Think you're being hit by ransomware right now? Don't panic — start here →
Already a safemode IT client? Call our 24/7 Security Operations Center immediately: 512-761-7652, Option 1
IF YOU'RE HIT

You think you've been hit. Here's exactly what to do, in order.

This sequence follows CISA and FBI guidance for ransomware and other cyber incidents. Move through it calmly — the decisions you make in the first hour matter more than the ones you make in the first minute.

1

Isolate the affected device(s) immediately

Unplug the network cable or disable Wi-Fi on any device showing signs of compromise. Don't power the device off unless it's actively spreading and you can't otherwise stop it — powering off can destroy evidence investigators need.

2

Alert your team by phone or text — not email or chat

If attackers are inside your network, they may be watching your email and messaging systems. Coordinate out-of-band.

3

Don't wipe, reinstall, or "clean" anything yet

It's tempting to start fixing immediately. Preserve the evidence first — your insurer and any investigator will need it, and a rushed cleanup can destroy your only path to a free decryption tool.

4

Call for hands-on-keyboard help

safemode IT clients: call your 24/7 support line. Otherwise, engage a qualified incident response provider immediately — this is not a solo job.

5

Call your cyber insurance carrier before you spend a dollar

Most cyber policies require you to use pre-approved incident response vendors and legal counsel. Spending first and filing a claim later can jeopardize coverage.

6

Report it to law enforcement

File a report with the FBI's Internet Crime Complaint Center (IC3), and contact your local FBI field office or CISA (report@cisa.gov). Reporting doesn't cost you anything and helps track the attackers.

7

Loop in legal counsel on notification obligations

In Texas, you generally have 60 days to notify affected individuals, and 30 days to notify the Texas Attorney General if 250 or more Texas residents are affected. See our Compliance Resources and Safe Harbor Laws pages for how this connects to your legal exposure.

8

Recover from clean, tested backups — don't trust a "cleaned" machine

Rebuild affected systems from backups you're confident predate the compromise, rather than trying to disinfect an infected machine and hoping nothing was left behind.

About paying the ransom

CISA and the FBI do not recommend paying a ransom. Payment doesn't guarantee you'll get a working decryption key, it funds future attacks against other small businesses, and in some cases payment can carry legal risk if the attacker turns out to be a sanctioned entity. This decision — if it comes to it — should be made with your legal counsel, insurer, and law enforcement at the table, not alone under pressure.

Check for a free decryptor first

Before considering any payment, check the No More Ransom Project — a free, law-enforcement-backed tool that has decryption keys for a number of known ransomware strains.

MID-INCIDENT AND NEED HELP RIGHT NOW?

Call safemode IT's team directly.

If you're actively dealing with an incident, don't wait on a form. Call 512-761-7652 for immediate hands-on-keyboard help.