Ransomware Attack in Calgary: The First 24 Hours — A Business Playbook
A ransomware attack in Calgary usually announces itself the same way on the worst morning of a business owner’s year: files renamed, systems locked, and a ransom note demanding payment in cryptocurrency within a countdown window. In that moment, the instinct is to panic, and the second instinct is to do something — anything — immediately. Both instincts tend to make things worse. The businesses that come through a ransomware attack in the best shape aren’t the ones that react fastest; they’re the ones that follow a plan they built before the attack ever happened.
This playbook walks through what those first 24 hours should actually look like for a Calgary business. It’s written to be useful whether you’re reading it as preparation or, worst case, reading it right now with a ransom note on your screen. Either way, PCe Solutions provides cybersecurity services to businesses across Calgary and Southern Alberta, and incident response is one of the areas where having a plan in place changes the outcome most dramatically.
The First Hour: Contain, Don’t React
Step 1 — Isolate, don’t shut down
Disconnect affected machines from the network — unplug the ethernet cable, disable Wi-Fi — to stop the ransomware spreading to other systems and backups. Critically, do not simply power the machines off. Shutting down can destroy forensic evidence in memory that helps identify how the attack happened and whether data was actually stolen. Isolate, then leave running.
Step 2 — Call your IT provider or incident response team first
Before touching anything else, get your MSP or security team on the phone. If PCe Solutions manages your environment, this is the point where our team takes over containment. If you cannot reach your provider, this is exactly the situation our callback line exists for — reach us at 1-855-423-3183 ext 202.
Step 3 — Preserve the ransom note and any evidence
Photograph the ransom screen, note the exact time you discovered it, and record which systems are affected. This documentation matters for law enforcement, for your cyber insurer, and for the forensic investigation that follows.
What NOT to Do in the First Hour of a Ransomware Attack
🚫 Don’t pay the ransom impulsively
Paying is a decision for later in the process, made with your insurer, legal counsel, and IT team — not a panic response in the first hour. Payment doesn’t guarantee your data back, may fund further attacks, and can carry legal complications. It’s an option to evaluate carefully, never a reflex.
🚫 Don’t try to “clean” the machines yourself
Deleting files, running consumer antivirus, or attempting to remove the ransomware yourself can destroy evidence and, in some cases, trigger the malware to do further damage. Leave remediation to professionals.
🚫 Don’t restore from backups before the threat is removed
Restoring onto a network the attacker is still inside simply hands them your fresh data too. Recovery comes only after containment and eradication are confirmed complete.
Responding to a Ransomware Attack in Calgary: Hours 2 to 8
Determine Scope With Your IT Team
Your provider works to answer the critical questions: which systems are affected, whether data was exfiltrated (stolen) as well as encrypted, and whether clean, uncompromised backups exist. The answers shape every decision that follows.
Notify Your Cyber Insurance Provider
If you carry cyber insurance, your policy almost certainly requires prompt notification — often within a specific window — and your insurer will typically have their own approved incident response resources. Failing to follow the notification process can jeopardize your coverage. If you’re not sure what your policy requires, that’s a gap worth closing before an incident, not during one.
Understand Your Privacy Breach Obligations Under Alberta Law
If personal information was compromised, Alberta’s Personal Information Protection Act (PIPA) requires organizations to notify the Office of the Information and Privacy Commissioner (OIPC) where a breach creates a real risk of significant harm — and affected individuals must be notified as well. For healthcare providers, Alberta’s Health Information Act adds its own breach-notification duties. These are legal obligations with real timelines, and a ransomware attack that touches personal data triggers them.
Hours 8 to 24: Recover in the Right Order
Once your IT team confirms the threat is fully contained and eradicated, controlled recovery begins — restoring systems from clean backups, prioritizing the systems your business most depends on, and verifying each restored system before reconnecting it. This is deliberately methodical. Rushing recovery is how businesses reinfect themselves and start the entire ordeal over. Throughout, someone should be documenting what happened for the post-incident review, the insurance claim, and any regulatory reporting.
The Real Lesson: The Plan Comes Before the Attack
Everything in this playbook is dramatically easier to execute if it was decided in advance — who to call, where the offline backups are, what the insurance policy requires, who notifies the OIPC. A Calgary business with a documented incident response plan works through a stressful but manageable sequence. A business without one improvises every decision under maximum pressure, and improvisation is where the expensive mistakes happen. Surviving a ransomware attack in Calgary comes down to that preparation far more than to anything done in the moment. If you’re not certain your business could answer every question in this playbook today, that uncertainty is the thing to fix. Our guide on small business cybersecurity in Calgary covers the preventive foundation that keeps most attacks from succeeding in the first place.
Does Your Calgary Business Have a Real Incident Response Plan?
Schedule a free, no-obligation assessment with PCe Solutions. Our local Calgary team will review your current backup strategy, security posture, and incident readiness — and give you an honest picture of how your business would actually fare in the first 24 hours of a ransomware attack. No sales pressure, just expert local advice.
Book Your Free Calgary Security Assessment
