Hour zero: contain without destroying evidence
- Disconnect affected machines from the network — pull cables, disable Wi-Fi — but leave them powered on. RAM contains encryption keys and attacker artifacts that vanish at shutdown.
- Disconnect or power down backup systems and drives immediately if they aren't already encrypted — surviving backups are your recovery.
- Photograph ransom notes and screen states; note timestamps of when things were first noticed.
- Change credentials from a known-clean device (a phone on cellular counts) — start with email, banking, and admin accounts.
- Establish communications off the suspect network. Assume the attacker read what's on it.
The first day: insurers, assessment, and the honest inventory
Call your cyber-insurance carrier's incident line as early as possible — most policies require prompt notice, and many carriers bring breach counsel and response resources you're already paying for. Loop in your attorney; depending on what data was touched, Louisiana's notification obligations and industry rules may apply on a clock.
Then comes the unglamorous core of recovery: the honest inventory. What systems are encrypted? What data may have been exfiltrated? Which backups survived, from when, and are they clean? What's the true rebuild order — which system does the business need Monday morning versus next month? This assessment, not the ransom note, determines every decision that follows.
On paying: that decision belongs to leadership with counsel and carrier at the table. Payment doesn't guarantee working decryption, may carry legal exposure depending on the actor, and does nothing about how they got in. The assessment's job is to give you the factual basis: what's recoverable without paying, at what cost, in what time.
Day two and beyond: rebuild clean, in priority order
The cardinal recovery sin is restoring good data onto a compromised network — reinfection turns a bad week into a bad quarter. Rebuild targets must be verified clean or built fresh: new hosting for public-facing services, rebuilt or reimaged servers for internal ones, restored data validated before reconnection. Nubinity scopes recovery engagements that include clean rebuild targets on its own New Orleans-operated infrastructure when yours can't be trusted yet.
Recovery isn't finished when systems are back — it's finished when the entry point is closed and the pattern can't repeat: managed endpoint protection with anti-ransomware controls on every device, firewall policy that kills exposed remote access, MFA through single sign-on, and backups that are separated, offline or immutable, and actually test-restored.