Jeyki SecurityCybersecurity consulting
Ransomware

Ransomware Response Checklist for Small Businesses in BC

A first-hours checklist for small Vancouver and BC businesses hit by ransomware: what to isolate immediately, what to preserve as evidence, and how to decide next steps without panic-driven mistakes.

← Back to guidesPublished 2026-08-20 · Updated 2026-08-20

The first hour decides how bad this gets

Ransomware rarely announces itself gently. It shows up as files that will not open, a ransom note on the desktop, or a wave of help-desk calls at once. What you do in the first hour has an outsized effect on how much data and money you lose, because ransomware spreads through shared drives and connected systems while you are still figuring out what happened.

Contain first, investigate second

The instinct to start digging through files to understand what happened is natural, but containment comes first. Every extra minute a device stays connected is a chance for the infection to spread further.

  • Disconnect affected devices from the network immediately, physically pulling the cable or disabling Wi-Fi if needed
  • Do not power devices off if avoidable, since some evidence and encryption keys can live in memory; disconnect from the network instead
  • Isolate shared drives, backup servers, and file shares from any device suspected of infection
  • Change passwords for admin and other privileged accounts from a device you know is clean
  • Do not pay the ransom or engage the attacker before getting professional and, where relevant, legal advice

What to preserve before you touch anything else

Evidence gets destroyed easily during a panicked cleanup. Preserving it matters for insurance claims, law enforcement reporting, and understanding how the attacker got in so it does not happen again.

  • Photograph the ransom note and any on-screen messages before closing anything
  • Keep a timeline: when symptoms were first noticed, by whom, and what actions were taken
  • Preserve affected devices in their disconnected state rather than reimaging immediately
  • Identify which backups exist and whether they were connected to the network at the time of the attack

Backups: your leverage against paying

Offline or immutable backups are the single biggest factor in whether a business needs to consider paying a ransom at all. If backups are current, tested, and were disconnected from the network when the attack hit, recovery without paying is usually possible.

  • Confirm backup integrity before assuming they are usable; a corrupted backup is not a real backup
  • Restore to clean, rebuilt systems rather than the infected environment
  • If backups were also encrypted because they stayed connected to the network, this is the lesson for next time: keep at least one copy offline or immutable

After containment: report, notify, and rebuild deliberately

Once the bleeding has stopped, the work shifts to reporting obligations, communication, and a rebuild that does not just restore the same vulnerability.

  • Report the incident through Canada's national cybercrime and fraud reporting system
  • Assess whether personal information was affected, which may trigger PIPEDA breach notification obligations
  • Notify your cyber insurance carrier promptly; many policies require early notification to preserve coverage
  • Rebuild from clean images rather than trusting a disinfected but not rebuilt machine
  • Close the entry point before reconnecting anything, since ransomware groups frequently reuse the same access

Frequently asked questions

Should we ever pay the ransom?

Paying does not guarantee a working decryption key, can fund further criminal activity, and may carry legal risk depending on who the attacker is. Most guidance, including from the Canadian Centre for Cyber Security, advises against paying and toward prevention and clean recovery from backups wherever possible. Get professional and legal advice before making this decision.

How do we know if the attacker also stole data, not just encrypted it?

Many modern ransomware groups exfiltrate data before encrypting it, then threaten to publish it as extra leverage ('double extortion'). Log review and, in serious cases, a forensic investigation are usually needed to determine whether data left the network, which also affects breach notification obligations.

Can a small business realistically recover without professional help?

Sometimes, if backups are solid and the environment is simple. But identifying the entry point, confirming the infection is fully removed, and handling reporting and insurance correctly usually benefits from experienced help, especially since a rushed, incomplete cleanup is a common reason ransomware recurs at the same business within months.

Official resources