Guides & Blog · 2026-07-06 · eWEB TEC
Ransomware for a 10-Person Sydney Office: First 24 Hours
In the first 24 hours after ransomware, focus on containment, communication, clean recovery and identity — not heroic experiments on infected machines. For a small Northern Beaches or North Shore office, speed and calm process beat panic reinstalls.
Hour 0–1: contain
- Isolate affected PCs from Wi-Fi and LAN if safe to do so
- Preserve one untouched encrypted sample if possible (for insurers/forensics)
- Disable risky remote access until passwords and MFA are reviewed
- Call your IT provider — do not run random decryptor tools from ads
Hour 1–4: establish facts
- What is encrypted (files, servers, M365)?
- Which accounts signed in unusually?
- Are backups offline or immutable, or also hit?
- Who needs to know (owners, staff, key clients if services are down)?
Hour 4–24: recover and harden
- Restore from known-good backups after malware is cleared from restore path
- Reset credentials; prioritise admin and email
- Review MFA, app passwords, OAuth grants on Microsoft 365
- Document timeline for insurance
Related: Microsoft 365 backup, DR one-pager, managed IT.
FAQ
Should we pay the ransom?
That is a legal, insurance and leadership decision. Technical priority is contain, assess backups, and restore cleanly — do not assume payment restores trust.
Is turning everything off correct?
Containment matters, but random power-offs can destroy forensic evidence and shared services. Use a short decision tree with your IT provider.
How do we reduce odds next time?
MFA, least privilege, tested M365 and file backups, patching, and phishing-resistant habits.
Related service: view this service page · contact eWEB TEC.
Need help containing or recovering?