Ransomware is now the most common and most damaging cyber threat facing Canadian small and mid-size businesses. According to the Canadian Centre for Cyber Security, ransomware attacks on Canadian organizations increased significantly year-over-year, with SMBs increasingly targeted because they're seen as having weaker defences than enterprises.
The average ransomware recovery for a small business costs $200,000–$500,000 when you account for downtime, data recovery, security remediation, and reputational impact — whether or not a ransom is paid. Many businesses never fully recover.
What happens in the first 72 hours determines whether you're looking at a bad week or a catastrophic business disruption. This guide covers the response.
Hour 1: Contain, Don't Panic
The moment you suspect ransomware — encrypted files, ransom note on your desktop, systems behaving abnormally — your first priority is containment, not recovery.
Disconnect affected systems from the network immediately. Pull the ethernet cable or disable Wi-Fi. Do not shut the system down — you may destroy forensic evidence. Disconnection prevents the ransomware from spreading to other systems and from communicating with the attacker's command-and-control servers.
Do not pay the ransom yet. This sounds counterintuitive when your business is down, but paying immediately eliminates your negotiating leverage, doesn't guarantee data return, and may violate OFAC sanctions if the ransomware group is on a Canadian or US sanctions list. The payment decision can wait 24–48 hours while you assess the situation.
Alert your IT team or MSP immediately. If you have an IT provider, call them now — not by email (email may be compromised). They need to know what's happening so they can begin incident response.
Preserve evidence. Take photos of ransom notes on screens. Do not interact with encrypted files. If possible, capture any unusual network activity in your firewall or router logs before systems are shut down.
Alert your team. Employees need to know not to open suspicious emails or click unfamiliar links until the situation is assessed. The initial infection may still be spreading via phishing.
Hours 2–8: Assess the Scope
Once immediate containment is done, the next priority is understanding what happened and what's affected.
Identify affected systems. Which computers, servers, and network shares have encrypted files? Is the backup system affected? Was the domain controller compromised? The answers determine your recovery path.
Check your backups — carefully. This is the critical question. Do you have clean, recent backups that are not infected? Ransomware specifically targets backup systems; if your backups were connected to the infected network, they may be compromised or encrypted too.
Look for:
- Offline backups (external drives disconnected from the network)
- Cloud backups with versioning (can you restore to a point before infection?)
- Immutable backup snapshots (some backup systems maintain read-only snapshots that ransomware cannot encrypt)
If you have clean backups, your recovery path is straightforward: rebuild affected systems and restore. If backups are compromised, you're facing more complex options.
Identify the ransomware variant. The ransom note, file extension on encrypted files, and the behavior you observed can identify the specific ransomware family. This matters because:
- Some older ransomware variants have free decryptors available (check nomoreransom.org)
- The variant may indicate whether paying is likely to result in actual decryption
- Some variants are known to be associated with sanctioned entities, making payment illegal
Engage a forensics firm if the attack is significant. For attacks affecting more than a handful of systems or involving sensitive data, engaging a cybersecurity incident response firm in the first few hours is worth the cost. They can identify the attack vector, scope the breach properly, and provide expert guidance on the payment question.
In Canada, firms like Beazley, Coveware, and Mandiant (Google) have dedicated ransomware response teams. Your cyber insurance policy may require you to use their approved vendors.
Hours 8–24: Notify and Decide
Notify your cyber insurance carrier. If you have cyber insurance — and you should — call your carrier immediately. Many policies have time-limited reporting requirements. Your insurer may provide incident response resources, cover ransom payments, and cover business interruption costs.
Assess your legal notification obligations. If personal information was accessed (not just encrypted), you may have breach notification obligations under PIPEDA or provincial privacy legislation. In Canada, PIPEDA requires notification of "real risk of significant harm" breaches to the Privacy Commissioner and affected individuals. Engage legal counsel to assess your obligations quickly — notification requirements are time-sensitive.
The payment question. If you don't have usable backups, you're evaluating whether to pay. The considerations:
Arguments for paying: If legitimate backups don't exist and data is critical for business continuity, paying may be the fastest path to recovery. Many major ransomware groups (LockBit, BlackCat, etc.) do provide working decryptors after payment because their business model depends on it.
Arguments against paying: Payment doesn't guarantee recovery. Files may not decrypt fully. Some groups exfiltrated data before encrypting and will demand additional payment. Payment funds criminal operations and marks your organization as one willing to pay, potentially inviting future attacks. Some payment recipients are on sanctions lists, making payment a legal violation regardless of circumstances.
The practical reality: Most businesses without backups who need to recover quickly and have cyber insurance coverage do pay. Negotiate through a professional incident response firm — ransoms are frequently negotiated down 40–70% from initial demand.
Sanctions check. Before any payment, verify the ransomware group is not on the OFAC SDN list or Canadian sanctions lists. Your incident response firm can advise on this. Paying sanctioned entities can result in criminal penalties regardless of whether you were victimized.
Hours 24–72: Recovery
The recovery path depends on what you've determined about backups and whether payment is being made.
If clean backups exist:
- Rebuild or reimage affected systems (don't clean ransomware from infected systems — rebuild from scratch)
- Close the attack vector before restoring (if ransomware entered through a phishing email, through an RDP port, or through compromised credentials, fix it first or you'll be reinfected immediately)
- Restore from backups in chronological order, starting with the most critical systems
- Test restored systems before bringing them back to production
- Monitor closely for 30+ days — some ransomware has dormant components that activate later
If no clean backups and decryptor received:
- Obtain decryptor through your incident response firm
- Test decryptor on non-critical systems first before running on production data
- Document the decryption process — it sometimes fails on specific file types
- Rebuild systems alongside decryption rather than restoring to infected OS
- Assume some data loss — decryptors don't always recover 100% of files
Regardless of recovery path:
Close the attack vector. You cannot reconnect recovered systems to the network until you know how the attacker got in and have closed that path. Common vectors: phishing email leading to credential theft, internet-exposed RDP (Remote Desktop Protocol), unpatched vulnerabilities in internet-facing systems, compromised MSP supply chain.
Reset all credentials. All passwords, all service accounts, all API keys. Assume everything is compromised until proven otherwise.
Engage forensics for root cause. Understanding exactly how the attack happened is essential for preventing recurrence. This requires forensic investigation of available logs, network traffic, and endpoint data.
Preventing the Next Attack
After you've recovered, the work of not being here again begins. The most impactful controls:
Immutable backups. The single most important ransomware defense is backups that ransomware cannot encrypt. This means offline backups (physically disconnected), cloud backups with point-in-time versioning and protection from deletion, or hardware/software solutions that create immutable snapshots.
Multi-factor authentication, everywhere. The majority of ransomware attacks exploit stolen credentials. MFA on all remote access, all cloud services, and all administrative accounts eliminates the credential-theft attack vector.
Privileged access controls. Ransomware spreads because employee accounts have write access to network shares they shouldn't need. Implementing least-privilege access — employees can only access the data they actually need — contains the blast radius of any single compromised account.
Endpoint detection and response (EDR). Modern EDR tools (Microsoft Defender for Business, CrowdStrike, SentinelOne) detect ransomware behavior in early stages and can stop encryption before it spreads. This is meaningfully different from traditional antivirus.
Security awareness training. Most ransomware arrives via phishing email. Training employees to recognize phishing — and running regular simulated phishing campaigns — reduces the probability of initial infection.
Incident response planning. The worst time to figure out your ransomware response is when ransomware is encrypting your files. A documented incident response plan with clear roles, contact numbers, and decision trees means the first hour goes to containment rather than to figuring out what to do.
Cleva IT helps Alberta businesses build the preventive security controls that make ransomware attacks less likely and less damaging — and helps clients navigate recovery when attacks occur. If you'd like to assess your current ransomware exposure, a conversation about your backup strategy, MFA implementation, and endpoint protection is a useful starting point.