
Learn how to respond fast to a ransomware attack
Don’t let your servers, computers and data be taken hostage and held for ransom. Asking yourself a few simple questions could help you save millions of hard-earned dollars.
Cyber security is critical to the safety of your organization. In addition to strengthening your security posture and increasing profitability and efficiency, protecting your business against cyber threats brings you peace of mind. Knowing how to respond if your organization is hit with ransomware is crucial.
Download the Checklist

"*" indicates required fields
In need of a new MSP? We’re a Tulsa-based firm serving businesses in Tulsa, Bartlesville, Broken Arrow, Muskogee, Oklahoma City, Moore, Tahlequah, Stillwater, Ponca City, Sand Springs, Owasso and beyond. Contact our team today.
I’m Brian Largent. I’ve spent 30+ years running IT and cybersecurity for Oklahoma businesses, and I’ve walked into more ransomware scenes than I’d like to count. This page is the checklist I wish every business owner had taped to the inside of their server room door before the attack, not after.
It’s built from the real incidents we’ve handled: the Tulsa manufacturer who lost $100,000 a day in production, the 1,500-employee company that came within 15 minutes of total data loss, and the hospital that was still rebuilding years after they paid the ransom. No theory. No fluff. Just what actually happens and what actually works.
Use it two ways. If you’re in a calm moment, use the preparedness checklist below to audit your environment this week. If you’re staring at a ransom note right now, skip to The First 60 Minutes. Either way, the goal is the same: keep your business alive.
Before Ransomware Hits: The Preparedness Checklist
Every item on this list came out of a real incident where having it saved a company, or not having it cost one dearly. Go through it with your IT team or your MSP. If they hesitate on any answer, that’s your answer.
Insurance
Most business owners think “I have cyber insurance” and stop there. That’s not the conversation. The conversation is what’s buried in the fine print.
- ☐ You know your ransomware sub-limit in writing (a $4M policy can have a $100K ransomware cap, and yes, we’ve seen it)
- ☐ You know your business email compromise sub-limit separately from ransomware
- ☐ You have your carrier’s approved attorney list and approved forensics vendor list saved somewhere you can reach without your network
- ☐ You understand the notification requirements: how many hours you have to report an incident before coverage can be denied
- ☐ You know what security controls your carrier requires you to maintain (MFA, EDR, patching cadence); if you’re not meeting them, your claim can be reduced or denied
- ☐ You’ve asked your broker point-blank: “If we get dropped after a claim, what does replacement coverage look like?” (Budget for 10x to 30x premium increases)
Backups
I’ll say this plainly: if your backups live on the same network as your production systems with the same credentials, you don’t have backups. You have a file copy the attackers will encrypt next.
- ☐ Backups run on a separate network from production (not just a different subnet, not just a VPN tunnel)
- ☐ Backups use separate authentication: a different admin account with a different password than your domain admin
- ☐ Backups use separate encryption keys that aren’t recoverable from a compromised domain controller
- ☐ You have immutable or offline copies (tape, air-gapped, or object-lock cloud storage)
- ☐ You’ve actually tested a full restore in the last 90 days, not just a single file
- ☐ Every critical server (especially custom or in-house developed applications) is confirmed in the backup set, not assumed
- ☐ SAN/NAS snapshots are enabled and retained long enough to survive an attack that sits dormant for days before executing
Endpoint Security
Traditional antivirus is an abacus in a calculator world. It looks for known signatures. Modern ransomware operators don’t use known signatures. They use living-off-the-land techniques and legitimate tools. You need something that watches behavior.
- ☐ EDR (Endpoint Detection and Response) on every workstation and server, not traditional AV
- ☐ 24/7 SOC monitoring that can isolate a machine the moment it starts behaving badly
- ☐ Privileged Access Management (PAM) so domain admin credentials aren’t sitting in memory on every workstation
- ☐ RMM (Remote Monitoring & Management) with locked-down scripting access
- ☐ Intune or equivalent MDM managing device posture, patching, and BitLocker keys
- ☐ MFA on every remote access point: VPN, RDP, email, cloud admin consoles, backup portals
- ☐ Patching cadence documented and audited (not just “we patch regularly”)
Employee Training
I’ve fallen for one of our own phishing tests. It happens to all of us. The point isn’t shame, it’s knowing where you stand.
- ☐ Monthly phishing simulations with results tracked per employee
- ☐ Accountability tied to repeat clickers: extra training, manager conversations, not just “oh well”
- ☐ Annual security awareness training at minimum, quarterly micro-training is better
- ☐ Training covers business email compromise, wire fraud, and gift-card scams, not just classic phishing
- ☐ Clear, documented policy for verifying financial requests out-of-band (a phone call to a known number, not a reply to the email)
Incident Response Plan
- ☐ Documented incident response plan that exists outside your network (printed, in a safe, or in a secure cloud doc you can reach from your phone)
- ☐ A designated incident commander named in advance, with a backup
- ☐ Your IT provider’s emergency after-hours number in writing, not just in someone’s cell phone
- ☐ Your insurance carrier’s claims line saved the same way
- ☐ A written “do not touch” rule so a panicked employee doesn’t reboot an encrypted server and destroy evidence
- ☐ A communication plan for customers, vendors, and employees (you can’t hide a ransomware event past 24 hours)
- ☐ Tabletop exercise run at least once a year with leadership, not just IT
Recovery Readiness
This is the part that surprises people. You can’t recover onto your existing hardware during an investigation. Insurance and forensics need to preserve those machines as evidence. So where are you recovering to?
- ☐ A source for cold-spare servers ready within hours, not days (we keep over $100,000 in cold spares racked and waiting for exactly this)
- ☐ A new-hardware budget line approved in advance so procurement doesn’t stall recovery
- ☐ Laptop logistics worked out for remote employees: shipping accounts, reimaging capacity, loaner pool
- ☐ A list of vendor contacts who can expedite hardware (Dell, HPE, local resellers)
- ☐ Known-good gold images for workstations and servers, stored offline
The First 60 Minutes: What to Do (and What NOT to Do)
If you’ve just realized you have ransomware, your instincts are going to be wrong. I mean that with respect. Every normal IT instinct you have is backwards right now. Here’s the discipline.
STOP. Do NOT do these things.
- ☐ Do NOT try to fix it. Don’t reboot servers. Don’t run scans. Don’t delete files. Every action destroys forensic evidence and can void your insurance claim.
- ☐ Do NOT turn off infected servers. Powering down wipes volatile memory forensics need. Disconnect from the network instead (pull the cable, disable the switchport, kill the Wi-Fi).
- ☐ Do NOT pay the ransom without insurance involvement. Payments to sanctioned entities can be a federal violation. Your carrier and their attorneys will walk this minefield; you will not.
- ☐ Do NOT start restoring backups until forensics clears you. You may be restoring the attacker’s persistence along with your data.
- ☐ Do NOT talk to the attackers yourself. Let the professional negotiators your insurance assigns handle that channel.
DO these things, in this order.
- ☐ Disconnect affected machines from the network. Physical cable, disabled switchport, disabled Wi-Fi. Leave the machines powered on.
- ☐ Call your insurance carrier first. Not IT. Not your lawyer. Not the FBI. Insurance. This protects your claim through the subrogation process.
- ☐ Call your IT provider (their after-hours emergency line) so they can coordinate with the forensics team your carrier assigns.
- ☐ Document everything. Screenshots of the ransom note, timestamps, what was noticed when, who did what. A running log in a notebook or a phone is fine.
- ☐ Communicate with customers and vendors who are actively affected. You can’t hide a ransomware event past 24 hours, and partners will respect transparency more than a mysterious outage.
That’s the first hour. The encryption is already done by the time you see the note, so speed doesn’t help you. Discipline does.
Days 1 to 3: What Actually Happens
Here’s where expectation and reality part ways. You think recovery starts on day one. It doesn’t. The first 72 hours are about triage, paperwork, and picking vendors under pressure.
Your insurance carrier will hand you two lists: an approved attorney list and an approved forensics vendor list. You don’t get to use your own. You pick names off the list under extreme pressure. It’s like being handed a phone book in the emergency room and told to pick your own surgeon.
Then comes the wait. In the Tulsa manufacturer case we handled, the forensics company took three full days just to assemble their team and begin. Three days before anyone started looking at the problem. At $100,000 per day in lost production, that’s $300,000 gone before a single recovery action is taken.
The forensics company will probably be underwhelming. I don’t say that to be harsh. It’s just what we’ve seen repeatedly. Our engineers have ended up leading the recovery while the assigned forensics team watched. On that manufacturer, the forensics team’s first instruction was “turn the computers back on and install our agent.” Our guy stopped them cold and insisted on safe-mode boots first so the ransomware wouldn’t re-execute. They hadn’t thought of it.
While forensics is getting organized, you should be doing three things in parallel. Line up replacement hardware (you cannot recover onto the infected machines). Confirm your backups are intact and identify gaps (custom software, not-in-the-backup-set servers, the things that would be catastrophic if lost). And start the customer communication plan.
Use our disaster recovery calculator to put a real number on what each of these days is costing you. It helps frame why preparation matters before the incident, not during.
Weeks 1 to 4: Recovery That’s Not What You Think
Even once forensics clears you to start recovery, it’s not “restore from backup and go home.” Here’s what the next three to four weeks actually look like.
You can’t use your existing hardware. Every infected machine is potential evidence. You’re standing up recovery on cold-spare servers or new hardware you’re procuring in the middle of a crisis. On the manufacturer case, the client rented two high-end loaner servers from us at $1,000 per month each for three months while they purchased permanent replacements.
You rebuild almost every workstation. Even if forensics says the backup window was clean (less than 24 hours of exposure, as it was on the manufacturer), you don’t trust the workstations. Ever. You reimage them all. You reimage remote employees’ laptops too, which means shipping accounts, loaners, and a logistics plan most companies don’t have.
Some servers aren’t in the backup set. There are always a few. A server that got spun up for a project three years ago. A dev box somebody forgot to add. Those get rebuilt from file copies scattered across other systems, if you’re lucky. If you’re not, they’re gone. On one case we handled, the company’s in-house developed CRM was in the backup set by pure luck. If it hadn’t been, the business might not have survived.
You never trust your systems the same way again. That’s not paranoia, it’s the right response. Ransomware leaves a psychological residue on an IT environment. Every weird alert for the next two years gets the same question: is this them again?
There’s a related case we handled that’s worth knowing about. A 1,500-employee manufacturer was 15 minutes from permanent data loss when we thought to check their SAN snapshots. A third-party vendor had configured automatic snapshots years earlier; the internal team didn’t even know they existed. The snapshot rotation was about to overwrite the last clean copies. We stopped the rotation and restored from snapshot. Fifteen more minutes and that company would have been rebuilding from nothing.
After the Incident: The Things Nobody Warns You About
The incident doesn’t end when the systems come back up. Here’s what the next 12 to 36 months look like, and why the financial damage keeps compounding long after the ransom conversation is over.
Your carrier drops you. Not always, but often. And when you shop for replacement coverage, you’re not looking at a 10% or 20% premium increase. We’ve watched organizations hit with 10x to 30x their previous premium. A $300,000 policy becomes $3 million. Some organizations simply can’t get coverage at all with a ransomware incident on their record.
Rebuilding takes years, not weeks. We’ve consulted on hospital ransomware incidents (publicly reported in the news, like the Stillwater Regional Medical Center event) where the organization was still dealing with aftereffects three, four, five years later. Shadow infrastructure set up during the crisis becomes permanent. Legacy configurations nobody fully understands creep into compliance gaps. Technical debt compounds.
Reputation doesn’t heal on your schedule. Customers remember. Partners remember. Prospects Google your company name and see the incident. For years afterward, you’re “the company that got hacked.” It affects deals, partnerships, and the talent you can recruit.
Regulatory exposure lingers. HIPAA, PCI, state breach notification laws. Each one has its own timeline, its own fines, its own paperwork. The attack is over; the compliance work is just starting.
Download the Full Checklist (Optional)
Want a printable, one-page version to tape inside your server room door or hand to your leadership team? We kept the original PDF download available. No gate, no hoops; just grab it and use it.
Download the one-page Ransomware Response Checklist (PDF)
Print it. Share it with your leadership team. Run a tabletop exercise against it. Whatever you do, don’t file it in a share that gets encrypted the day you need it. Keep a physical copy.
Schedule a Free 27-Point IT Risk & Ransomware Assessment
A checklist is a starting point. Knowing where your actual gaps are takes a real assessment. At ArcLight, we do a free 27-point IT Risk & Ransomware Assessment for Oklahoma businesses. It takes about an hour. You get a clear picture of where you stand and what to prioritize. No hard sell. No obligation.
I’d genuinely rather spend an hour with you now than get that emergency phone call at 2 AM. Call (918) 270-6600 or schedule your assessment online. If you want to go deeper on what ArcLight actually does day-to-day, see our cybersecurity services page, or read the full story of what happens when your business gets ransomware.
Brian Largent is the founder and CEO of ArcLight Group, a Tulsa-based managed IT and cybersecurity firm serving Oklahoma businesses with 10 to 100+ computers. He has spent 30+ years helping companies build IT infrastructure that doesn’t fall apart when it matters most.