Chant's IT
Back to Insights
Security6 min read

When your Cape Breton business gets hit with ransomware

What to do in the first hour, first day, and first week after a ransomware attack — practical playbook from someone who has walked local businesses through it.

Ransomware doesn't announce itself. Someone opens what looks like a normal invoice PDF on a Tuesday afternoon, and by Wednesday morning half of your office can't get into their files. The whole shared drive is renamed.encrypted and there's a text file on the desktop asking for Bitcoin.

We've walked a handful of Cape Breton businesses through this over the years. None of them saw it coming, and every one of them wished they'd known what to do in the first hour. Here's the playbook.

The first hour: contain, don't panic

The single most important thing in the first hour is to stop the spread. Ransomware doesn't just encrypt the machine it lands on — modern variants scan the network, find shared drives, and encrypt everything they can reach. Every minute a compromised machine stays connected to your network is more files gone.

  1. Unplug the affected machines from the network. Yank the Ethernet cable, disable WiFi, physically disconnect. Do not shut them down cleanly — leave them running so we can look at memory later if needed, but isolate them.
  2. Disconnect the shared drive / server, if you have one. Either pull its network cable or shut it down. This is the second-most important step.
  3. Do not pay the ransom yet. The ransom note has a countdown; ignore it. Paying should be a last-resort business decision made after you understand your options, not a panic reaction.
  4. Call us. If you're a managed client we're already alerting; if not, this is the call to make before any others.

The first day: assess, don't overreact

Once things are isolated, the questions are: what got encrypted, when did it start, do we have clean backups, and do we know how it got in.

What got encrypted: we walk every affected machine and every network share, catalogue what's touched, and — critically — check what'snot touched. Often key systems are fine because they weren't reachable from the infected machine.

When it started: ransomware usually sits dormant for hours or days after initial infection, mapping the network before it triggers. Knowing the actual initial-compromise time matters because it tells you which backups are safe to restore from.

Backup posture: this is the moment your backup strategy either saves you or doesn't. Backups that are online and reachable from the network are often encrypted too. Backups that are offline, immutable, or air-gapped are the ones that save businesses. If your backups are gone, restore-from-backup stops being an option and the decision tree gets uglier.

How it got in: almost always email (a link or an attachment) or an exposed remote-access service (RDP, an old VPN, a weak-password admin account). Knowing the entry point tells you what else might be compromised.

The first week: rebuild carefully

If backups are clean, the plan is: wipe affected machines completely (not "clean them up" — full wipe, fresh OS install), restore data from the last known-good backup, rotate every password that was on any affected machine, and close the entry point that let it in.

If backups are gone or partial, the calculus changes. Sometimes there's data you can accept losing (last month's emails, that machine's local files). Sometimes the data is business-critical and irreplaceable. That's when paying the ransom enters the conversation as a business decision, not a panic reaction. It's a conversation with your insurance broker, your lawyer, and us — not something you want to be figuring out at 2 AM on a Thursday.

What actually prevents this

We could write a whole other article on prevention, but the short version:

  • Offline / immutable backups. Backup to a system the ransomware can't touch. Test the restore quarterly.
  • Multi-factor auth on every remote-access system. No exceptions for "the owner."
  • Endpoint security that actually works. A modern EDR (we deploy Bitdefender) catches most current ransomware variants before they detonate.
  • Patching. Ransomware often uses months-old vulnerabilities. Automated patching kills those.
  • Staff training on phishing. The last line — but sometimes the one that saves you.

If your business hasn't been through this, you don't want to be finding out how much you don't have in the middle of an active attack. If you'd like a free walkthrough of what your current backup and security posture actually looks like — no obligation — get in touch. It's an hour of our time and it's the closest thing to insurance that we can offer against this specific nightmare.


Is your business actually protected against ransomware?

Free walkthrough — we'll look at your backups, remote access, email posture, and endpoint security, and tell you straight what's working and what isn't.