Flyght
← Back to Blog
Cybersecurity

What to Do If Your Toledo Business Gets Hit by Ransomware (Hour-by-Hour Guide)

Flyght TeamMay 3, 202610 min read

You come in on a Tuesday morning. Screens show a ransom note. Files won't open. Your business is locked.

Ohio businesses saw a 40%+ increase in SMB ransomware incidents over the past two years, according to the FBI's Internet Crime Complaint Center (IC3). Toledo and NW Ohio have not been spared — manufacturers, medical practices, law firms, and small businesses of every kind have been hit. And unlike large enterprises with full security teams on staff, small and mid-sized businesses rarely have a practiced incident response plan ready to go.

What you do in the first hours determines whether you recover in days or weeks. Every decision — who you call, whether you pay, how you handle your backups — carries real consequences. This guide walks you through it, phase by phase, so you're making the right calls under pressure.

Hour 0: The Moment You Discover It

The worst thing you can do is panic and start clicking around. The second worst is doing nothing while the malware spreads.

Disconnect from the network immediately. Pull the ethernet cable. Disable Wi-Fi on affected machines. If you're unsure which systems are infected, shut down your network switch entirely. Ransomware spreads laterally at machine speed — every minute of connectivity means more encrypted files.

Do not turn off the infected computers yet. Powering down can destroy forensic evidence and, in some variants, prevent decryption even if you later obtain a valid key. Leave them on but isolated.

Do not pay the ransom yet. You need more information first. Alert your team: stop working, stay off computers, don't open anything unusual.

Hours 1–4: The Critical Calls

Call your IT provider first. An experienced MSP can begin forensic triage, assess the scope, and activate your recovery plan. No IT provider? Call a cybersecurity incident response firm.

Call your cyber insurance carrier second. Most policies require notification before you authorize any payments or engage outside responders. Failing to follow that process can jeopardize your coverage. Have your policy number ready.

Contact the FBI's IC3 at ic3.gov. Federal agencies track ransomware groups and sometimes have decryption keys recovered from prior law enforcement operations — you may recover data without paying anything.

Notify legal counsel. If your business handles customer or employee data, you may have notification obligations under Ohio's breach law. An attorney familiar with data breach requirements will know the timelines and thresholds. Hold off on any public statements until you understand the full scope.

Hours 4–24: Assessment and Evidence Preservation

Do not wipe or reimage machines before forensic images are captured. Your IT team should document affected systems, collect firewall and endpoint logs, and preserve the ransomware artifacts — malware files, the ransom note, indicators of compromise. This evidence is required for insurance claims and understanding how attackers got in.

Assess your backups — this single factor determines everything else. Are they recent, intact, and stored separately from your primary network? Many ransomware variants specifically target backup systems before detonating. Clean, tested, offsite backups mean recovery is measured in hours to days. Compromised backups mean your options narrow significantly.

Identify the ransomware variant. Your IT provider can often determine the strain from the ransom note format and file extensions. Some variants have been cracked — free decryption tools are available at nomoreransom.org. Check before paying anything. Document all actions, costs, and decisions for your insurance claim.

Should You Pay the Ransom? (The Honest Answer)

The FBI's official position is: don't pay. Paying funds criminal operations, marks you as a willing target, and about 20% of businesses that pay never receive working decryption keys.

That said, the calculus changes when backups are gone and data is irreplaceable. If you're considering payment: your cyber insurance carrier must be involved first. Carriers have negotiation specialists who routinely reduce demands by 50–80%. Never wire funds yourself outside your carrier's process.

Before agreeing to anything, confirm the ransomware group is not OFAC-sanctioned — paying a sanctioned entity may be a federal crime regardless of circumstances.

Bottom line: if your backups are intact, restore from backup. If not, consult your carrier, legal counsel, and IT team before deciding anything.

Day 2–7: Recovery Timelines

Recovery depends almost entirely on backup integrity.

With clean, recent backups: systems are typically restored within 24–72 hours. Your IT team rebuilds from clean images, restores data, verifies integrity, and brings systems online in priority order.

With partial or older backups: expect one to two weeks, with some data permanently lost.

With no usable backups: if decryption works after paying, the process alone takes a week or more. Rebuilding from scratch for a mid-sized business takes two to four weeks.

Cybersecurity firms report the average ransomware recovery time for SMBs is 21 days. Businesses with tested backup and disaster recovery plans recover in a fraction of that. Don't rush recovery — restoring infected systems before identifying the attack vector means potential re-infection within hours.

Reporting Requirements: FBI, CISA, and Ohio Law

Beyond the initial FBI IC3 report, additional filings may apply.

CISA: If you operate in critical infrastructure — healthcare, manufacturing, financial services — report the incident at cisa.gov/report. CISA uses this data to warn other businesses.

Ohio Data Breach Notification Law: Ransomware attackers routinely exfiltrate data before encrypting it. If personal information of Ohio residents was exposed, state law requires notification to affected individuals and potentially the Attorney General. Your attorney will know the specific timelines.

Sector-specific rules: HIPAA-covered entities have a 60-day HHS notification deadline. PCI-DSS compliance requires notifying your card processor. Keep documentation of every step — regulators want evidence of an appropriate response.

The Flyght IT Difference: 24/7 Monitoring That Stops Ransomware Before It Spreads

Most ransomware attacks aren't discovered at the moment of infection. The average dwell time — the gap between initial compromise and ransom deployment — is 9 to 21 days. During that window, attackers map your environment, locate your backups, and position for maximum damage.

Flyght's managed detection and response (MDR) service monitors your environment around the clock. Our security operations center watches for the behavioral patterns that precede detonation: unusual lateral movement, privilege escalation, mass file access, backup deletion. When we detect these at 2 AM on a Sunday, we don't send an email alert — we isolate the affected system automatically and respond immediately.

The difference between containing an intrusion at one endpoint versus a full-network encryption event is measured in minutes. That's what 24/7 monitoring actually means in practice.

After Recovery: Making Sure It Never Happens Again

Businesses that restore and move on without addressing root cause are attacked again — often by the same group, who sell your credentials on the dark web.

Conduct a post-incident review. Identify the initial access vector definitively before closing the incident. Common entry points: phishing emails, exposed RDP, unpatched vulnerabilities, compromised credentials.

Rebuild your backup architecture using the 3-2-1 rule: three copies of data, on two media types, with one copy offsite or in immutable cloud storage. Test restores regularly — don't assume they work.

Implement what was missing: MFA on every account, EDR on every device, critical patches applied within 72 hours, least-privilege access controls, and network segmentation to contain any future blast radius. Run ongoing security awareness training so employees can spot phishing before it becomes your next incident.

Print our free Ransomware Incident Response Checklist — a 10-page hour-by-hour playbook with isolation steps, who to call, evidence preservation, backup assessment, and Ohio reporting requirements. Keep a copy offline before you need it.

View Our Services

Don't Wait for an Attack — Get a Free Security Gap Assessment

If your Toledo business doesn't have 24/7 monitoring, tested backups, and a documented incident response plan, you're not ready for a ransomware attack. With Ohio SMB incidents up 40%+, the question isn't whether businesses like yours are targeted — it's whether yours will be ready.

Flyght offers a free security gap assessment for businesses in Toledo and across NW Ohio. No jargon, no scare tactics — just a straight conversation about what it would take to protect what you've built.

Ready to talk?

If this article hit close to home, let's have a conversation. No pitch, no pressure — just an honest look at where your IT stands today.

Get Your Free IT Assessment