0–30 minutes: contain
- Disconnect affected devices from Wi‑Fi/Ethernet (don’t power off unless advised).
- Disable suspicious accounts and reset admin credentials (use MFA).
- Stop the spread: isolate servers/shared drives if ransomware is suspected.
30–120 minutes: assess + preserve evidence
- Document what happened, when, and which systems are impacted.
- Preserve logs/emails/screenshots. Avoid wiping devices.
2–24 hours: recover safely
- Restore from known-good backups (test restores first).
- Patch vulnerabilities and rotate credentials.
- Enable stronger baselines: MFA, device security, backup monitoring.
If you are in Auckland or working remotely in New Zealand, do not pay a ransom and do not wipe devices until someone has captured evidence. Call your IT provider, your bank if payments were hit, and the Police if money or personal data was stolen. 365wiz can help contain the incident, restore from backup, and lock accounts down the same day where possible.
Related reading
Reduce future incidents with proactive support: Why Managed IT Services Save You Money Long Term.
Need urgent help?
If you suspect ransomware or account compromise, contact us. We’ll help contain, recover, and harden your environment.