Let me start with a belief I want you to question.
Most business owners walk around with a quiet assumption in their heads:
"Cybersecurity means not getting hacked."
It sounds obvious. It sounds responsible. It sounds like the kind of thing you'd nod along to in a board meeting.It's also one of the most expensive rules you've ever accepted without examining it.
Because here's what actually happens in the real world: the businesses that get destroyed by ransomware and the businesses that shrug it off six weeks later are not separated by who had the better firewall.
They're separated by who had already made decisions.
Let me show you what I mean.
"Prevention is only Half the plan. Strong security can reduce your risk, but no defense is perfect. The businesses that survive ransomware are the ones prepared to respond when prevention fails."
The Story We Tell Ourselves About Ransomware
Ask ten people to describe a ransomware attack and you'll get roughly the same movie.
Files get encrypted. A skull appears on a monitor. Somebody demands Bitcoin. That version is clean. Dramatic. Kind of cinematic. It's also almost entirely useless, because it describes the event and completely ignores the experience.
The ransom note isn't the crisis.
The crisis is the ninety-six hours that follow it, when your employees can't work, your customers can't get answers, your accounting team can't touch a single record, and you are making the largest decisions of your professional life with almost no information.
So let's stop explaining the technology. Let's walk through the hour, the day, and the week — the way you'd actually live them.
Hour One: "Something Isn't Right"
It rarely announces itself.
It starts with somebody who can't open a file.
Then somebody says the shared drive is acting strange. Then a third person says the same thing. Applications stop responding. Files have extensions nobody recognizes. Maybe a message appears on a screen.
And here is the first moment where your model of reality decides your outcome.
Because the natural human instinct — the deeply reasonable, deeply understandable instinct — is to treat this like a normal IT hiccup.
The internet's being weird again. Somebody reboot something.
That instinct is the enemy.
If ransomware is actively moving through your environment, every connected machine, server, and system is a potential next victim. The clock isn't metaphorical. It's literal.
Your IT team has to determine what's happening and start containing it. That may mean disconnecting computers. Disabling accounts. Killing network connections. Isolating servers. Pulling systems offline entirely.
And to your staff, this will feel insane. "Why are you shutting everything down? We have work to do."
I want you to sit with that tension, because it's the whole lesson in miniature.
In hour one, productivity is not the goal. Containment is the goal.
In hour one, productivity is not the goal. Containment is the goal.
Every minute you spend protecting today's output, you may be spending next month's revenue. And there's a second question that has to get answered fast — one most leaders don't even know to ask:
Did they only lock your data, or did they take a copy first?
Modern attackers frequently do both. They encrypt, and they steal, and then they threaten to publish what they took. The moment that's true, you're not managing an outage anymore. You're managing a data breach.
Different clock. Different lawyers. Different consequences.
Day One: The Technical Problem Becomes a Business Problem
Picture yourself standing in front of your team saying: "Nobody use your computer until we tell you it's safe."
Now play the tape forward.
Can sales reach the CRM?
Can accounting send invoices?
Can anyone get to email?
Can customer service pull up a customer record?
Can you take a payment?
Can a single person do the job you're paying them to do?
Depending on what got hit, entire departments are now operating on paper — or not operating at all.
And then the questions start arriving from every direction at once. Employees want a timeline. Customers want an explanation. Leadership wants a damage assessment. Your insurance carrier needs to be notified. Legal counsel needs to be looped in. Forensic specialists need to start digging.
And every single one of them is asking the same thing: "When are we back online?"
Here's the uncomfortable truth: on day one, there usually isn't an answer. Not because your people are incompetent. Because nobody yet knows the shape of what happened.
"A Backup Is Only as Good as Its Recovery. Having backups doesn't guarantee you can restore your business. If they haven't been protected, tested, and timed, you won't know what they're worth until the worst possible moment."
And Then Someone Says the Word "Backups"
This is my favorite moment in the entire story, and I mean that with genuine affection, because this is the moment where all the preparation you did — or didn't do — becomes visible in about forty seconds.
"We have backups" is a comforting sentence.
It's also not the same sentence as "we can recover this business."
Watch what happens when you push on this idea:
Where are they stored?
Can the ransomware reach them?
When did the last one actually complete?
Has anyone ever restored from one?
How long would a full restore genuinely take — not in theory, in hours?
Are your cloud platforms backed up separately, or did you assume someone else was handling that?
And the big one: if the attackers got administrator credentials, could they have deleted or encrypted the backups on their way through?
An untested backup isn’t a safety net. It’s a hypothesis.
The middle of an active incident is a spectacularly bad time to run your first experiment.
Days Two and Three: Welcome to Decisions You've Never Made Before
Now two things are happening simultaneaously, and they’re pulling against each other.
Investigators are trying to figure out how the attackers got in, how long they were inside, what they touched, and whether they still have a way back.
Meanwhile, the business is desperate to restore.
See the conflict?
You want everything back now. But if you restore into an environment that's still compromised, you may simply be scheduling your next incident for a week from Tuesday.
And on top of that, leadership is facing questions that have never appeared on any agenda:
Do we notify customers?
Was sensitive information accessed?
Do we have regulatory reporting obligations, and on what deadline?
What does our cyber policy actually require us to do — and in what order?
Do we contact law enforcement?
What are employees allowed to say to customers?
And eventually, inevitably: Do we pay?
I want to be very direct here.
That is not a question a human being should encounter for the first time while looking at a countdown timer, running on four hours of sleep, with a hundred employees standing around unable to work.
The quality of a decision is largely determined by the conditions under which it's made. Ransomware is designed to make those conditions as bad as possible.
The First Week: Online Is Not the Same as Normal
Systems start returning. This is the part everyone imagines as the ending.
It isn't. It's the middle.
Passwords get reset — all of them. Machines get rebuilt. Servers get restored. Security tooling gets redeployed. Every account gets reviewed. Network configurations change. Employees need new instructions before they're allowed to reconnect. Some systems come back fast. Others take weeks. Nobody gets to choose which.
And even after the technology works again, the business is still bleeding in places nobody put on a dashboard:
Delayed orders.
Sales that quietly went to a competitor.
Invoices that never went out.
Overtime.
Outside security expertise billed hourly.
Legal fees.
Insurance claims.
Weeks of leadership attention consumed entirely.
And relationships with customers who trusted you with their information and are now recalculating that trust.
The ransom, if it’s even paid, is freqently the smallest number in the entire incident.
Make the Decisions Before the Crisis
A ransomware attack is the wrong time to decide who calls the insurer, who communicates with customers, or who has authority to shut down systems. Make those decisions now, while you have time to think clearly.
The Model Shift
So let's return to that belief from the beginning.
"Cybersecurity means not getting hacked."
Prevention absolutely matters. Please don't hear this as permission to skip it.
But no security stack on earth can promise you a permanent guarantee. Anyone selling you that certainty is selling you a feeling, not a capability.
So here's the upgraded question — the one that actually changes how your company behaves:
"If this happens tomorrow, how fast can we detect it, contain it, and recover?"
Notice what that question does. It stops being about buying a product and starts being about building a capability.
And it comes with a checklist you can honestly answer today:
Do you have backups an attacker can't reach or destroy?
Have you personally watched someone restore from them?
Do you know exactly who holds administrator access — everyone, by name?
Is multi-factor authentication turned on everywhere it should be, not just where it was convenient?
Is anything monitoring your machines for suspicious behavior?
Does a specific human being receive and respond to security alerts?
Is there a written incident response plan?
Does leadership know who has decision authority during a crisis?
Does an employee who sees something weird at 6 p.m. on a Friday know exactly who to call?
Those are not post-incident questions.
Those are Tuesday-afternoon questions.
Run This Exercise Tomorrow. Seriously. Tomorrow.
Here's something you can do this week that costs nothing and will teach you more than any vendor demo.
Get your leadership team in a room. No agenda. Then say this out loud:
"It's 9:15 on Monday morning. We believe ransomware has compromised our network. Email is down, shared files are inaccessible, and we don't yet know whether customer data was stolen. What do we do right now?"
Then hold the line on one rule: nobody gets to talk about hypothetical hackers.
Talk about your business. Your people. Your Monday.
Who makes the first call?
Who reaches the IT provider — and do they have that number outside of email?
Who contacts the insurance carrier?
How does anyone communicate if email is gone?
Who can actually access the backups?
Which three systems have to be running today or the business genuinely stops?
Who speaks to customers?
Who has the authority to make the expensive call?
Here's my prediction about what you'll find. Your biggest vulnerability probably isn't a firewall rule or a weak password.
It's the silence in the room when you ask who makes the first phone call.
That silence is fixable. It's fixable this month. It's fixable before anything happens.
That's the resilience worth building.
That's the recovery plan worth having.
Build for Recovery, Not Just Resistance
Ransomware doesn't just attack your network.
It performs an audit of every technology decision your company has quietly postponed — the aging systems, the permissions nobody cleaned up, the backup nobody tested, the documentation nobody wrote, the shared password everybody still uses, the alerts nobody reads, the responsibilities nobody claimed.
You are going to find those weaknesses eventually. That part isn't optional.
The only variable is whether you find them on your own calendar, with coffee and a whiteboard and time to think — or during the worst hour your business has ever had.
Choose the whiteboard.
Because if ransomware ever does reach your company, the most valuable asset you'll have isn't another product with a glowing logo.
It's a room full of people who already know exactly what to do.
About Angelia Taylor
As a certified teacher with a degree in Education (Music Minor), Angelia is able to translate highly complex technical concepts into something easy for anyone to understand.
Specializing in project management, documentation, training, AI, and presentations explaining concepts ranging from selling tech services for Shared Workspaces to troubleshooting network issues.
Help us keep sharing real stories
▶ Know someone who’d love this? Forward it their way.
▶ Buy us a coffee so we can keep doing this.
▶ Got something cool? Let’s get it out there.
▶ Was this email forwarded to you?




