All Resources
Backup & Disaster Recovery

Ransomware Recovery: What Should a Business Do First?

Discovering ransomware is one of the worst moments a business owner will experience, and the decisions made in the first hour genuinely affect how the rest of the incident plays out. This guide focuses specifically on the recovery response once ransomware has already hit. For prevention steps taken before an attack, see [how to protect your business from ransomware](/resources/how-to-protect-your-business-from-ransomware), and for the broader question of what to do after any kind of compromise, see [what to do if your business has been hacked](/resources/what-to-do-if-your-business-has-been-hacked). This article is general information, not legal advice; consult a lawyer and your cyber insurer for guidance specific to your situation.

Published August 9, 2026 Updated August 9, 2026 9 min read By Joshua Arimoro Greater Sudbury & Ontario
The short answer

The first steps after discovering ransomware are to isolate affected devices from the network immediately without shutting them down, preserve evidence, notify your IT provider or incident response team, and involve your cyber insurer and, where personal information is affected, consider notification obligations, before making any decision about restoring from backup or considering payment.

The first 60 minutes

  1. Isolate, do not power off. Disconnect affected devices from the network (unplug ethernet, disable Wi-Fi) rather than shutting them down, which can destroy forensic evidence needed to understand how the attacker got in.
  2. Alert your IT provider or internal IT team immediately, even if you are unsure whether it is truly ransomware or a smaller-scale infection.
  3. Identify what is actually encrypted or affected, including whether the attack has reached backup systems, before deciding on next steps.
  4. Preserve evidence: take photos of ransom notes, note timestamps, and avoid deleting or reinstalling anything until told it is safe to do so.
  5. Contact your cyber insurance provider if you have a policy, many require notification within a specific window and may direct you to an approved incident response firm.
  6. Do not attempt to negotiate with or pay the attacker on your own before consulting your insurer, legal counsel, and IT/incident response team.

Containment beyond the first hour

  • Change passwords for all administrator and privileged accounts from a known-clean device
  • Disable remote access tools (VPN, RDP) until the entry point is identified
  • Check whether backup systems were accessed or altered before assuming they are safe to restore from
  • Review firewall and endpoint logs with your IT provider to scope how far the attacker moved through the network
  • Keep affected systems isolated rather than reconnecting them to "see if it's fixed"

Who to notify in Canada

Reporting obligations and recommendations vary by the nature of the incident and what data was affected. The following is general guidance, not legal advice.

  • The Canadian Centre for Cyber Security (cyber.gc.ca) accepts incident reports and publishes guidance for organizations responding to ransomware
  • Local police or the RCMP, particularly where extortion, theft, or a significant financial loss has occurred
  • The Office of the Privacy Commissioner of Canada, where personal information has been compromised, PIPEDA requires notification of affected individuals and the Commissioner in cases posing a real risk of significant harm; regulated industries (health, legal, financial) may have additional obligations
  • Your cyber insurance provider, generally as a first call given contractual notification windows
  • Your legal counsel, especially before making any public statement or decision about payment

In the middle of a ransomware incident right now?

Isolate affected devices immediately and contact us for emergency incident response support.

Get Emergency IT Support

Should a business pay the ransom?

There is no blanket recommendation here, and this is not advice to pay or not pay. What is important is understanding the real risks involved in paying: there is no guarantee attackers will provide a working decryption tool, payment can mark a business as a repeat target, and in some jurisdictions payment to sanctioned entities can carry legal exposure. Many organizations that pay still face partial or corrupted data recovery.

The decision should involve your insurer, legal counsel, and IT provider together, weighing the specific circumstances, including whether clean backups exist as an alternative to paying at all.

Restoring from backup after ransomware

This is exactly why immutable, offline backup copies matter so much, an immutable backup following the 3-2-1-1-0 rule cannot be deleted or encrypted by an attacker who has already compromised admin credentials, which is often the difference between a fast recovery and having no clean copy to restore from at all.

  1. Confirm the scope of the attack and the entry point before restoring, otherwise you risk reinfecting a freshly restored system.
  2. Identify the most recent clean, verified backup taken before the infection began, which may be earlier than the point of encryption if the attacker was present undetected for some time.
  3. Restore to isolated, rebuilt infrastructure rather than the compromised systems directly.
  4. Rotate all credentials again once systems are back online, including service accounts and any credentials stored on affected devices.
  5. Bring systems back online in a controlled sequence, starting with core infrastructure and identity systems before line-of-business applications.
  6. Monitor closely for signs of reinfection or lingering attacker access for weeks after restoration.

Post-incident hardening

  • Conduct a post-incident review to understand exactly how the attacker got in and close that gap
  • Roll out or reinforce security awareness training, phishing remains the most common entry point
  • Review and tighten endpoint detection and response and managed detection and response coverage
  • Re-test backup restores on a regular schedule going forward, not just after an incident
  • Review the broader cybersecurity posture of the business, ransomware recovery is a good forcing function for changes that were previously deferred

Sources and further reading

Frequently asked questions

Should I turn off an infected computer?

No, disconnect it from the network instead of shutting it down, powering off can destroy evidence needed to understand how the attacker got in.

Do I have to report a ransomware attack in Canada?

Reporting depends on the situation; PIPEDA requires notifying affected individuals and the Privacy Commissioner where personal information is compromised and there is a real risk of significant harm, and reporting to the Canadian Centre for Cyber Security is recommended regardless. Confirm specific obligations with legal counsel.

Should a business pay the ransom?

This is not something we advise on generically, paying carries real risks including no guarantee of data recovery, and the decision should involve your insurer and legal counsel.

Can we just restore from backup and skip the investigation?

No, restoring without understanding the entry point risks reinfecting the restored systems, containment and investigation need to happen first.

How is this different from a general "we've been hacked" situation?

Ransomware specifically involves encryption or extortion and often requires a decision about restoring from backup versus considering payment, which general compromise response does not, see our related guide on what to do if your business has been hacked for broader compromise steps.

About the author

Joshua Arimoro

Joshua Arimoro is the Principal Consultant at Nickel City Tech Solutions, a managed IT and cybersecurity provider based in Lively, Ontario, serving businesses across Greater Sudbury and Northern Ontario. He works hands-on with Microsoft 365, server and network infrastructure, endpoint management, and backup and recovery for small and mid-sized organisations.

More about our team

Build a ransomware response plan before you need one

We help Northern Ontario businesses put an incident response and ransomware-resilient backup plan in place ahead of an attack, not during one.

Keep exploring

Related services, locations, and resources

Related services

Related resources