🛡️ Free Resource — Instant Download

What to do when your business gets hit with ransomware

A step-by-step response guide for small and midsize businesses. Know exactly what to do in the first 60 minutes — before you make a mistake that costs you everything.

  • 6-step response framework used by incident responders
  • Ransomware prevention checklist for your IT team
  • Who to call, what to document, and what NOT to do
  • Written for business owners — not IT professionals
No spam. Ever.
Instant delivery
Free — no catch
🛡️
Ransomware Response Guide
Moore Technology Consulting · 2 pages · Free PDF
01
Isolate ImmediatelyDisconnect, don't shut down
02
Assess the ScopeWhat's encrypted, what's not
03
Preserve EvidenceWhat investigators will need
04
Identify the Attack VectorHow they got in
05
Notify the Right PeopleLegal, insurance, FBI
06
Begin RecoveryThe right order matters
+ Prevention checklist & hardening steps included
Why This Matters

Most businesses don't know what to do — and that's exactly what attackers count on

Ransomware moves fast. In the first 60 minutes after an attack is discovered, most business owners make at least one critical mistake — shutting down infected machines, paying without exploring options, or restoring from a backup that was also compromised.

This guide gives you the exact sequence of steps that incident responders follow. It won't replace an IT team, but it will keep you from making things worse while you get help.

  • Written from real ransomware recovery experience — not theory
  • Covers both the technical and legal/insurance notification requirements
  • Includes a prevention checklist to assess your current exposure
  • Two pages. Printable. Keep it somewhere accessible.

⚠️ Don't wait until it happens

The businesses that recover fastest are the ones who had a plan before the attack. Print this guide and put it somewhere your team can find it — even if your systems are down.

Free Download

Get the Ransomware Response Guide

Enter your details below — we'll send the PDF directly to your inbox. No spam, no sales sequence. Just the guide.

✅

You're all set!

Check your inbox — the guide is on its way. You can also download it directly now.

📄 Download PDF Now

Your information is never sold or shared. Unsubscribe anytime.

What's Inside

The complete response framework — plus a prevention checklist

The guide covers both sides: what to do after an attack hits, and what to put in place before one happens. Most businesses find the prevention checklist is where they identify their biggest gaps.

It's two pages. Designed to be printed and stored somewhere accessible — including somewhere physical, since your systems may not be available when you need it.

Download the Free Guide
01

Isolate Immediately

Disconnect affected machines without shutting them down — memory may contain forensic evidence attackers don't want you to have.

02

Assess the Scope

Identify what's encrypted, whether the attack is still active, and whether data was exfiltrated before encryption began.

03

Preserve Evidence

Document everything — ransom notes, error messages, timestamps. This is required for insurance claims and FBI reporting.

04

Identify the Attack Vector

You cannot safely restore until you know how the attacker got in. Skipping this step leads to reinfection.

05

Notify the Right People

Legal counsel, cyber insurance (prompt notification required), and FBI IC3. If client data was exposed, additional obligations apply.

06

Begin Recovery — In the Right Order

Assess backup integrity before restoring anything. Rebuild from clean images. Restore from the most recent verified clean backup.

“
We got hit with ransomware on a Friday. By the following week, Moore Technology had restored our data, rebuilt our entire Active Directory, and had every machine back online. They figured out how the attackers got in, cleaned everything up, and put real protections in place we never had before.

Managing Partner — Weintraub, Traub, Tracy & Virk, CPA's | Long Island, NY

Read the Full Guide Online

The 7-step ransomware response framework

Each step is a standalone article you can read now or come back to. Together, they cover what to do in the first hour, the first day, and the first week after a ransomware attack.

1
First 60 seconds

Isolate infected systems

Stop lateral spread before you do anything else. Network disconnect — not power off.

Read Step 1 →
2
First 30 minutes

Assess the scope of the attack

Which systems, which data, which users. Map the impact before reacting further.

Read Step 2 →
3
First 60 minutes

Preserve forensic evidence

Stop accidentally destroying what your cyber insurer and law enforcement need.

Read Step 3 →
4
First 2 hours

Identify the attack vector

How they got in. Phishing, RDP, VPN, or vendor. Close the door before re-opening.

Read Step 4 →
5
First 4 hours

Notify stakeholders

Who to call, in what order, on what channels. Out-of-band communication only.

Read Step 5 →
6
First 24–72 hours

Assess legal & compliance impact

NYDFS, HIPAA, SEC notification deadlines. What you must report, when, to whom.

Read Step 6 →
7
First 30 days post-recovery

Harden the environment

The next attack is already being planned. Identity, endpoints, backups, access — closing every gap that made the first attack possible.

Read Step 7 →

Prefer the printable version?

Download the full PDF guide — 7 steps, single document, designed to live next to your incident response plan.

Download the Full PDF Guide Talk to MTC About Your Risk
Already Been Hit?

We've helped businesses recover from ransomware before

If you're dealing with an active incident or want to make sure you're protected before it happens, call us directly. We pick up.

Schedule a Free Consultation (646) 791-2137

Stamford, CT  ·  White Plains, NY  ·  Westport, CT

0
Skip to Content
Moore Technology Consulting
Home
About
Services
Pricing
Client Stories
Free Consultation
Moore Technology Consulting
Home
About
Services
Pricing
Client Stories
Free Consultation
Home
About
Services
Pricing
Client Stories
Free Consultation

Contact Us

646-791-2137info@mooretechnologyconsulting.com

MTC_logo_R2-01.png

New York Locations
New York City, NY Manhattan | Brooklyn | Queens | Bronx | Staten Island

White Plains, NY 44 S Broadway, White Plains, NY 10601

Connecticut Locations
Stamford, CT 700 Canal Street, Stamford, CT 06902



Westport, CT 55 Post Rd W, Westport, CT 06880

©2026 Moore Technology Consulting.

All Rights Reserved.

Privacy Policy | FAQ

Moore Technology Consulting

Cybersecurity-first managed IT for SMBs across CT, NY & NYC.

(646) 791-2137 ✉ info@mooretechnologyconsulting.com 📍 Stamford, CT · White Plains, NY · Westport, CT
Services
  • Managed IT Services
  • Cybersecurity
  • Microsoft 365
  • Cloud Services
  • Backup & DR
  • Compliance & vCIO
Resources
  • Free Consultation
  • Ransomware Guide
  • About MTC
  • Client Stories
  • Blog
  • Contact Us
Stay Informed

Practical IT & cybersecurity insights for business owners. No spam, no fluff — just useful intel.

We respect your inbox. Unsubscribe anytime.

Powered by an Enterprise-Grade Stack

Microsoft Partner · Datto Partner · Huntress Partner · ThreatLocker Partner
Cisco Meraki · Fortinet · Cloudflare · Pax8

Moore Technology Consulting is headquartered in White Plains, NY and certified as a Minority Business Enterprise (MBE) by the New York City Department of Small Business Services (SBS) and New York State Empire State Development (ESD). We deliver managed IT and cybersecurity services to small and mid-sized businesses across Fairfield County, Westchester, and the greater New York metro area.

© 2026 Moore Technology Consulting. All rights reserved.
Privacy Policy Terms of Service Accessibility