SOS File All articles
Data Recovery

Locked Out and Under Fire: A Business Owner's Tactical Guide to Surviving a Ransomware Attack

SOS File
Locked Out and Under Fire: A Business Owner's Tactical Guide to Surviving a Ransomware Attack

Photo: business owner stressed looking at locked computer screen ransomware warning, via www.apple.com

The message appears without warning. Your files are encrypted. A countdown timer is running. Someone you have never met is demanding payment in cryptocurrency before a deadline you did not agree to. For thousands of small and medium-sized businesses across the United States each year, this scenario is not hypothetical — it is Tuesday morning.

Ransomware attacks have evolved from nuisance-level intrusions into sophisticated, targeted campaigns. Criminal organizations now research their victims in advance, calibrate ransom demands to match business revenue, and operate customer service portals to guide payment. The professionalism of the attack, however, does not obligate you to treat it as a legitimate transaction. What it does demand is a clear-headed, structured response.

The First Thirty Minutes: Containment Before Everything Else

The single most consequential action you can take immediately after discovering a ransomware infection is network isolation. Disconnect affected machines from your local network and from the internet. If you cannot identify which systems are compromised, disconnect everything. This is not an overreaction — ransomware strains frequently spread laterally across connected devices before triggering their encryption payload.

Do not shut down infected machines unless instructed by a qualified incident responder. Some ransomware variants store decryption keys temporarily in system memory, and a forced shutdown can destroy that data permanently. Preserve the state of the system as it is.

Assign one person to document everything: timestamps, ransom notes, error messages, and every action taken. This record will matter later — for law enforcement, for your insurance carrier, and potentially for your legal team.

The Pay-or-Don't Question: A Honest Assessment

No guidance on ransomware would be complete without addressing the payment question directly, and the honest answer is that there is no universal right answer. What there is, however, is a framework for making the decision responsibly.

Arguments against paying: The FBI and CISA both advise against ransom payments, and for good reason. Payment funds future attacks, provides no guarantee of decryption, and may expose your business to legal liability if the attacker group is on a sanctions list maintained by the U.S. Treasury's Office of Foreign Assets Control (OFAC). In some cases, businesses have paid, received a decryption tool, and found that the tool worked only partially — or not at all.

Arguments that complicate the picture: For businesses without viable backups, a 48-hour recovery window versus a 3-week rebuild from scratch is not an abstract calculation. It has real consequences for employees, customers, and survival. Some organizations have paid, received working decryption keys, and resumed operations — though they typically do not publicize this outcome.

Before making any payment decision, consult with a cybersecurity attorney. Verify whether the attacker group appears on OFAC's Specially Designated Nationals list. Explore whether a decryptor for the specific ransomware strain already exists — resources like No More Ransom (nomoreransom.org), a project supported by Europol and multiple cybersecurity firms, maintain a free library of decryption tools for known variants.

Involving Law Enforcement: Why It Helps More Than It Hurts

Many business owners hesitate to contact law enforcement out of fear that it will slow their response or expose them to scrutiny. In practice, the opposite is more often true.

The FBI's Internet Crime Complaint Center (IC3) and local FBI field offices actively investigate ransomware cases. Reporting your incident does not obligate you to pause recovery operations. What it does do is contribute to a national intelligence picture that has, in documented cases, led to decryption keys being obtained and provided to victims — sometimes at no cost — following law enforcement action against attacker infrastructure.

Your cyber insurance carrier may also require prompt law enforcement notification as a condition of coverage. Review your policy before assuming otherwise.

Navigating the Insurance Claim

Cyber insurance policies vary considerably in what they cover and what they exclude. Common coverage elements include ransom payment reimbursement, business interruption losses, forensic investigation costs, and notification expenses if customer data was involved. Common exclusions include attacks attributed to nation-state actors, incidents involving unpatched known vulnerabilities, and claims filed outside narrow reporting windows.

Notify your insurer as soon as containment is underway. Most policies require notification within 24 to 72 hours of discovery. Failure to meet this window is one of the most common reasons legitimate claims are denied.

Your insurer will likely deploy their own incident response team. Cooperate with them, but understand that their primary interest is limiting the insurer's exposure — not necessarily optimizing your recovery. Having your own technical counsel is a reasonable precaution.

What Recovery Without Capitulation Actually Looks Like

In 2021, a regional logistics company in the Midwest was hit with a LockBit ransomware variant that encrypted approximately 80 percent of their operational data. They declined to pay. Their IT team, working with an external incident response firm, identified that the attackers had exploited a VPN vulnerability patched two months earlier — a patch the company had not yet deployed.

Recovery took eleven days. It relied on a combination of offline backups (some of which were partially corrupted and required reconstruction), shadow copy remnants on several machines, and manual data re-entry for the gap period. The total cost exceeded the ransom demand. But the company retained full control of its systems, avoided potential OFAC exposure, and — critically — never handed a criminal organization proof that their business model works.

That outcome is not always available. But it is available far more often than attackers want their victims to believe.

Building Resilience After the Incident

Once operations are restored, the work of hardening your environment begins. Prioritize the implementation of the 3-2-1 backup rule: three copies of data, on two different media types, with one stored offline or offsite. Conduct a tabletop exercise with your leadership team to rehearse your incident response plan before the next event — not during it.

Ransomware is a business problem as much as a technical one. The organizations that recover fastest are not necessarily those with the most sophisticated infrastructure. They are the ones that treated the possibility seriously before it became a reality.

All Articles

Related Articles

Stop Digging: How Well-Intentioned Recovery Attempts Can Permanently Destroy Your Data

Stop Digging: How Well-Intentioned Recovery Attempts Can Permanently Destroy Your Data

The Backup Illusion: Why Most Recovery Plans Collapse Under Real Pressure

The Backup Illusion: Why Most Recovery Plans Collapse Under Real Pressure

The Clock Is Already Running: What Every Minute of Delay Costs You After Data Loss

The Clock Is Already Running: What Every Minute of Delay Costs You After Data Loss