This walkthrough is a hypothetical. The company, the people and the sequence are invented to illustrate decisions that real organizations face. Nothing here describes an actual event.
Imagine a 90-person commercial contractor with a main office and four active jobsites. At 5:40 on a Monday morning, an estimator arrives early and finds that files will not open. Every document has a strange extension, and a text file on the desktop demands payment.
Hour 0 to 1: Recognize and contain
The most important early move is to stop the spread, and the temptation to troubleshoot is strong. A prepared company has a one-page incident card, taped inside a drawer and stored on phones, that says what to do.
What the estimator should do
- Disconnect the computer from the network by unplugging the cable or turning off Wi-Fi, but do not power it off if you can avoid it
- Do not delete anything or click on the note
- Call the designated incident number, not email, because email may be compromised
What the IT lead or provider should do
- Confirm scope by checking which systems show signs of encryption
- Isolate affected machines and, if necessary, disconnect the office from the internet
- Disable suspected accounts and force sign-outs
- Protect the backups by disconnecting backup systems and confirming they were not reached
Hour 1 to 3: Assemble the team
The owner or president activates the response team. A good plan names roles in advance:
- An incident lead making decisions
- A technical lead directing the investigation and recovery
- A communications lead handling staff, customers and any public statements
- A finance and legal contact to manage insurance, counsel and contracts
The plan should include phone numbers for the cyber insurance carrier, outside counsel and the incident response provider. Many cyber insurance policies require early notification and may specify approved vendors, so reading the policy before an incident matters.
Hour 3 to 8: Understand what happened
Investigators try to answer three questions: how did the attacker get in, what did they reach and are they still inside? Preserve evidence by capturing logs and images of affected systems before wiping anything. Rebuilding too quickly without understanding the entry point invites a second attack.
At the same time, the business must keep functioning. Superintendents need drawings. Payroll is due Friday. Subcontractors are waiting on approvals. A manual fallback plan helps: printed contact lists, personal-device access to cloud project tools if policy allows, and a pre-approved procedure for approving payments by phone with verification.
Hour 8 to 16: Decide on recovery
The central question becomes whether clean backups exist. This is where earlier preparation pays off.
- If backups are immutable and tested, the team can rebuild systems in priority order, starting with identity services, then accounting, then file storage.
- If backups were reached, recovery is far harder and the discussion about options becomes difficult. Paying criminals is a serious decision with legal, ethical and practical risks, and it never guarantees data return. Decisions of this kind should involve counsel, the insurer and law enforcement guidance.
Whatever the path, reset every credential that may have been exposed, starting with administrators, and review remote access and email rules for tampering.
Hour 16 to 24: Communicate and report
Staff need clear, honest updates, including what to do and not do. Customers and partners may need notice, especially if their data or access is involved. Contracts, insurance and regulations may carry notification duties, and counsel can advise on timing. For incidents involving federal contract information or CUI, reporting obligations in your contracts may apply. Consider reporting to law enforcement as well, such as the FBI, and to CISA, which can provide assistance.
What made the difference in this story
The hypothetical company recovered faster than it might have because it had:
- A written plan and phone numbers outside the compromised systems
- Immutable backups it had tested
- Multifactor authentication on remote access
- Separation between administrator and everyday accounts
- A relationship with a response provider before it was needed
What to do this month
- Write the one-page incident card
- Confirm your insurer's notification requirements
- Verify that your backups cannot be changed by an administrator account
- Run a short tabletop exercise using this scenario
- Save key contacts somewhere that does not depend on your network
How Ironfield Cyber helps
Ironfield Cyber helps contractors and energy companies prepare for incidents and respond to them, including response planning, tabletop exercises, backup hardening and recovery support. If you would like to rehearse a scenario like this with your leadership team, we can facilitate it.