A ransomware playbook for owners and small teams.
A six-phase walk-through tailored for businesses without a dedicated security team. Recommendations assume a trusted IT partner / MSP, cloud-first tools, and a cyber insurance policy doing the heavy lifting.
Preparation & Prevention
Before anything happens. With no full-time security team, your edge is simplicity: a trusted IT partner, a written incident contact, MFA on every account, and an insurance policy you actually understand. The decisions here decide whether an incident is survivable.
- 01Pick an IT / MSP partner you trust and put their 24/7 number on paper - not just in a Slack DM.
- 02MFA on every account (Microsoft 365, Google Workspace, banking, accounting) - authenticator app over SMS.
- 03Cloud-native backups for Microsoft 365 / Workspace via a third-party tool (the platform recycle bin is not a backup).
- 04Cyber insurance - entry-level policies start around €1–3k / year and are often the difference between surviving and closing.
- 05Use the free baseline: Defender for Business, Google Workspace alerts, national CERT checklists (CISA, NCSC, ANSSI).
- 01Don't share the owner password across the team - every person gets their own account.
- 02Don't run unsupported systems (Windows 7, EOL accounting software) just because "it still works".
- 03Don't assume your MSP is doing backups and patching - get the scope of work in writing.
- 04Don't let staff use personal devices for customer data without basic device management.
- 05Don't misrepresent controls on the insurance form - a small lie about MFA can void a six-figure claim.
- 01Single point of failure: only one person knows admin passwords / goes on holiday next week.
- 02Backup tested? Most small businesses have never tried to restore - the time to find out is not during an incident.
- 03Where is customer data? If you can't list it in 5 minutes, attackers will find more than you do.
Initial Intrusion
Someone clicked, a password leaked, or a vendor was breached. You probably won't see the attack — you'll see weird side effects: an unexpected MFA prompt, customers asking about strange emails, a PC that "just feels slow". Speed and humility matter more than expertise.
- 01Tell the owner immediately - within minutes, not "after we sort it out".
- 02Call your IT / MSP partner on their 24/7 number - they are your first responders.
- 03Disconnect the device (unplug cable, switch off Wi-Fi) but DO NOT shut it down - leaving it on preserves evidence.
- 04Call your insurer hotline the same day - many policies require notice in 24–72 h or reimbursement drops.
- 05Write down what happened on paper: who saw what, when, in what order. Memory fades fast.
- 01Don't search Google for "remove ransomware free" and run random tools - that often destroys evidence.
- 02Don't pay anything that appears on the screen in the first hours, however small.
- 03Don't email everyone "please check your accounts" before you have a plan - staff will panic and lose evidence.
- 04Don't post anything on social media or LinkedIn until you have a statement signed off.
- 05Don't run two antivirus tools at once - they fight each other and miss the threat.
- 01Unusual sign-in alerts from Microsoft 365 / Google in the admin notification email.
- 02Customers report phishing emails coming from your domain - almost always a real breach.
- 03MFA prompts you didn't make: classic sign of credential theft + bypass attempt.
The Attack Hits
Files start encrypting, the ransom note appears, OneDrive / Google Drive shows mass changes, and the team is panicking. Your job is to step back and let the professionals (your MSP + the insurer's DFIR firm) take the technical wheel — and to protect the business while they work.
- 01Let the specialists work - your MSP and the insurer's incident-response firm are now in charge of the technical fight.
- 02Change critical passwords from a clean personal device: email first, then bank, accounting, payroll.
- 03Call your bank - ransomware groups often try to redirect outgoing wires while you're distracted.
- 04Switch to personal phones (Signal, Telegram, calls) - assume corporate email and Teams are compromised.
- 05Tell staff to stop using corporate accounts and devices until your IT partner gives the all-clear.
- 01Don't pay the ransom yourself - your insurer has a negotiator and a sanctions check; paying directly can be a crime.
- 02Don't restore from backup yet - you may be restoring the attacker's backdoor straight back in.
- 03Don't talk to journalists or post explanations on LinkedIn before legal sign-off.
- 04Don't promise customers an exact date for return to service - under-promise, over-deliver.
- 05Don't try DIY decryption from forum posts - paid "decryptors" online are almost always scams or malware.
- 01Cloud drives encrypted: sync clients often spread ransomware through OneDrive / Drive folders.
- 02Emails sent from your domain to customers - check sent items and DMARC reports.
- 03Bank accounts: any pending or recent wire transfers you didn't authorise?
Taking Back Control
The bleeding has stopped. Now: trust the lawyer the insurer gives you, run minimum-viable operations, and start a paper trail of every cost. Survival cash and customer communication matter as much as IT here.
- 01Trust the breach coach (the lawyer your insurer appoints) - they coordinate negotiation, forensics and disclosure.
- 02Define minimum-viable operations: which 1–2 services HAVE to work for the business to invoice and pay staff?
- 03Talk to your accountant about cash flow during downtime - payroll cannot wait.
- 04Keep a paper log of every decision, every invoice, every hour of downtime - your insurance claim depends on it.
- 05Draft a customer message but hold it back until your lawyer and insurer have signed off.
- 01Don't bring systems back until your IT partner confirms in writing they are clean.
- 02Don't fire the employee who clicked the email - blame kills honest reporting next time.
- 03Don't pay invoices that "appear" related to the incident without verifying with your MSP.
- 04Don't cancel cyber insurance to save money during recovery - coverage is still working for you.
- 05Don't ignore your own mental health - owners often spiral; one tough conversation with a friend or coach helps.
- 01Post-incident wire fraud: attackers (or copycats) target your bank account in the chaos.
- 02Customer phishing impersonating your brand in the days after disclosure.
- 03Staff burnout and panic decisions - slow down before signing anything new.
Getting Back To Work
Operations slowly come back. For a small business, "rebuild fresh" is usually cheaper and safer than fixing old machines. The goal is to come out with a simpler, more cloud-first setup — and a customer base that trusts you handled it well.
- 01Rebuild, don't restore wherever possible - new laptops and a clean Microsoft 365 tenant are often cheaper than risk.
- 02Go cloud-first if you weren't already: less server estate means less surface area to defend.
- 03Set up basic monitoring with your MSP / MSSP for at least 6 months after recovery.
- 04Apologise sincerely to customers - for a small brand, honesty beats spin every time.
- 05Keep documenting expenses for the insurance claim, including lost revenue (Business Interruption coverage).
- 01Don't try to save compromised machines for "data we might need" - wipe and reinstall is faster and safer.
- 02Don't restore all staff access at once - stagger it so any issues surface in a small group first.
- 03Don't drop cyber insurance just because premiums went up - you need it more than ever now.
- 04Don't forget Business Interruption: most small businesses underclaim downtime and lost revenue.
- 05Don't go silent - even a short weekly update keeps customers (and your team) from drifting away.
- 01Customer churn in the 30 days after disclosure - track it as a real KPI.
- 02Backup chain restored and tested end-to-end, not just "the file came back".
- 03Revenue lost during downtime - documented daily for the BI claim.
Lessons & Renewal
A few weeks after recovery, sit down with your IT partner and write a simple two-page review. Pick three real improvements, not twenty wishful ones. Use the post-mortem to negotiate next year's insurance with proof of better controls.
- 01Two-page review with your MSP: what happened, what worked, what we change.
- 02Three improvements with deadlines and budget - not twenty without owners.
- 03Get a written renewal quote from the insurer with the new controls in place - premiums often partially recover.
- 04Run a 30-minute tabletop with the team: "if this happened tomorrow, what would we do differently?"
- 05Share anonymously with your local Chamber of Commerce or industry network - others learn, your reputation gains.
- 01Don't blame the person who clicked - they're the most loyal teacher you have now.
- 02Don't think "we got hit once, it's done" - about 38% of victims are re-attacked, often within a year.
- 03Don't sign renewal attestations without updating them honestly with the new controls.
- 04Don't keep paying for security tools you bought in panic but won't use - stick to the essentials.
- 05Don't ignore the team's emotional recovery - incidents leave real marks.
- 01Top 3 improvements actually implemented within 90 days, not promised forever.
- 02Insurance renewal with realistic premium - expect +30–100% the first year.
- 03Total cost vs. annual revenue - the number that argues for next year's prevention budget.