Guide

Ransomware response: the first 24 hours for a small firm

Legal I.T. services from DASTech ConsultingRelated serviceLegal I.T.See the service

If ransomware hits, the first move in the first hour is to isolate the infected machines from everything else, not to pay and not to power everything off in a panic. Disconnect affected devices from the network, keep them running to preserve evidence, alert your IT and legal contacts, and start recovering from a clean, tested backup. The single best predictor of how this day ends is whether you have a backup you actually restored from last week. Paying the ransom is a last resort with no guarantee, not a first step.

Before you read on

This guide is general information about technology practice, not legal advice. It reflects what we see doing hands-on IT work with Canadian law firms, and it does not account for your firm’s particular circumstances. Confirm any specific obligation with your own counsel or with the Law Society directly before you act on it.

This is a general best-practice playbook for a small firm, written to be read before anything goes wrong. It is not legal advice, and it does not replace a real incident response plan built for your environment. If you want one of those, that is exactly the kind of thing our fractional IT service team sets up.

The three rules that matter most

Everything below fits under three ideas. Keep them in front of you when the screen turns to a ransom note and adrenaline is high.

  1. Isolate, do not detonate. Pull the affected machines off the network immediately, but do not start wiping or rebooting everything. You need to contain the spread and preserve evidence at the same time.
  2. Do not pay blindly. Paying funds a criminal operation, does not guarantee you get your files back, marks you as a firm that pays, and can carry serious legal risk if the group is under sanctions. Payment is a decision made slowly, with counsel and your insurer, not a reflex.
  3. The backup you tested last week is the hero. Immutable or offline backups that you have actually restored from are what turn a catastrophe into a bad Tuesday. Untested backups are just hope with a schedule.

Hour-by-hour: the first 24 hours

The table below is a compact timeline. Times are rough. In a real event things overlap, and a small firm will often run several of these at once with the same two or three people.

Time window Goal Key actions
0-1 hour Contain the spread and preserve evidence Disconnect affected devices from the network: unplug the network cable, disable Wi-Fi, revoke VPN access, and isolate the affected VLAN or switch ports. Do NOT power the machines off unless encryption is actively spreading and you cannot isolate them any other way, because shutting down destroys memory evidence. Stop touching the encrypted files. Call your IT lead or provider and open the incident. Note the exact time and what you saw.
1-4 hours Assess scope and pull in the right people Figure out what is actually affected: which machines, which servers, which shared drives, and whether cloud accounts (Microsoft 365, Google Workspace) are involved. Identify the ransomware note and any strain name, but do not click links in it. Notify your cyber insurance carrier, because many policies require early notice and give you access to a breach coach and forensics team. For a law firm, loop in the responsible lawyer and any privacy or breach counsel now. Preserve logs and take photos of ransom screens.
4-12 hours Verify clean backups and plan recovery Locate your backups and confirm they are intact and were not encrypted along with production. Immutable or air-gapped copies are what you are hoping to find here. Do a test restore of a small, known file before you trust the whole set. Change passwords and reset credentials for admin and key accounts from a known-clean device, and turn on or confirm multi-factor authentication. Begin standing up clean systems in parallel rather than reusing infected ones. Draft holding messages for staff and, if needed, clients.
12-24 hours Restore in a controlled way and start notifications Rebuild or reimage affected machines and restore data from the verified clean backup, bringing systems back in a controlled order rather than all at once. Watch closely for signs the attacker still has a foothold. With counsel, assess whether the incident triggers a legal duty to report or notify, and start that clock deliberately. Keep a written timeline the whole way through: who did what, when, and why. Do not declare victory the moment files come back, because attackers often linger.

If you take one thing from the table, take this: nearly every good outcome in the 12-24 hour row depends on a decision you made weeks earlier about backups. That is why we treat tested, offline backups as the foundation of every plan, especially in our IT support for law firms, where client files and matter data are not something you can afford to lose or leak.

Why “do not pay” is the default, not a slogan

The pressure to pay is real, and it is worth being honest about why the answer is usually still no.

  • There is no guarantee. You are trusting criminals to hand over a working decryption key. Sometimes the key is slow, partial, or broken.
  • It funds and invites more attacks. Firms that pay are known to pay, and a meaningful share are targeted again, sometimes within the year.
  • There may be a legal wall. Sanctions regimes can restrict payments to certain groups, and attribution is rarely obvious in the first days. Do not treat payment as a purely commercial decision. Have your counsel and your insurer confirm what restrictions apply to your firm, and check the current guidance, before any money moves.
  • It does not make the breach go away. Even if you pay and decrypt, the data was still accessed, so your notification and reporting duties do not disappear.

Payment, if it is ever on the table, is a slow decision made with your insurer, forensics team, and legal counsel, after backups have been ruled out. It is the end of the story, not the start.

The legal and notification piece

For a law firm, a ransomware attack is not only an IT problem. It can be a privacy breach and a professional obligation at the same time, so this part is handled with counsel, not improvised.

  • Under Canadian federal privacy law (PIPEDA), an organization must report a breach of security safeguards to the Office of the Privacy Commissioner and notify the affected individuals where the breach creates a “real risk of significant harm”, and must do both as soon as feasible after it determines that a breach has occurred.
  • Significant harm is defined broadly: bodily harm, humiliation, damage to reputation or relationships, loss of employment, business or professional opportunities, financial loss, identity theft, negative effects on the credit record, and damage to or loss of property. The factors you weigh in deciding whether that risk is real include how sensitive the information is and how likely it is to be misused. For a law firm holding matter files, both tend to point the same way.
  • Separately from the reporting threshold, you have to keep a record of every breach of security safeguards, whether or not it meets the real risk of significant harm test, and keep those records for 24 months. Start that record on day one rather than reconstructing it later.
  • Confirm with your own counsel whether PIPEDA or a substantially similar provincial law governs your practice, because that determines who you report to and on what terms.
  • Lawyers carry professional duties on top of the privacy legislation. The duty of confidentiality in Rule 3.3-1 of the Law Society of Ontario’s Rules of Professional Conduct requires you to hold in strict confidence all information concerning the business and affairs of a client acquired in the course of the professional relationship, subject to four exceptions: the client authorizes disclosure, disclosure is required by law or by order of a tribunal, it is required by the Law Society, or it is otherwise permitted by the rules.
  • Competence covers your technology as well. Rule 3.1-2 is the competence rule, and its commentary says a lawyer should develop an understanding of, and the ability to use, technology relevant to the nature and area of their practice, and should understand the benefits and risks of that technology given the duty to protect confidential information. The Law Society adopted the Federation of Law Societies model commentary on this, amended in fall 2019. A ransomware event is where that commentary stops being abstract.
  • If staff who are not licensees are doing any of the response work, the supervision rules in Chapter 6 still apply while the lights are flashing.
  • Whether, when and how you tell affected clients turns on the facts of your own matters. Settle that with your own counsel, or ask the Law Society directly, before you send anything.

The practical takeaway: decide with counsel, document everything, and do not let the technical cleanup crowd out the notification clock. Both matter.

Get the plan built before you need it

The firms that handle ransomware well are boring on the day it happens, because the interesting work was done in advance: offline backups that get tested, MFA everywhere, network segmentation, and a written plan with phone numbers on it. We helped a law firm move to a hardened cloud setup with full MFA coverage and zero downtime in our Heeney Lawyers cloud migration case study, and the same groundwork is what makes a bad day survivable.

If you would rather find your backup gaps in a calm planning session than at 2am during a live incident, get in touch. We are your friendly neighbourhood nerds, and we would genuinely rather help you prevent this one.

FAQ

Common questions.

Should we pay the ransom to get our files back faster?

Not as a first move. Paying does not guarantee working decryption, funds criminal groups, can make you a repeat target, and may be legally restricted if the attacker is under sanctions. Rule out your backups first, and only consider payment slowly, with your insurer and legal counsel involved.

What is the single most important thing to do in the first hour?

Isolate the affected machines from the network right away by disconnecting cables, disabling Wi-Fi, and revoking VPN and cloud access, while leaving the machines powered on to preserve evidence. Then call your IT and legal contacts and start writing down what you see.

Do we have to tell anyone, or can we just quietly fix it?

You often cannot keep it quiet. Under PIPEDA, a breach of security safeguards that creates a real risk of significant harm has to be reported to the Office of the Privacy Commissioner and the affected individuals have to be notified, as soon as feasible after you determine the breach occurred. Every breach also has to be recorded, whether or not it clears that threshold, and the record kept for 24 months. Your duty of confidentiality under Rule 3.3-1 sits on top of that. Confirm with your own counsel whether PIPEDA or a substantially similar provincial law governs your practice, and decide the notification path with them.

How do backups actually save us here?

A clean backup lets you rebuild systems and restore data without ever negotiating with the attacker. The catch is that backups only help if they were not encrypted too, which is why offline or immutable copies that you have recently test-restored are the ones that matter.

We are a small firm without in-house IT. What should we do now?

Before an incident, make sure you have tested offline backups, MFA on every account, and a written response plan with contact numbers. Our fractional IT team sets this up for firms of roughly 5 to 80 seats so the plan exists before you need it.