You think you've been hit. Here's exactly what to do, in order.
This sequence follows CISA and FBI guidance for ransomware and other cyber incidents. Move through it calmly — the decisions you make in the first hour matter more than the ones you make in the first minute.
Isolate the affected device(s) immediately
Unplug the network cable or disable Wi-Fi on any device showing signs of compromise. Don't power the device off unless it's actively spreading and you can't otherwise stop it — powering off can destroy evidence investigators need.
Alert your team by phone or text — not email or chat
If attackers are inside your network, they may be watching your email and messaging systems. Coordinate out-of-band.
Don't wipe, reinstall, or "clean" anything yet
It's tempting to start fixing immediately. Preserve the evidence first — your insurer and any investigator will need it, and a rushed cleanup can destroy your only path to a free decryption tool.
Call for hands-on-keyboard help
safemode IT clients: call your 24/7 support line. Otherwise, engage a qualified incident response provider immediately — this is not a solo job.
Call your cyber insurance carrier before you spend a dollar
Most cyber policies require you to use pre-approved incident response vendors and legal counsel. Spending first and filing a claim later can jeopardize coverage.
Report it to law enforcement
File a report with the FBI's Internet Crime Complaint Center (IC3), and contact your local FBI field office or CISA (report@cisa.gov). Reporting doesn't cost you anything and helps track the attackers.
Loop in legal counsel on notification obligations
In Texas, you generally have 60 days to notify affected individuals, and 30 days to notify the Texas Attorney General if 250 or more Texas residents are affected. See our Compliance Resources and Safe Harbor Laws pages for how this connects to your legal exposure.
Recover from clean, tested backups — don't trust a "cleaned" machine
Rebuild affected systems from backups you're confident predate the compromise, rather than trying to disinfect an infected machine and hoping nothing was left behind.
About paying the ransom
CISA and the FBI do not recommend paying a ransom. Payment doesn't guarantee you'll get a working decryption key, it funds future attacks against other small businesses, and in some cases payment can carry legal risk if the attacker turns out to be a sanctioned entity. This decision — if it comes to it — should be made with your legal counsel, insurer, and law enforcement at the table, not alone under pressure.
Check for a free decryptor first
Before considering any payment, check the No More Ransom Project — a free, law-enforcement-backed tool that has decryption keys for a number of known ransomware strains.
Call safemode IT's team directly.
If you're actively dealing with an incident, don't wait on a form. Call 512-761-7652 for immediate hands-on-keyboard help.