How Should a Small Business Respond to a Ransomware Attack? A Step-by-Step Guide

Isolate infected systems immediately, do not pay the ransom without legal counsel, notify your incident response team or MSP, preserve forensic evidence, and report to the FBI's IC3. Recovery priority depends on whether verified, tested backups exist. Full containment typically takes 24-72 hours for SMBs with basic preparation.

Should a small business pay a ransomware demand?

The FBI and CISA advise against paying without law enforcement consultation. Payment does not guarantee decryption, may violate OFAC sanctions if the attacker is a designated entity, and can encourage repeat targeting. Legal counsel should be engaged before any payment decision. If backups exist and are clean, payment is rarely necessary.

How long does ransomware recovery take for a small business?

Recovery timelines range from 24 hours (small scope, clean backups, fast response) to 3-4 weeks (widespread encryption, compromised backups, no IR plan). The 2022 Sophos State of Ransomware report found the average recovery time for SMBs was one week, with organizations that had tested backups recovering roughly 50% faster than those without.

Does ransomware trigger data breach notification requirements?

In most cases, yes. Modern ransomware groups routinely exfiltrate data before encrypting it. Because you typically cannot prove data was not accessed, most state attorneys general treat ransomware as a presumptive data breach triggering notification obligations. All 50 U.S. states have breach notification laws with timelines ranging from 30 to 90 days.

How does a ransomware attack affect a SOC 2 audit?

A ransomware incident is reviewed under SOC 2 common criteria CC7.3, CC7.4, and CC7.5, which address incident detection, response, and recovery. An undocumented or unstructured response - even one that succeeded technically - can result in audit findings. Organizations must produce an incident log, documented containment actions, root cause analysis, and evidence of corrective controls.

What is double extortion ransomware and how should SMBs respond to it?

Double extortion ransomware involves attackers both encrypting your data and threatening to publish it publicly if the ransom is not paid. This makes clean backups alone insufficient as a response strategy, since the data exposure threat persists. Response requires engaging legal counsel immediately, assessing what data was accessible, and evaluating notification obligations regardless of whether you restore from backup.

What cyber insurance does a small business need for ransomware coverage?

A standalone cyber liability policy or a technology errors and omissions (Tech E&O) policy with cyber coverage is needed. Coverage should include ransomware extortion payments, business interruption, forensic investigation, legal counsel, and notification costs. Most insurers now require MFA on email, remote access, and privileged accounts as a baseline underwriting requirement before issuing a policy.

How can a small business prevent ransomware before an attack occurs?

The highest-impact preventive controls are: multi-factor authentication on all remote access and email, immutable offsite backups tested monthly, endpoint detection and response (EDR) on all devices, patching of internet-facing systems within 14 days of release, and security awareness training. CISA's free Ransomware Readiness Assessment (RRA) tool provides a structured gap analysis for SMBs at no cost.