Contain the spread
Disconnect affected systems and avoid logging into sensitive accounts from infected machines.
If files are encrypted, popups demand payment, or a workstation is locked, disconnect affected machines from the network and call before taking more action.

Ransomware and suspected compromise cases need emergency intake, containment steps, and recovery planning before normal repair work starts.
Disconnect affected systems and avoid logging into sensitive accounts from infected machines.
Identify impacted devices, files, backups, accounts, and possible entry points.
Restore from clean sources where possible, remove persistence, and close security gaps.
Call first so containment, backup status, and recovery options can be triaged quickly.
The first step is containment, evidence preservation, and recovery-option assessment. Payment decisions need to wait until the scope and backup status are understood.
Possibly. Backups need to be checked carefully so infected or encrypted files are not restored over clean systems.
Yes. Post-incident work can include patching, backup review, MFA, endpoint protection, and user training.
For urgent cases, calling is better than waiting on a form.