Operational cyber readiness for SMEs

Under attack?

Ransomware

Ransomware: what to do in the first hours without making it worse

A guide for SMEs on isolation, internal communication, evidence capture and the decisions that must be made immediately when ransomware appears.

Team PresidioSec

Incident response and cyber resilience for SMEs

2026-04-03

First rule: do not rush in disorder

The first mistake during ransomware is confusing speed with chaos. Shutting down machines blindly, writing in uncontrolled chats or involving too many people too early can make the situation worse.

For an SME the priority is not to do everything, but to establish minimum coordination: who decides, who speaks, who captures evidence, who contacts the IT provider and who tracks business impact.

The four decisions that change the outcome

Isolation: decide quickly whether to disconnect endpoints, servers, VPN or shared services. Communication: centralize one controlled channel. Evidence: preserve screenshots, timelines and affected systems. Continuity: identify what must resume first.

These decisions are not purely technical. They affect production, customers, contracts, GDPR and reputation. That is why the playbook must be readable by leadership and operations, not only by IT.

Sources

Related reads

Next step

If you want to bring this method into your company, talk to us.

Go to contact