Nobody wants to need this article. Keep it anyway. Incidents happen on Friday afternoons and holiday weekends, and what the first person does in the first hour makes a measurable difference to how many days the recovery takes.
Do
- Call your IT team first — for Spicsoft customers, the 24/7 line, answered by an engineer, not a queue.
- Disconnect the affected machine from the network (unplug the cable or turn off Wi-Fi). Isolating stops spread; it does not destroy evidence.
- Write down what you saw and when — the message, the file names, who was logged in. It feels trivial; it saves hours.
- Tell staff not to open anything or "try to fix it". Good intentions cause a lot of collateral damage.
Don't
- Don't power everything off in a panic — some malware runs its final act on shutdown, and logs are lost.
- Don't pay, reply, or negotiate. That is a decision for later, with your IT team and insurer.
- Don't log in as an administrator on the affected machine "to have a look".
- Don't wait until Monday because it might be nothing. Call. If it is nothing, we will say so cheerfully.
What happens on our side
The call becomes an incident. The affected systems are isolated, the entry point identified and closed, credentials reset, and recovery started from the isolated backups we restore-test for exactly this day. You are kept informed by one named engineer, start to finish. A well-prepared incident is a procedure; the preparation is the part we do every week so that the procedure works.

