By Jason Da Silva, Principal Consultant, DASTech Consulting · Last updated: June 2026
Related serviceLegal I.T.See the service →If ransomware hits, the first move in the first hour is to isolate the infected machines from everything else, not to pay and not to power everything off in a panic. Disconnect affected devices from the network, keep them running to preserve evidence, alert your IT and legal contacts, and start recovering from a clean, tested backup. The single best predictor of how this day ends is whether you have a backup you actually restored from last week. Paying the ransom is a last resort with no guarantee, not a first step.
This guide is general information about technology practice, not legal advice. It reflects what we see doing hands-on IT work with Canadian law firms, and it does not account for your firm’s particular circumstances. Confirm any specific obligation with your own counsel or with the Law Society directly before you act on it.
This is a general best-practice playbook for a small firm, written to be read before anything goes wrong. It is not legal advice, and it does not replace a real incident response plan built for your environment. If you want one of those, that is exactly the kind of thing our fractional IT service team sets up.
Everything below fits under three ideas. Keep them in front of you when the screen turns to a ransom note and adrenaline is high.
The table below is a compact timeline. Times are rough. In a real event things overlap, and a small firm will often run several of these at once with the same two or three people.
| Time window | Goal | Key actions |
|---|---|---|
| 0-1 hour | Contain the spread and preserve evidence | Disconnect affected devices from the network: unplug the network cable, disable Wi-Fi, revoke VPN access, and isolate the affected VLAN or switch ports. Do NOT power the machines off unless encryption is actively spreading and you cannot isolate them any other way, because shutting down destroys memory evidence. Stop touching the encrypted files. Call your IT lead or provider and open the incident. Note the exact time and what you saw. |
| 1-4 hours | Assess scope and pull in the right people | Figure out what is actually affected: which machines, which servers, which shared drives, and whether cloud accounts (Microsoft 365, Google Workspace) are involved. Identify the ransomware note and any strain name, but do not click links in it. Notify your cyber insurance carrier, because many policies require early notice and give you access to a breach coach and forensics team. For a law firm, loop in the responsible lawyer and any privacy or breach counsel now. Preserve logs and take photos of ransom screens. |
| 4-12 hours | Verify clean backups and plan recovery | Locate your backups and confirm they are intact and were not encrypted along with production. Immutable or air-gapped copies are what you are hoping to find here. Do a test restore of a small, known file before you trust the whole set. Change passwords and reset credentials for admin and key accounts from a known-clean device, and turn on or confirm multi-factor authentication. Begin standing up clean systems in parallel rather than reusing infected ones. Draft holding messages for staff and, if needed, clients. |
| 12-24 hours | Restore in a controlled way and start notifications | Rebuild or reimage affected machines and restore data from the verified clean backup, bringing systems back in a controlled order rather than all at once. Watch closely for signs the attacker still has a foothold. With counsel, assess whether the incident triggers a legal duty to report or notify, and start that clock deliberately. Keep a written timeline the whole way through: who did what, when, and why. Do not declare victory the moment files come back, because attackers often linger. |
If you take one thing from the table, take this: nearly every good outcome in the 12-24 hour row depends on a decision you made weeks earlier about backups. That is why we treat tested, offline backups as the foundation of every plan, especially in our IT support for law firms, where client files and matter data are not something you can afford to lose or leak.
The pressure to pay is real, and it is worth being honest about why the answer is usually still no.
Payment, if it is ever on the table, is a slow decision made with your insurer, forensics team, and legal counsel, after backups have been ruled out. It is the end of the story, not the start.
For a law firm, a ransomware attack is not only an IT problem. It can be a privacy breach and a professional obligation at the same time, so this part is handled with counsel, not improvised.
The practical takeaway: decide with counsel, document everything, and do not let the technical cleanup crowd out the notification clock. Both matter.
The firms that handle ransomware well are boring on the day it happens, because the interesting work was done in advance: offline backups that get tested, MFA everywhere, network segmentation, and a written plan with phone numbers on it. We helped a law firm move to a hardened cloud setup with full MFA coverage and zero downtime in our Heeney Lawyers cloud migration case study, and the same groundwork is what makes a bad day survivable.
If you would rather find your backup gaps in a calm planning session than at 2am during a live incident, get in touch. We are your friendly neighbourhood nerds, and we would genuinely rather help you prevent this one.
Not as a first move. Paying does not guarantee working decryption, funds criminal groups, can make you a repeat target, and may be legally restricted if the attacker is under sanctions. Rule out your backups first, and only consider payment slowly, with your insurer and legal counsel involved.
Isolate the affected machines from the network right away by disconnecting cables, disabling Wi-Fi, and revoking VPN and cloud access, while leaving the machines powered on to preserve evidence. Then call your IT and legal contacts and start writing down what you see.
You often cannot keep it quiet. Under PIPEDA, a breach of security safeguards that creates a real risk of significant harm has to be reported to the Office of the Privacy Commissioner and the affected individuals have to be notified, as soon as feasible after you determine the breach occurred. Every breach also has to be recorded, whether or not it clears that threshold, and the record kept for 24 months. Your duty of confidentiality under Rule 3.3-1 sits on top of that. Confirm with your own counsel whether PIPEDA or a substantially similar provincial law governs your practice, and decide the notification path with them.
A clean backup lets you rebuild systems and restore data without ever negotiating with the attacker. The catch is that backups only help if they were not encrypted too, which is why offline or immutable copies that you have recently test-restored are the ones that matter.
Before an incident, make sure you have tested offline backups, MFA on every account, and a written response plan with contact numbers. Our fractional IT team sets this up for firms of roughly 5 to 80 seats so the plan exists before you need it.