Most companies I walk into have two things: a backup that runs every night, and a vague sense that someone in IT would handle it if something bad happened.
That second thing is not a plan. It's a hope with a job title attached.
Ransomware doesn't care that you're a $20M company and not a bank. Attackers go after mid-market companies exactly because you're big enough to pay and small enough to have no incident response playbook. Your MSP might catch it fast. They might not. And in the first hour, it won't be a technology problem. It'll be a leadership problem.
The First Hour Matters More Than the Backup
Here's what the first sixty minutes after a ransomware hit actually look like. Someone can't open a file. Then someone else can't open one. Then the whole server is locked and there's a note demanding payment in crypto.
The question nobody has answered yet is who makes the calls. Who pulls the plug on the network. Who talks to the insurance carrier. Who decides whether the business stops billing for a day.
If the answer is "our IT guy," you have a single point of failure. If that person is on vacation, you have no answer at all.
A Phone Tree Is Not a Plan
A real incident response plan fits on two pages and answers three questions: who does what, in what order, with what authority.
Who declares an incident. Who isolates the affected systems. Who calls the cyber insurance carrier (you should have one, and they have a breach hotline that's faster than anything you can do yourself). Who talks to the staff, and who talks to customers if data was exposed.
Write names, not roles. "The network admin" is useless at 2 AM when he's in Cabo. Write the backup name too.
And here's the part everyone skips: the plan has to include the decision nobody wants to make in a panic, which is whether you pay. Decide the framework now. What data is non-negotiable. What downtime costs you per day. Who has the authority to say yes or no. Because that decision, made at 3 AM by whoever happens to be awake, is the worst possible version of it.
Practice It Before You Need It
A plan nobody has read is decoration. Once a year, sit the leadership team down for an hour and run a tabletop exercise. Walk through the scenario: ransomware at 11 PM on a Friday, backups are intact, but recovery will take four days.
Watch what happens. Someone will discover they don't have the insurance policy number. Someone else will realize the CFO is the only one who can approve the recovery vendor's contract, and he's unreachable. These are the gaps you fix on a calm Tuesday, not during the incident.
It costs you one meeting. The companies that do it recover in days. The ones that don't measure it in weeks, plus the customers they lost in the meantime.
Ransomware Is a Business Problem
Your MSP handles the technology. Your backups handle the recovery. But the response, the first hour, the decisions, the communication, that belongs to leadership. That's the gap I see most often in mid-market companies, and it's the cheapest one to close.
You don't need a 60-page playbook. You need two pages, real names, and one hour a year of practice.
Not sure where your IT really stands? Start with a Clarity Audit: a focused assessment of your backups, security, vendors, and AI readiness. It's the first step in every engagement I take on.
About the author: Chris McGlasson is a fractional CIO and the founder of ClearStack Advisory, where he helps mid-market companies build AI governance, IT strategy, and technology roadmaps without the overhead of a full-time CIO. He previously built and sold LANPRO Systems, an IT services firm serving 350+ enterprise clients.
