs, mail, and the note kept
- No restore onto the affected network
- CISA or IC3 started; FBI field office noted
One-page printable first hour
Copy or print this table. Leave blanks as unknown. Don't guess.
| # | Minute | Action | Done? | Who |
|---|---|---|---|---|
| 1 | 0–5 | Time, device, and screen text written down | Y / N | |
| 2 | 0–5 | Screen photo on a phone, not company email | Y / N | |
| 3 | 5–15 | Ethernet unplugged or Wi-Fi off | Y / N | |
| 4 | 5–15 | Left on; no wipe, reimage, or default shutdown | Y / N | |
| 5 | 5–15 | Notes, emails, and files not deleted | Y / N | |
| 6 | 15–30 | IT provider called by phone | Y / N | |
| 7 | 15–30 | Insurer hotline called, if a policy exists | Y / N | |
| 8 | 15–30 | Bank called if money or payees changed | Y / N | |
| 9 | 15–30 | No pay, no reply, no negotiation | Y / N | |
| 10 | 30–60 | Admin and bank passwords changed on a clean device | Y / N | |
| 11 | 30–60 | MFA and recovery checked; other sessions signed out | Y / N | |
| 12 | 30–60 | CISA or IC3 started; FBI field office noted | Y / N |
Date: YYYY-MM-DD · Filled by: · Suspected or confirmed:
Save it as first-hour-YYYY-MM-DD alongside your ransomware prep checklist.
Incident notes log
Use one row per thing you saw or call you made. On a calm day, write after-hours numbers for your IT provider, insurer, bank, and counsel beside this log.
| Time | What you saw | Who you called | What they told you |
|---|---|---|---|
Confirmation number: · Devices left on: · Powered off, and why:
What if the calls disagree? Follow counsel, the insurer, or law enforcement when they give instructions. Until then, follow your IT provider. This page does not decide coverage.
After the hour
Rebuilding, restoring, and the wider password reset wait until your IT provider says the affected systems are contained. Use the guides below on a calm day.
Related guides
- Ransomware protect checklist — prep before this hour
- Test your backup in 15 minutes — a restore on a calm day
- Run a 20-minute MFA coverage drill — confirm the second step
- Ask your IT host these 8 questions — who answers after hours
- Resources — CISA and NIST references
Educational content only — not legal, insurance, or compliance advice.