A ransomware attack can turn a normal workday into a business emergency in minutes.

One employee clicks the wrong attachment, a compromised account gives an attacker access to the network, or someone discovers that important company files suddenly won’t open. Then the ransom message appears.

For Canadian small businesses, this isn’t a far-fetched scenario. According to a 2024 KPMG Canada survey of 735 small and medium-sized business leaders, 72% said their organization had experienced a cyberattack in the previous year, compared with 63% the year before.

While you can’t predict exactly when an attack will happen, you can control how your organization responds. The actions taken during the first hour can affect how far ransomware spreads, how much data is compromised and how quickly your business can begin recovering.

If you suspect you’ve been hit, the priority isn’t to immediately get every system running again. It’s to contain the attack, protect evidence, understand what has been affected and determine the safest path toward recovery.

Here is what Canadian businesses should do during those critical first 60 minutes.

How to Recognize the Signs You’ve Been Hit

Not every ransomware attack begins with a dramatic message demanding cryptocurrency. Some warning signs appear before the ransom note does.

The most obvious sign is suddenly being unable to open files that worked normally moments earlier. Files may have unfamiliar extensions, folders may contain strange new files, or documents may appear corrupted or encrypted.

In many cases, attackers also leave a ransom note explaining that the organization’s data has been encrypted and demanding payment for its release.

Other warning signs can be easier to overlook, including:

  • Computers or applications suddenly running unusually slowly
  • Antivirus or endpoint security software being disabled
  • Unexpected password or account changes
  • Suspicious login alerts
  • Unusual network activity
  • Employees being locked out of accounts
  • Files being renamed or modified without explanation
  • Multiple systems experiencing similar problems at the same time

Speed matters. Ransomware can spread beyond the first compromised computer to connected workstations, shared drives and servers.

Attackers may also attempt to reach backup infrastructure.

The sooner your organization recognizes the warning signs and begins its ransomware attack response, the better the opportunity to contain the incident.

Ransomware Attack Response: What to Do

When an attack is underway, it’s easy to focus entirely on getting files back. That’s important, but recovery comes later.

The first hour should be about containment, communication, documentation, and understanding what recovery options are available.

Step 1: Isolate, Don’t Panic

Your first priority is stopping the suspected ransomware from reaching additional systems.

Disconnect affected computers from the network immediately. Unplug their Ethernet cables and disable Wi-Fi and Bluetooth connections where appropriate. If other devices or servers appear to be compromised, isolate them as well.

Unless your IT or cybersecurity team instructs you otherwise, avoid immediately shutting down the affected computer. Keeping the system in its current state may preserve volatile information that could help cybersecurity professionals determine what happened.

Don’t start randomly unplugging or restarting every system in the company either. Your IT team needs to determine which systems are affected and which can be safely isolated.

This is where preparation becomes extremely valuable. Employees should already know who has the authority to isolate systems and who needs to be contacted when suspicious activity occurs.

A few minutes spent wondering, “Who handles this?” can give an active threat more time to spread.

Step 2: Don’t Pay the Ransom (Yet)

Seeing a ransom demand creates enormous pressure to act quickly, particularly when employees can’t access the systems they need to work.

Don’t immediately pay.

Paying a ransom does not guarantee that attackers will provide a working decryption key, that every file will be restored, or that stolen data will actually be deleted. Even if systems are decrypted, the underlying vulnerability that allowed attackers inside may still exist.

There may also be legal, regulatory, cybersecurity insurance, and law enforcement considerations surrounding a payment.

This doesn’t mean a business owner has to make a permanent decision about the ransom within the first hour. Quite the opposite.

The decision should be made later, after consulting the appropriate cybersecurity, legal, and insurance professionals and gaining a clearer picture of the incident.

During the initial ransomware incident response, concentrate on containment and assessment rather than negotiating with the attacker.

Step 3: Activate Your Incident Response Plan

If your company already has a ransomware incident response plan, now is the time to use it.

Your first technical call should generally be to the IT department, managed service provider (MSP) or cybersecurity provider responsible for your systems. This isn’t the moment to rely on whichever employee happens to know the most about computers.

Your response plan should establish exactly who needs to be contacted and in what order.

Leadership should also be informed so business decisions can be coordinated. Depending on the nature of the incident, legal counsel, your cyber insurance provider and other specialists may need to become involved.

Canadian organizations can also report cyber incidents to the Canadian Centre for Cyber Security. Reporting an incident can help connect organizations with appropriate guidance while contributing to a better understanding of threats affecting Canadian businesses.

The middle of a ransomware attack is a terrible time to create an incident response plan from scratch.

Before an attack occurs, businesses should know who is responsible for making decisions, how employees will communicate if normal systems are unavailable, where emergency contact information is stored, and what steps should be followed to contain an incident.

Canadian Cloud Backup can help businesses assess disaster recovery readiness before those plans are put to the test.

Step 4: Preserve Evidence for Investigation

Your instinct may be to delete suspicious files, wipe the infected computer, or immediately reinstall everything.

Don’t.

Before making major changes, preserve as much information about the incident as possible.

Take a screenshot or photo of the ransom note. Record the exact wording, payment instructions, and any contact information it contains.

Write down when the problem was first noticed, which employee discovered it, and what they were doing beforehand. Document affected devices, unusual login alerts, and any other suspicious behaviour your team noticed.

If possible, create a basic timeline:

  • 8:42 a.m.: Employee reports being unable to open shared files.
  • 8:47 a.m.: Ransom note appears.
  • 8:50 a.m.: Workstation disconnected from the network.
  • 8:55 a.m.: IT provider contacted.

Those details can become extremely useful during the investigation.

Avoid deleting logs, wiping computers, or restoring systems until your technical team has determined what evidence needs to be preserved. Understanding how the attacker entered the environment is important for preventing the same vulnerability from being exploited again.

Step 5: Assess What’s Backed Up

This is the moment when your backup strategy either becomes one of your greatest assets or exposes a serious weakness.

Don’t immediately connect backup drives or begin restoring data. First, your IT or disaster recovery team needs to establish whether the attack has been contained and whether your backups are safe.

Start with three important questions:

Are the backups immutable?

Immutable backups are designed so stored data cannot be altered or deleted during a defined retention period. This provides an important layer of protection when ransomware attempts to encrypt or destroy accessible backup copies.

Are the backups isolated from the production network?

If your only backup is continuously accessible from the same environment that was compromised, ransomware or an attacker may be able to reach it too. Offsite and appropriately isolated backup infrastructure reduces this risk.

When was the last known clean restore point?

Having backups isn’t enough. You need to know when the last successful backup occurred and whether it was created before the compromise.

For example, yesterday’s backup isn’t necessarily useful if the attacker had already been inside the environment for several days.

This is why data backup and ransomware protection need to go beyond copying files to another drive.

A strong strategy combines multiple layers of protection, including offsite storage, immutable backups, appropriate access controls and regular recovery testing.

Immutable backups can provide a protected recovery point even when ransomware has damaged production systems. Instead of depending on an attacker for access to encrypted information, your organization may be able to restore clean copies of its data once the environment is safe.

For a business facing a ransomware incident, that can make a significant difference in the speed and predictability of recovery.

Step 6: Loop in Your Legal & Compliance Obligations

A ransomware incident isn’t only an IT problem, it can also become a privacy and regulatory issue.

Under Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), organizations subject to the legislation have obligations related to breaches of security safeguards involving personal information.

If a breach creates a “real risk of significant harm” to an individual, the organization must report the breach to the Office of the Privacy Commissioner of Canada and notify affected individuals. Organizations must also maintain records of breaches of security safeguards in accordance with PIPEDA requirements.

Whether a particular ransomware incident triggers notification requirements depends on what information was involved and the circumstances surrounding the breach.

Remember that ransomware doesn’t necessarily mean attackers only encrypted your files. Modern ransomware incidents can involve data theft before encryption, which means customer, employee or other sensitive information may have been exposed.

Your legal and cybersecurity teams should help determine:

  • What data may have been accessed
  • Whether personal information was involved
  • Whether information was exfiltrated
  • Which privacy laws or industry regulations apply
  • Whether regulators must be notified
  • Whether customers, employees or other affected individuals need to be contacted

Avoid making assumptions about whether information was stolen simply because the ransom note only mentions encryption.

How Canadian Businesses Can Prepare Before an Attack Happens

The best ransomware recovery in Canada begins before ransomware reaches your network.

You don’t want to discover during an attack that your backups haven’t completed successfully in three months, your emergency contacts are stored on an inaccessible server, or your only backup was encrypted along with everything else.

Preparation starts with building recovery into your normal cybersecurity strategy.

Use immutable and isolated backups.

Your recovery copies shouldn’t be as easy for an attacker to modify as your production data. Immutable backup technology helps protect recovery points from alteration or deletion, while offsite and appropriately isolated storage provides another layer between ransomware and your backup data.

Test your backups regularly.

A dashboard showing “backup successful” isn’t the same thing as successfully restoring a business-critical application. Organizations should regularly test restoration procedures to verify that their data can actually be recovered.

Know your recovery priorities.

Not every system needs to return online simultaneously. Identify the applications, servers, and data your business needs first. Your disaster recovery plan should establish the order in which critical systems will be restored.

Create and rehearse an incident response plan.

Employees should know how to report suspicious activity, while leadership and IT teams should understand their responsibilities during an incident. Periodic tabletop exercises can reveal gaps before an actual emergency.

Consider Canadian data sovereignty. For organizations with regulatory, contractual, or data-residency requirements, knowing where backup information is physically stored matters. A Canadian-hosted backup strategy can help businesses maintain greater clarity over where their data resides while working within the Canadian regulatory environment.

Work with a partner that understands Canadian businesses. Cybersecurity and disaster recovery aren’t only technical issues. Canadian organizations operate within specific privacy, compliance and data sovereignty considerations. Working with a Canadian provider means those requirements can be incorporated into the backup and recovery strategy from the beginning.

For a small business ransomware attack, preparation can be particularly important. Smaller organizations may not have dedicated cybersecurity teams available around the clock. A well-designed backup and disaster recovery plan provides a clear path forward when internal resources are limited.

Prepare for the First Hour Before It Happens

The first hour after a ransomware attack is the most crucial time to make the right early decisions.

Isolate affected systems. Don’t rush into paying the ransom. Contact your IT and cybersecurity professionals. Preserve evidence. Determine whether your backups are clean and recoverable. Bring in legal and compliance expertise when personal or sensitive information may have been compromised.

Most importantly, don’t wait for an attack to find out whether your recovery plan works.

Canadian Cloud Backup provides backup and Disaster Recovery as a Service (DRaaS) solutions designed to help Canadian businesses protect critical information and recover when the unexpected happens.

With the right backup architecture, tested recovery procedures and an incident response plan already in place, ransomware doesn’t have to become a business-ending event.

Don’t wait for the first hour to test your plan. Contact Canadian Cloud Backup about disaster recovery solutions built for Canadian businesses.

Send a Message