Hit by ransomware or fraud? Call now.
If files are encrypted, money has moved, or someone is inside your email, the next hour matters more than the next week. Call the number below — then do the four things further down this page while you wait.
One number · no ticket form · no queue position
Capacity — read this first
We are a small team, and an active incident takes people off other work. Call first. We will tell you within the hour whether we can take it — and if we can’t, we’ll say so plainly instead of leaving you waiting.
Business hours
Mon–Fri, 8am–5pm Central. A human answers, or calls you back within the hour. You will not be asked to open a ticket to talk to someone.
After hours — if you’re not a client yet
You will reach voicemail. Call anyway and leave your name, a callback number, and what happened. Then do the four things below tonight. We call back first thing at 8am CT.
Four things to do in the first hour.
These work whether you end up hiring us or not. Three of them cost nothing; the fourth has a window measured in hours.
Disconnect the affected machines from the network
Unplug the network cable and turn off Wi-Fi on anything showing symptoms. Do not power them off. Leave them running, screens on.
WHY — pulling the network stops it spreading to the server and the backups. Shutting down wipes what’s in memory, which is often the only record of how it got in and what it took.
Do not pay, and do not wipe
Don’t contact the attacker, don’t pay, and don’t let anyone reimage a machine to “just get it working.” Not tonight.
WHY — payment rarely returns everything and funds the next one. Reimaging destroys the evidence your insurer will ask for, and it usually leaves the way in wide open for a second visit.
Preserve the evidence, on paper if you have to
Photograph the ransom screen and any strange messages with your phone. Leave logs and email alone. Write down times: when it was noticed, by whom, and what they had just clicked.
WHY — the timeline is the first thing an insurer, a forensics firm, or a regulator asks for. Memory fades in a day; a phone photo and a notepad do not.
Call your bank now — before you call anyone else
If a wire or ACH went out, phone the bank’s fraud line and ask for a wire recall or ACH return. Then file with the FBI at ic3.gov.
WHY — the recall window is measured in hours, sometimes less, and it closes whether or not anyone has diagnosed the breach yet. This one call is the only step that cannot wait for IT.
How Micro-IT takes over.
The order matters more than the speed. Restoring before the door is shut is how a business gets hit twice in one week.
Containment
Isolate what’s infected, cut the path it used, and lock the identities involved — passwords, sessions, mail rules, MFA. Nothing gets restored until the door is shut.
Scope
Establish what was actually reached, when, and by what. Guessing here is what produces a second incident — and a scope you can’t defend is a scope your insurer won’t accept.
Restore
Rebuild from backups we’ve verified as clean, in a deliberate order — identity and infrastructure first, the workstation everyone is shouting about last.
Coordination
We talk to your insurer’s breach counsel and your bank in the language they use, with the timeline, log excerpts, and evidence they ask for. You stay in the loop, not in the middle.
Hardening
The gap that let it in gets closed, documented, and shown to you. Then we tell you what else we found while we were in there — including the things you won’t want to hear.
If money moved, this is a different emergency
Wire fraud and business email compromise rarely break anything. Nothing is encrypted, no alarm goes off — a real invoice simply gets paid to the wrong account, because someone was reading the thread first. The recovery clock is the bank’s, not IT’s: call the fraud line before you call us. Then we work backwards through the mailbox to find how long they were in there and what else they saw. How business email compromise works → · The wire-verification playbook →
Not under attack right now?
Then this is the cheapest hour you’ll ever spend on it. Most of the incidents we take were preventable at a cost nobody would have argued about.
Fifteen questions about backups, email, admin rights, and patching. You get a scored result and the specific gaps, not a sales call disguised as a quiz.
Written for owners, not engineers: what the days after look like, what recovery really costs, and which decisions have to be made before anything is on fire.
