602-725-2818Licensed, insured & bondedSchedule a Consultation
Call 602-725-2818Consultation

Ransomware Hit Your Business? The First 24 Hours (Arizona Guide)

The first hour after you discover ransomware is the hour that decides how bad this gets. Files are encrypted, a ransom note is on the screen, and every instinct is telling you to do something — reboot the machine, wipe it, pay, or start pulling systems apart. Most of those instincts, acted on in a panic, make the situation worse. They destroy the evidence you need and can eliminate recovery options you did not know you still had.

This guide walks you through the first 24 hours calmly and in order: what to do, what to avoid, and when to bring in a forensics and incident response team. It is written for Arizona business owners and IT leaders, but the technical principles apply anywhere — and Honeybadger’s digital forensics and cybersecurity work is available nationwide. If you are in the middle of an active incident right now, call (602) 725-2818 and preserve the environment while help is on the way.

The First Hour — Contain Without Destroying

Your goal in the first hour is containment, not cleanup. Secure the scene, do not scrub it.

  1. Isolate affected systems from the network. Unplug the network cable or disable Wi-Fi on infected machines and disconnect from shared drives. This slows or stops lateral movement.
  2. Leave infected machines powered on. Do not shut them down or reboot them. Isolation stops the spread; you do not need to power off to contain.
  3. Disconnect backups if they are still clean. Get them off the network immediately so the ransomware cannot reach them.
  4. Alert your internal response people — IT, security, and leadership — now, not after you have tried to fix it yourself.
  5. Start a simple written timeline. Note when you discovered it, what you saw, and every action you take.

What NOT to Do (These Mistakes Cost the Most)

  • Do not wipe or reformat the machine. Wiping destroys forensic evidence about how the attackers got in and can erase the only path to recovery.
  • Do not reboot or power-cycle infected systems. Rebooting can trigger further encryption and destroy volatile evidence in memory — RAM can hold encryption keys and network artifacts that vanish on shutdown.
  • Do not delete the ransom note or the encrypted files. They help responders identify the strain and assess options.
  • Do not pay the ransom before getting expert advice. Payment carries no guarantee of recovery and can raise legal and regulatory questions.
  • Do not communicate with the attackers on your own. Negotiation is a specialized task with real consequences.
  • Do not use the compromised email or systems to coordinate your response. Assume the attackers may still be watching.

Preserve the Evidence — Why It Matters

Proper forensic preservation helps determine how the attackers got in, whether they are still inside, what data was accessed or exfiltrated (which drives your notification obligations), and which recovery options remain. This is why “unplug from the network but leave it running, and touch nothing else” is the right posture. Our digital forensics team handles exactly this kind of preservation and analysis, nationwide.

When to Call a Forensics and Incident Response Team

Call sooner than feels comfortable. Bring in professional help when business-critical systems are encrypted, you cannot confirm the attackers are out, sensitive or regulated data may be involved, your backups are unclear, or you are being pressured toward a ransom decision. Honeybadger’s cybersecurity services cover incident response and recovery, and because this work is not tied to physical presence, we can support businesses across the country.

After the First 24 Hours — Recovery and Hardening

Once contained, the work shifts to safe recovery: restoring from verified-clean backups, closing the exploited vulnerability, rotating credentials, validating that the attackers no longer have access, and reviewing what allowed the intrusion. If you are reading this before an incident, that is the ideal time to assess your exposure with a structured Cyber Risk Check.

Frequently asked questions

Should I turn off a computer that has ransomware on it?
No. Isolate it from the network but leave it powered on. Shutting down or rebooting can destroy evidence held in memory and eliminate recovery options.

Should I pay the ransom to get my files back?
Not before getting expert advice. Payment carries no guarantee of recovery and can raise legal and regulatory issues.

When should I call an incident response team?
Immediately — as soon as critical systems are affected, you cannot confirm the attackers are out, sensitive data may be involved, or your backups are in question.

If ransomware has hit your business, isolate, preserve, and get professional help — do not wipe, do not reboot, do not go it alone. Honeybadger Solutions provides digital forensics and incident response nationwide. Call (602) 725-2818 now, or request a consultation.

What NOT to do in the first 24 hours

In a ransomware event, the wrong reflexes destroy the evidence and options you will need later. Avoid these:

  • Do not power the machines off. Pulling the plug can wipe volatile memory that often holds encryption keys, attacker tooling, and the clues to how they got in. Isolate from the network instead of shutting down.
  • Do not start deleting or “cleaning” files. You may be destroying forensic evidence and the very artifacts needed to scope the breach and support an insurance claim.
  • Do not wipe and restore immediately. Rebuilding before the environment is understood often reinfects from a backdoor the attacker left behind.
  • Do not communicate on the compromised network. Assume email and chat are being watched. Move incident communications to an out-of-band channel.
  • Do not negotiate or pay on your own. Payment has legal, sanctions, and practical risks, and paying does not guarantee recovery.

Should you pay the ransom?

There is no universal answer, and it is not a decision to make in a panic. Paying can carry legal and regulatory exposure, funds criminal operations, and frequently still leaves data encrypted or exfiltrated. It should only ever be weighed with legal counsel, your cyber-insurance carrier, and incident-response professionals at the table — after the scope is understood. Often, disciplined forensics and clean backups make payment unnecessary.

How digital forensics changes the outcome

Proper forensic response does more than clean up. It preserves a defensible record of what happened, determines whether data was exfiltrated (which drives your legal notification obligations), identifies the initial access point so it can be closed, and produces the documentation your insurer and, if needed, regulators will require. Skipping this step is how organizations get hit twice and lose their claim. Honeybadger’s digital forensics and cyber services teams handle exactly this — evidence-first response that protects both your recovery and your legal position.

Reporting and notification — do not overlook it

Depending on the data involved, a ransomware incident can trigger legal notification duties to affected individuals, regulators, and partners, and specific requirements if you carry cyber insurance. The forensic finding of whether data was accessed or exfiltrated is what determines those obligations, which is another reason evidence preservation in the first hours matters so much.

Frequently asked questions

How fast should we engage incident response? Immediately. The first hours shape both technical recovery and legal exposure.

Will our backups save us? Only if they are clean, tested, and offline. Attackers routinely target backups first, which is why they must be verified before restoration.

Can you help after hours? Yes. Ransomware does not keep business hours, and neither does incident response. Call (602) 725-2818.

Who needs to be in the room, and in what order

The first hour usually fails not because people do the wrong technical thing but because nobody knows who decides. Establish the call list before you need it, and work it in this order.

Counsel first. Engaging counsel early allows the investigation to be directed in a way that preserves privilege where it applies, and counsel owns the notification analysis that starts running immediately. This is not a formality; the sequence materially affects what can be protected later.

The insurer, within the policy’s notice window. Most cyber policies require prompt notice and many require the use of panel vendors for forensics and negotiation. Engaging your own firm before notifying can jeopardise coverage for those costs.

Incident response and forensics, either your own provider or the panel firm.

Executive leadership, with a single named decision-maker. Three people making independent calls is the most common failure mode in the first day.

Law enforcement. The FBI takes ransomware reports and occasionally holds decryption keys or intelligence about a specific group. Reporting does not obligate you to anything.

Keep a written log from the first minute: what was observed, what was done, by whom, at what time. It will be needed for the insurer, for counsel, and for the after-action review, and nobody reconstructs it accurately afterwards.

Communicating while systems are down

Most incident plans assume email works. In a ransomware event it frequently does not, and neither does the phone system if it runs on the same infrastructure.

Decide now what the out-of-band channel is: a group messaging application on personal phones, a conference bridge with dial-in numbers printed on paper, or a pre-agreed alternate email domain. Keep a printed contact list including staff mobile numbers, the insurer’s claim line and policy number, counsel, and key vendors, somewhere that does not depend on the network.

Assume the attacker may be reading internal communications if they still have access. Sensitive discussion about response, negotiation or containment should happen out-of-band until you know the environment is clean.

What to tell staff, customers and the public

Silence creates rumour and rumour creates worse facts than the truth. A short, accurate holding statement issued early beats a detailed one issued late.

For staff: what has happened in plain terms, what they should and should not do — specifically, do not attempt to fix anything, do not connect personal devices, do not discuss it externally — who to contact with questions, and when the next update will come. Staff who hear nothing assume the worst and talk to customers anyway.

For customers and partners: what is affected, what is not, what you are doing, and when they will hear more. Avoid characterising the scope before the forensics support it; “we are investigating” is defensible and “no customer data was affected” is a statement you may have to retract.

Do not speculate publicly about attribution or about whether data was taken. Both change as the investigation develops.

Restoration order matters

Recovery is not a race to bring everything back. Restoring into an environment that is still compromised is how organisations get encrypted a second time during recovery, and it happens regularly.

The sequence that works: establish a clean environment, rebuild identity infrastructure first and reset credentials including service accounts, verify that the initial access path is closed, then restore systems in business priority order from verified backups, validating each before connecting it. Rebuild rather than clean where the machine held attacker tooling; “cleaned” is not a state anyone can verify.

Track two numbers as you go: how long restoration is actually taking against what the plan assumed, and what could not be restored. Both are findings for the after-action review, and the second is usually the more important.

The after-action review is where the value is

Within a few weeks of recovery, while memory is fresh, walk the whole event with everyone involved and answer six questions honestly. How did they get in? How long were they present before detection? What detection should have caught it and why did it not? What slowed the response? What data was actually accessed or taken? And what would we do differently?

Turn the answers into a short list of changes with owners and dates. Organisations that skip this step experience the same incident twice, and the second one is not cheaper.

Reporting obligations in Arizona and beyond

Notification clocks begin before the investigation finishes. Arizona’s breach notification statute has its own definitions, timelines and triggers. Healthcare data brings HIPAA obligations with separate timing. Payment card data brings contractual obligations to card brands. Customers in other states bring those states’ requirements, and some are considerably shorter. Publicly traded companies face disclosure rules of their own.

This is why the forensic scope is set with counsel: the technical investigation has to answer the specific questions the notification analysis needs, and an investigation scoped only for recovery frequently cannot.

This page is general information, not legal advice. Notification obligations are fact-specific and change; involve counsel early.