First Hour of a Ransomware Incident: A Texas Business Guide
A ransomware alert just popped up. Here's exactly what to do in the first 60 minutes to limit damage, preserve evidence, and protect your Texas business.
The Phone Call Every Owner Dreads
It's 7:40 on a Tuesday morning. Your office manager in Round Rock calls and says the shared drive won't open, and there's a text file on the desktop nobody recognizes. Maybe it says something about your files being "locked" and a countdown timer. Maybe someone in accounting already clicked a link they shouldn't have. Either way, your stomach drops, and the next sixty minutes matter more than almost any other hour in your company's history.
Most owners freeze right here. They either do nothing and hope it goes away, or they panic and start shutting things down randomly, which can destroy the very evidence you need later. Neither works. What follows is the sequence we walk clients through when they call, and it's built around one goal: stop the bleeding without erasing the crime scene.
Minute 0-5: Confirm and Isolate, Don't Investigate Yet
Your first job is not to figure out what happened. It's to stop it from spreading. Ransomware moves through a network fast, often hopping from one machine to file shares to backup targets within minutes.
- Pull the network cable or disable Wi-Fi on the affected machine. Don't power it off yet, memory sometimes holds clues.
- If multiple machines look affected, disconnect the switch uplink or disable the affected VLAN if you know how. If you don't, call for help immediately rather than guessing.
- Tell staff to stop clicking anything and stop logging into shared systems until you say otherwise.
This is the moment where having a monitored network pays off. Continuous SOC and SIEM monitoring can catch lateral movement before a human even notices the ransom note, which is one reason we push so hard for it as part of cybersecurity services rather than treating it as optional add-on.
Minute 5-15: Call for Help, Not for Blame
This is not the hour to troubleshoot solo or to start pointing fingers at whoever clicked the email. Get your IT provider or internal team on the phone now. If you have an after-hours emergency response arrangement, use it, that's exactly what it's for.
If you don't already have a relationship with a firm that offers business-hours support with after-hours emergency response, this is a hard lesson in why that matters. Ransomware doesn't wait for 9 a.m.
While you're making calls, do not contact the attacker yet, and do not decide about paying a ransom under pressure. Sophos's 2026 State of Ransomware report found that 69% of victims did not pay, up from 65% the year before, and plenty of businesses recover fully without ever sending money. Paying doesn't guarantee a working decryption key, and it paints a target on your back for future attacks.
Minute 15-30: Preserve Evidence, Don't Wipe It
The instinct to reformat the infected machine immediately is understandable and wrong. You need forensic evidence to understand scope, notify insurers, and in Texas, potentially demonstrate compliance for legal protection.
- Take photos of ransom notes and error screens with your phone.
- Note the exact time you first noticed the issue and who reported it.
- Leave affected machines powered on but disconnected from the network unless a security professional tells you otherwise.
- Do not run antivirus scans or "cleanup" tools yet, they can overwrite evidence needed to determine the ransomware family and entry point.
If your business carries cyber insurance, this is also the point to open a claim. Insurers often have specific forensic firms they require you to use, and calling them late can complicate coverage.
Minute 30-45: Check Your Backups Before You Touch Anything Else
Now's the moment to verify, quietly and without connecting anything infected, whether your backups are intact and isolated from the compromised network. Immutable, offsite, or air-gapped backups are the difference between a bad afternoon and a bad year.
If your backup system is on the same domain or network segment as production, there's a real chance it's already been touched too. This is exactly the scenario that cloud services architecture with segmented, versioned backups is designed to prevent. If you're not sure whether yours are protected this way, that's a conversation to have with your provider today, not after the next incident.
Minute 45-60: Loop In Leadership and Start the Paper Trail
By now you should have isolated the affected systems, called your IT and security team, preserved evidence, and checked backup status. The last stretch of the hour is about coordination.
- Notify company leadership and, if you have one, legal counsel. Texas businesses in regulated industries need to think about breach notification obligations early, not after the dust settles.
- If you handle health data, HIPAA notification timelines start ticking the moment you have evidence of a breach, see our HIPAA compliance guidance for specifics.
- If you handle financial data under FTC rules, similar urgency applies. Our FTC Safeguards Rule overview covers what counts as a reportable event.
- Start a simple incident log: time, action taken, who did it. This becomes invaluable for insurance, legal, and post-incident review.
One more thing worth knowing if you're a small or mid-sized Texas employer: SB 2610, effective September 2025, shields businesses with 20 to 99 employees from exemplary damages in a breach lawsuit if you've implemented the CIS Controls IG1 baseline (56 safeguards) before the incident. It doesn't create a new right to sue, and it only blocks exemplary damages, but it's a real incentive to have that baseline in place before you're in this exact situation, not after.
What Happens After the First Hour
The first hour is about containment and preservation. Hours two through twenty-four are about scoping the damage, engaging forensic specialists if needed, and deciding on a recovery path. Credential abuse shows up in a huge share of breaches, Verizon's 2026 DBIR puts it at 39% as the single most common thread, so part of your recovery plan has to include forcing password resets and reviewing privileged accounts, not just restoring files.
This is also where privileged access management earns its keep. If every account has broad admin rights, ransomware spreads faster and recovery takes longer because you have more to check and reset.
Recovery costs add up fast even without paying a ransom. Sophos's 2026 data puts the median recovery cost at $375,000, with a mean closer to $1.7 million once you count the long-tail cases with extended downtime or extensive rebuild work. That's why containment speed in the first hour matters so much, every extra machine that gets encrypted adds to that bill.
Building the Muscle Memory Before You Need It
Here's the uncomfortable truth: most businesses that handle the first hour well aren't smarter, they've just practiced. They have a written incident response plan, they know who to call, and their team has run through a tabletop exercise at least once. If your business doesn't have that yet, now is the time, not during an active incident.
Whether your current setup includes proper network segmentation, monitored endpoints, and tested backups is worth a hard look. A lot of the businesses we bring on through our switching IT providers process discover gaps they didn't know existed, usually around backup isolation and privileged accounts. If you're in Houston, The Woodlands, Sugar Land, or Katy and want a clear-eyed look at where you stand, our managed IT services team can walk through it with you before an attacker does it for you.
Frequently Asked Questions
Should I turn off the infected computer immediately?
Disconnect it from the network first by pulling the cable or disabling Wi-Fi. Don't power it off unless a security professional advises it, since some evidence lives in memory and disappears on shutdown.
Should we pay the ransom if we don't have backups?
Not as a first move. Get a professional assessment of what's actually encrypted and whether decryption tools exist for that ransomware family before considering payment. A majority of victims recover without paying.
Who do we legally have to notify after a ransomware attack in Texas?
It depends on what data was affected. Health information triggers HIPAA timelines, financial data triggers FTC Safeguards Rule obligations, and general breach notification law may apply depending on the number of Texas residents affected. Legal counsel should confirm specifics for your situation.
How fast does ransomware actually spread through a network?
It varies by strain, but lateral movement within minutes to a few hours is common once initial access is gained. That's why isolating affected systems in the first five minutes matters so much.
Does having good security controls actually reduce our legal risk in Texas?
Under SB 2610, businesses with 20 to 99 employees that have implemented the CIS Controls IG1 baseline before an incident are shielded from exemplary damages in a breach lawsuit. It's not blanket immunity, but it's a meaningful protection tied directly to having controls in place beforehand.
If you don't already have a written incident response plan and tested, isolated backups, don't wait for the ransom note to find out where the gaps are. Request a free IT assessment and get a clear picture of where your business actually stands.
Need Help With Cybersecurity?
LayerLogix provides expert cybersecurity solutions for businesses across Houston and nationwide.
Related Articles
Need Expert IT Support?
Let our team help your Houston business with enterprise-grade IT services and cybersecurity solutions.