📋 Ransomware Response Guide  ·  Step 5 of 7

Who to call, in what order, on what channels

Notification during a ransomware incident is not just etiquette — it's a series of decisions with legal, financial, and regulatory consequences. Getting the order wrong, using the wrong channel, or notifying the wrong party first can cost you insurance coverage, expose you to liability, and tip off attackers who may still be monitoring your communications.

Get the Full PDF Guide Our Cybersecurity Services

Use out-of-band communication only

Before any notification: assume your email, Slack, Teams, and corporate phone systems are compromised. Attackers frequently maintain access during the response phase specifically to monitor your communications, anticipate your moves, and identify additional targets within your organization.

Switch to communication channels the attacker cannot see:

  • Personal phones and personal email for incident coordination — not corporate
  • Signal or another end-to-end encrypted messaging app for sensitive discussions
  • In-person meetings where possible
  • A new, separate communication channel set up specifically for the incident response team

Treat all corporate channels as monitored until forensics has confirmed they're clean. Yes, this is operationally painful. It's also the difference between a contained incident and a much worse one.

Notification order — who and when

1. Your cyber insurance carrier — first call

Almost every cyber insurance policy contains a prompt notification requirement, usually 24 to 72 hours. Miss that window and you can lose coverage entirely. Call your broker or carrier directly from a personal phone, identify the incident, and follow their instructions exactly.

Most policies will activate a pre-approved panel of:

  • Breach counsel — outside legal counsel specialized in cyber incidents
  • Incident response and digital forensics firm
  • Ransom negotiator if needed
  • Crisis communications/PR firm

Use the panel. Insurance carriers have negotiated rates with these firms, and their work product is what your claim will be built on. Engaging your own outside firms before involving the carrier can result in expenses not being covered.

2. Outside legal counsel — established under privilege

If your insurance carrier hasn't assigned breach counsel yet, engage your own outside cybersecurity attorney immediately. All subsequent forensic work should be performed under attorney-client privilege — this protects the work product from discovery in any later litigation.

Your in-house counsel or general business attorney is not a substitute. Cyber breach response is a specialized legal practice with specific case law around privilege, notification obligations, and regulatory exposure.

3. Internal incident response team and executive leadership

Convene the formal incident response team — IT, security, legal, communications, and an executive sponsor. Decisions about ransom payment, public communications, and notification scope are executive decisions, not IT decisions. Get leadership in the loop on day one.

Limit the circle. The fewer people who know the details, the lower the risk of leaks, panic, or attackers learning your response strategy.

4. Law enforcement

Report the incident to the FBI through the Internet Crime Complaint Center (IC3.gov) and to your local FBI field office. For NYC, that's the New York Field Office; for Connecticut, the New Haven Resident Agency. CISA also accepts reports and can provide technical assistance.

Concerns about reporting are common but largely misplaced:

  • The FBI does not publicly disclose victims and does not require you to make any public statement
  • Reporting may be required by your cyber insurance policy or by regulations like NYDFS Part 500
  • The FBI sometimes has decryption keys for known ransomware variants that they can provide to victims
  • Reporting contributes to investigations that disrupt the threat groups attacking other businesses

5. Employees — once you have a coordinated message

Employees will know something is wrong long before you formally tell them. Get ahead of the rumor mill with a brief, accurate, controlled message. Do not over-explain or speculate about scope while the investigation is ongoing.

What to communicate:

  • That a cybersecurity incident is being managed
  • What specific systems are unavailable and what they should do as a workaround
  • Not to discuss the incident outside the company
  • To direct any external inquiries (media, vendors, clients) to a designated spokesperson

6. Customers, partners, and the public — last, and only with counsel review

External notification is the most consequential step in this sequence. Premature notification creates legal liability if your facts change later. Late notification can violate regulatory requirements and damage trust permanently.

External communication should:

  • Be drafted by breach counsel
  • Be reviewed by your insurance carrier and crisis communications firm
  • Reflect what you actually know — not what you suspect
  • Include only the information legally required and operationally necessary
  • Provide a clear point of contact for follow-up questions

The ransom decision is not made at this stage

If the attackers have left a ransom demand, do not respond, do not pay, and do not engage. The decision to pay or not pay involves your insurance carrier, breach counsel, OFAC sanctions analysis, ransom negotiators, and executive leadership. It's a structured decision made under privilege, not a frantic individual choice in the first hours.

Paying ransom can violate OFAC sanctions if the attackers are on the sanctions list. Many recent ransomware groups are. Penalties for sanctions violations apply regardless of intent. This is why ransom decisions go through specialized negotiators who handle OFAC compliance.

Step 5 Action Checklist
  • Switch to out-of-band communication — personal phones, Signal, in-person meetings
  • Notify cyber insurance carrier within the policy notification window (usually 24-72 hours)
  • Engage breach counsel to establish attorney-client privilege over forensic work
  • Convene formal incident response team with executive sponsor
  • Report to FBI via IC3.gov and local FBI field office
  • Communicate a controlled message to employees with workaround instructions
  • Hold external notifications until breach counsel has approved messaging
  • Do not respond to attacker communications or engage with ransom demands directly

What's next: Step 6: Legal & Compliance

Once you've completed this step, the next priority is assessing the legal and compliance impact of the breach. That's covered in Step 6 of this guide.

← Step 4: Attack Vector ↑ Back to guide overview Step 6: Legal & Compliance →
Ransomware Response · Step-by-Step Guide

The complete 7-step ransomware response cluster

Each step builds on the previous one. Skip a step at your own risk.

  • 1 First 60 seconds Isolate infected systems →
  • 2 First 30 minutes Assess the scope of the attack →
  • 3 First 60 minutes Preserve forensic evidence →
  • 4 First 2 hours Identify the attack vector →
  • 5 First 4 hours Notify stakeholders →
  • 6 First 24–72 hours Assess legal & compliance impact →
  • 7 First 30 days post-recovery Harden the environment →
← Back to main Ransomware Response Guide Download PDF
Need Help Right Now?

We've helped businesses recover from ransomware before

If you're dealing with an active incident or want to make sure you're protected before it happens, call us directly. We pick up.

Schedule a Free Consultation (646) 791-2137
0
Skip to Content
Moore Technology Consulting
Home
About
Services
Pricing
Client Stories
Free Consultation
Moore Technology Consulting
Home
About
Services
Pricing
Client Stories
Free Consultation
Home
About
Services
Pricing
Client Stories
Free Consultation

Contact Us

646-791-2137info@mooretechnologyconsulting.com

MTC_logo_R2-01.png

New York Locations
New York City, NY Manhattan | Brooklyn | Queens | Bronx | Staten Island

White Plains, NY 44 S Broadway, White Plains, NY 10601

Connecticut Locations
Stamford, CT 700 Canal Street, Stamford, CT 06902



Westport, CT 55 Post Rd W, Westport, CT 06880

©2026 Moore Technology Consulting.

All Rights Reserved.

Privacy Policy | FAQ

Moore Technology Consulting

Cybersecurity-first managed IT for SMBs across CT, NY & NYC.

(646) 791-2137 ✉ info@mooretechnologyconsulting.com 📍 Stamford, CT · White Plains, NY · Westport, CT
Services
  • Managed IT Services
  • Cybersecurity
  • Microsoft 365
  • Cloud Services
  • Backup & DR
  • Compliance & vCIO
Resources
  • Free Consultation
  • Ransomware Guide
  • About MTC
  • Client Stories
  • Blog
  • Contact Us
Stay Informed

Practical IT & cybersecurity insights for business owners. No spam, no fluff — just useful intel.

We respect your inbox. Unsubscribe anytime.

Powered by an Enterprise-Grade Stack

Microsoft Partner · Datto Partner · Huntress Partner · ThreatLocker Partner
Cisco Meraki · Fortinet · Cloudflare · Pax8

Service Areas

Stamford, CT Greenwich, CT Westport, CT White Plains, NY New York City

Moore Technology Consulting is headquartered in White Plains, NY and certified as a Minority Business Enterprise (MBE) by the New York City Department of Small Business Services (SBS) and New York State Empire State Development (ESD). We deliver managed IT and cybersecurity services to small and mid-sized businesses across Fairfield County, Westchester, and the greater New York metro area.

© 2026 Moore Technology Consulting. All rights reserved.
Privacy Policy Terms of Service Accessibility