When ransomware hits your organization, the question your IT provider answers in the next few hours is not technical. It is existential: do they have the capability, the authority, and the specific expertise to execute an effective ransomware response, or are they managing the situation they trained for while you needed the one they did not?
Most organizations find out the answer to this question during an active incident, which is the worst possible time to discover a gap. The IT provider that manages your infrastructure reliably, responds to tickets promptly, and keeps your systems running may not have the specialized ransomware response capability that the next few hours require.
Reliable general IT management and effective ransomware incident response are different capabilities that overlap but are not the same thing.
This article tells you exactly what your IT provider should be doing right now if ransomware is active in your environment, what the specific actions are in the correct sequence, what capabilities the response requires that general IT management does not always include, and how to assess whether your provider is executing effectively or whether additional resources need to be engaged immediately.
What Your IT Provider Should Be Doing in the First 30 Minutes
The first 30 minutes of a ransomware response determines the scope of the incident more than any other period. The actions that must occur in this window are specific, sequenced, and time-critical.
If your IT provider is not executing these actions, the incident is expanding while they are doing something else.
Confirming the Incident and Declaring a Response
The first action is confirmation that ransomware is actually present rather than a different cause of system unavailability, followed immediately by declaring an active incident response and activating whatever emergency response protocols exist.
Confirmation takes minutes, not hours. The signals that distinguish ransomware from other file access problems, ransom notes appearing on screens, files with altered extensions across multiple systems, and multiple users in different departments reporting inaccessible files simultaneously, are identifiable quickly.
Your IT provider should be confirming and declaring within minutes of being notified, not spending 30 minutes attempting to diagnose the problem before concluding it is ransomware.
If your IT provider is still in diagnosis mode 20 minutes after the first notification, ask specifically: have you confirmed this is ransomware, and have you started the emergency response sequence?
Organizations with a documented cyber incident response plan and defined incident response team roles are often able to move faster during this phase.
Executing Immediate Containment
The moment ransomware is confirmed, your IT provider should be executing network isolation of infected systems.
Not discussing what to do. Not escalating through internal approval chains. Executing.
For systems they have remote management access to, your IT provider should be remotely isolating infected endpoints through endpoint management consoles and endpoint detection and response tools.
For on-premises servers they manage, they should be directing your internal facilities or IT staff to physically disconnect network cables while keeping systems powered on.
Your IT provider should simultaneously be disabling VPN infrastructure, Remote Desktop Gateway, and any remote monitoring and management tools that could serve as ongoing attacker pathways.
Organizations that have adopted Zero Trust security principles, strong network security controls, and secure network architecture often contain ransomware faster.
What your IT provider should not be doing during containment is attempting to remove the ransomware from infected systems, attempting to decrypt files, or attempting to restore from backup.
Containment comes first.
Notifying You and Your Insurance Carrier
Your IT provider should be notifying you of the confirmed incident immediately and should be asking whether you have cyber insurance and whether you have notified your carrier.
If you have cyber insurance, your IT provider should understand that the insurance carrier call is the first call and should be directing you to make that call if you have not already.
An IT provider who begins executing a full response without asking about insurance, and whose response costs therefore accumulate before coverage is confirmed, is creating coverage risk that the carrier call would have prevented.
Establishing Out-of-Band Communication
If organizational communication infrastructure may be affected, your IT provider should be identifying and establishing out-of-band communication channels for the response team.
Coordinating a ransomware response through email infrastructure that may be compromised or monitored by the attacker exposes the response to attacker visibility.
Your IT provider should be directing response coordination to personal mobile phones and suggesting a specific out-of-band communication channel that the response team should use for the duration of the incident.

What Your IT Provider Should Be Doing in Hours One Through Three
The first three hours transition from immediate containment to scope assessment and evidence preservation.
Scope Assessment
Your IT provider should be conducting a systematic assessment of which systems are confirmed infected, which are potentially infected, and which are confirmed clean.
This assessment uses Active Directory authentication logs, network flow data, endpoint detection alert logs, and user reports to build a complete picture of the incident scope before recovery actions begin.
Scope assessment errors are among the most consistent causes of extended ransomware recovery timelines.
Your IT provider should be able to tell you within the first two to three hours which specific systems are confirmed infected, which are under assessment, and which are confirmed clean.
Forensic Evidence Preservation
Your IT provider should be preserving forensic evidence from infected systems before any remediation work begins.
If they have forensic memory capture tools deployed through their endpoint management infrastructure, they should be capturing volatile memory from infected systems.
If they do not have these tools, they should be contacting the incident response firm whose engagement was initiated through the insurance process to coordinate evidence preservation.
What your IT provider should not be doing is beginning remediation, wiping systems, or initiating restoration before forensic evidence is preserved.
Organizations that maintain strong incident response capabilities and managed detection and response services are generally better positioned to preserve critical evidence.
Backup Assessment
Your IT provider should be assessing the status and viability of your backup infrastructure within the first three hours.
This assessment determines the primary recovery path and should be completed before recovery planning begins.
The assessment must answer specific questions:
- Are backups stored in an isolated location?
- Are backups recent enough to support recovery objectives?
- Have backups been tested through actual restoration?
- Can restoration meet operational requirements?
Your IT provider should communicate the backup assessment findings clearly and specifically.
Organizations with mature backup strategies, disaster recovery services, and cloud disaster recovery solutions typically have more recovery options available.
Ransomware Variant Identification
Your IT provider should be identifying the specific ransomware variant through encrypted file extension examination, ransom note analysis, and submission of samples to identification tools including No More Ransom Crypto Sheriff.
Variant identification helps determine whether free decryption tools exist, informs legal review, and provides insight into attacker behavior.
What Your IT Provider Should Be Doing in Hours Three Through Eight
Supporting the Payment Decision Analysis
Your IT provider should provide technical input that supports leadership, legal counsel, and insurance stakeholders in evaluating available recovery paths.
The payment decision belongs to leadership, legal counsel, and the breach coach, not the IT provider.
Recovery Path Planning
Your IT provider should be developing a recovery plan that identifies the preferred recovery path, restoration sequence, system dependencies, and timeline estimates.
This plan should be communicated to leadership before recovery execution begins.
Regulatory Notification Support
Your IT provider should support legal counsel by providing technical facts regarding affected systems, impacted data, timeline details, and preliminary exfiltration findings.
The provider supplies technical evidence while legal counsel manages regulatory obligations.
What Your IT Provider Should Be Doing During Recovery
Threat Elimination Before Restoration
Your IT provider should be executing or coordinating threat elimination before any system is restored to the production network.
Threat elimination includes:
- Removing ransomware payloads
- Removing persistence mechanisms
- Resetting credentials
- Patching exploited vulnerabilities
- Validating that attacker access has been eliminated
This is often the area that separates providers with true ransomware response expertise from providers that primarily perform general IT support.
Sequenced Restoration With Validation
Your IT provider should restore systems in dependency order and validate each system before reconnecting it to production.
Infrastructure services such as Active Directory, DNS, and authentication systems should be restored first.
Critical business applications follow.
End-user systems should generally be restored last.
Communication With You Throughout Recovery
Your IT provider should proactively communicate recovery status, milestones, complications, and revised timelines throughout the recovery process.
Leadership should not need to ask for updates. Updates should be delivered consistently and proactively.
What Gaps Indicate You Need Additional Resources
- No ransomware-specific expertise
- No forensic capability
- Threat elimination not completed before restoration
- No communication with the insurance carrier
- Inability to explain current response status and methodology
When these gaps exist, organizations should engage specialized incident response resources immediately.
What a Strong IT Provider Response Looks Like
A strong IT provider response includes:
- Rapid incident confirmation and containment
- Clear communication and status updates
- Insurance awareness and coordination
- Forensic evidence preservation
- Threat elimination before restoration
- Accurate recovery planning and execution
- Engagement of specialized experts when necessary
Most importantly, they understand their limitations and bring in specialized resources when the situation requires expertise beyond their internal capabilities.
Meet Our CEO, Matt Rosenthal
With more than 30 years of experience in business and technology leadership, Matt Rosenthal has guided organizations across healthcare, finance, legal, manufacturing, and defense through ransomware incidents where the effectiveness of the IT provider response directly influenced containment speed, recovery timelines, and business impact. As President and CEO of Mindcore Technologies, Matt leads a team that delivers managed IT services and cybersecurity services built around both operational excellence and incident response readiness.
Matt believes organizations should evaluate ransomware response capability before an incident occurs, ensuring their provider can execute under pressure when every minute matters.
Frequently Asked Questions
How do we know if our IT provider has genuine ransomware response capability before an incident?
Ask to review their incident response procedures, ransomware-specific processes, after-hours response capabilities, and relationships with forensic incident response firms.
What should we do if our IT provider is not performing the actions described in this article?
Notify your cyber insurance carrier immediately and engage specialized incident response resources without delay.
Can our IT provider manage both routine IT operations and ransomware response simultaneously?
It depends on the provider’s size, staffing, and security capabilities. Smaller providers may struggle to support both functions during a major incident.
Should we replace our IT provider after a ransomware incident?
Evaluate both their prevention capabilities and their response performance before making a decision. The incident may reveal improvement opportunities rather than an immediate need for replacement.
What is the difference between an IT provider and an incident response firm?
An IT provider manages ongoing infrastructure and operations, while an incident response firm specializes in forensic investigation, containment, recovery, and ransomware-specific response activities.
Assess Your IT Provider Before the Incident Requires the Assessment
The gap between general IT management capability and effective ransomware response is most often discovered during an active incident.
The assessment of whether your IT provider has genuine ransomware response capability, what their procedures are, and what specialized resources they engage should happen before an incident makes it urgent.
Mindcore’s managed IT services and cybersecurity services provide organizations across healthcare, finance, legal, manufacturing, and defense with the operational support and ransomware response infrastructure required to navigate today’s threat landscape.

