Ransomware Response Playbook for Texas Engineering Firms: 72-Hour Action Plan

Ransomware Response Playbook for Texas Engineering Firms: 72-Hour Action Plan

Updated September 2, 2026

TL;DR: During a ransomware attack, isolate infected systems from your network immediately without powering them off, then notify your MSSP and leadership within the first hour. This ransomware response plan sequences the next 30 days into four phases: detect and contain within 4 hours, activate your response by hour 24, decide on the ransom question by day 3, then recover and harden your systems over the following month. Texas engineering firms carry Revit files, federal contract data, and ITAR drawings that add their own notification deadlines.

The most expensive mistake in a ransomware incident often happens in the first five minutes: powering off the infected machine. That single action destroys the memory-resident evidence a forensic investigator needs, turning a contained four-hour incident into a weeks-long guessing game. Federal guidance recommends isolating infected systems from the network instead of shutting them down.

A ransomware attack on a Texas engineering firm starts clocks you cannot stop. Forensic evidence degrades by the hour, and federal contracts can require the Department of Defense to hear from you within 72 hours. TechProComp provides cybersecurity services for engineering firms and 24/7 incident response for Texas engineering firms with 80 to 150 employees facing exactly this situation.

Hours 0-4: Detect and Contain

The first four hours decide how expensive the rest of the incident becomes. Confirm the threat is real, isolate it without destroying evidence, notify the right people, and start documenting from minute one.

Confirm and Isolate the Threat

Rule out a false positive first: check whether the encryption pattern, ransom note, and file extensions match a known ransomware family before you treat it as confirmed. Once confirmed, isolate the affected endpoints from the network. Do not power them off.

Federal containment guidance recommends isolating affected systems immediately rather than powering them down, and when multiple systems or subnets are affected, it points toward taking the network offline at the switch level rather than shutting individual machines down, per CISA’s StopRansomware Guide. Powering off destroys the memory-resident data forensic investigators rely on to trace the attacker’s path.

Isolate Storage and Disable Remote Access

Isolate file servers and Revit or CAD storage, not just individual workstations. These shared file stores are often the highest-value target and the hardest to recover, since dozens of team members and sometimes clients depend on the same central file.

Disable VPN access immediately after isolating storage. Attackers that gained a foothold through a compromised credential can otherwise re-enter through the same remote access path while your team is still assessing the damage.

Notify Leadership and Your Response Team

Notify your CEO, COO, IT lead, and MSSP as soon as containment is underway. Speed here matters as much as the technical containment itself.

What stands out the most is their exceptional responsiveness and reliability. – Verified User on Clutch

One Time IT Services TechProComp

Document and Begin Chain of Custody

Document the exact time of detection, every affected system, and any indicators of compromise you observe, before memory fades or logs rotate. Bring in your incident response team next: internal IT, your MSSP, and legal counsel together, not sequentially.

Begin chain of custody documentation immediately. Federal guidance instructs victims to file a detailed report identifying the ransomware variant, the encrypted file extensions, the attacker’s cryptocurrency address, and the email address used in the attack, per the FBI’s IC3 ransomware guidance.

Hours 4-24: Activate Incident Response

Between hour 4 and hour 24, the job shifts from containment to building the full response team and starting the clocks that matter most: insurance and legal.

Appoint an Incident Commander and Bring In Forensics

Appoint a single Incident Commander, often the Operations Leader at firms without a dedicated CISO. This person owns every decision so the response does not stall waiting for consensus.

Bring in a forensic firm the same day. Firms like Mandiant, CrowdStrike Services, and Stroz Friedberg are examples of the type of forensic firm engineering firms typically retain, and naming a firm in advance, before an incident happens, saves hours you do not have once one does.

Notify your cyber insurance carrier as early as possible. Insurance notification windows are policy-specific, so check your actual policy language rather than assuming a standard window applies.

The strongest current federal benchmark for incident-reporting speed comes from the Cyber Incident Reporting for Critical Infrastructure Act, which will require covered entities to report any covered cyber incident to CISA within 72 hours of the time the entity reasonably believes the incident occurred, per the CIRCIA reporting rule. Involve legal counsel in this same window, not after you have already made decisions you cannot undo.

Communicate and Determine Scope

Begin your communication plan with internal staff first, then move to key clients once you understand what is actually affected. Determine scope in parallel: which systems, which data, and which clients are touched by the incident.

Scope determination and communication happen together because you cannot honestly tell a client what happened until you know it yourself.

Assess Backup Integrity

Assess backup integrity for recovery before you commit to a restoration timeline. Two numbers matter here: your recovery point objective (RPO), how much data you can afford to lose, and your recovery time objective (RTO), how long you can afford to be down.

TechProComp’s own backup setup targets a 15 to 60 minute RPO using a 3-2-1 backup strategy with encrypted, immutable copies, the kind of target engineering firms with active Revit projects should be measuring their own backups against.

Days 2-3: Assess Scope and Make the Recovery Decision

By day 2, the emergency posture shifts toward a set of decisions that shape recovery cost and legal exposure for months afterward.

Complete the Scope Assessment and Start Recovery

Complete the scope assessment you started in hour 4: confirm every affected system, dataset, and client relationship. Begin recovery from backups in parallel, building clean infrastructure alongside the investigation rather than waiting for it to finish.

Parallel-building clean infrastructure while forensics continues is what keeps a 30-day recovery from becoming a 90-day one.

Decide on the Ransom Question

The ransom decision uses a five-part test covering backup integrity, the odds payment actually restores your data, the attacker’s sanctions status, the cost of recovering without paying, and what federal guidance recommends. The next section of this playbook walks through each factor in detail.

Do not make this decision alone or under time pressure. It belongs to the Incident Commander, legal counsel, and your insurer together.

Meet Regulatory Notification Deadlines

Texas’s breach notification law sets two clocks. Notify affected residents within 60 days of confirming a breach, and notify the Texas Attorney General within 30 days once 250 or more Texas residents are affected, per a Texas data breach law summary confirmed by a second legal summary.

A federal contract handling Controlled Unclassified Information adds a third clock. The operative clause defines “rapidly report” as “within 72 hours of discovery of any cyber incident,” per the DFARS cyber incident reporting clause. Firms managing overlapping deadlines often lean on outside cybersecurity compliance for engineering firms support.

Communicate With Clients and Staff

Notify affected clients within roughly 72 hours of confirming they are impacted, once your legal counsel has reviewed the notification language. Keep staff communication concise, non-panic, and focused on what changes for them operationally.

An operational continuity plan matters here too: staff need to know which systems are down, which workarounds are in place, and who to ask when something does not work as expected.

Should You Pay the Ransom? A Decision Guide

The FBI’s guidance is not to pay, but the real decision involves more than one rule. Weigh these five factors together before your team commits to a path.

Are Your Backups Verified and Complete?

If your backups are verified clean and complete, the answer is straightforward: restore from them and do not pay. Verified means you have actually tested a recent restore, not just confirmed that a backup job ran.

If your backups are incomplete, contaminated, or untested, move to the next factor before deciding anything.

Will Paying Actually Restore Your Data?

Paying is a weaker bet than most firms assume. In the current Sophos State of Ransomware report, 48% of encrypted victims paid the ransom, in line with the roughly 50% four-year average, while backup-based recovery jumped to 66% of encrypted-data cases, up 12 percentage points from 2025.

Backup-based recovery is now the more common path, not payment. That shift is the strongest argument for testing your backups before you ever need this decision tree.

Is the Attacker a Sanctioned Entity?

Paying a sanctioned entity may be illegal even if you had no way to know it. U.S. persons are “generally prohibited from engaging in transactions, directly or indirectly,” with anyone on the Treasury’s sanctions list, per OFAC’s ransomware advisory.

The liability standard is strict: a company can face civil penalties even when it had no way of knowing the recipient was sanctioned, according to the same advisory. This is precisely why legal counsel needs to be involved before any payment, not after.

Compare the ransom demand against the real cost of recovering without paying: rebuild time, lost billable hours, and client relationships at risk. The FBI states plainly that “[t]he FBI does not support paying a ransom in response to a ransomware attack,” since payment does not guarantee the data comes back, per FBI IC3 guidance.

If a ransom payment is made anyway, federal rules require fast disclosure: covered entities must report any ransom payment made in response to a ransomware attack to CISA within 24 hours after the payment is made, per CIRCIA’s ransom payment rule. Involve legal counsel before any payment decision, never after.

Decision FactorQuestion to AnswerGuidance
Backup integrityAre your backups verified clean and complete?Yes: restore and don’t pay. No: continue to the next factor.
Data recovery likelihoodWill paying actually restore your data?Only 48% of victims paid in 2026, while 66% of cases now recover through backups instead.
Sanctioned-entity statusIs the attacker a sanctioned entity?Paying a sanctioned actor can create civil liability even without knowledge.
Business costWhat does recovery cost without paying?Weigh rebuild time and lost hours against the ransom demand.
Federal and legal guidanceWhat do the FBI, your insurer, and legal counsel say?FBI recommends against paying. Always involve legal counsel before any payment.

Days 4-30: Recover and Harden Your Systems

image gallery of our team techprocomp 16

Recovery is measured in weeks, not days. “Only 18% took more than a month to recover,” a marked improvement from 34% the year before, per Sophos’s State of Ransomware report. Plan staffing and client communication around 30 days as a realistic floor, not a ceiling.

Restore From Clean Backups and Rebuild Systems

Restore priority systems from verified clean backups first, starting with whatever your Incident Commander flagged as business-critical during scope assessment. Rebuild any affected systems that cannot be cleanly restored, rather than trying to disinfect a compromised machine in place.

Reset Credentials and Reissue MFA

Reset every credential with access to the affected environment, not just the accounts you know were compromised. Reissue multi-factor authentication tokens across the board, since a stolen session token can bypass MFA that was never technically broken.

Audit Access Logs for Persistence

Audit access logs across the recovered environment for signs the attacker left a backdoor behind. Ransomware groups increasingly plant persistence mechanisms before triggering encryption so they can return after a rushed recovery.

Run a Lessons-Learned Session and Harden Controls

Run a lessons-learned session with everyone who touched the incident, from the Incident Commander to the forensic firm. Use it to close whatever control gap let the attacker in, not to assign blame.

Control hardening is where firms decide which cybersecurity features that matter most for their specific environment, since the attack vector that worked once is the first one worth closing permanently.

Update Your Insurance Attestation

Update your cyber insurance attestation once recovery and hardening are complete. Insurers often require documentation of the controls you added after an incident before renewing or adjusting a policy.

Engineering-Firm-Specific Considerations

Engineering firms carry data types generic ransomware guides never address. Each one below comes with its own notification obligation on top of the general response timeline.

Revit Central Files and Shared Client Data

Revit central files are shared across an entire project team and often across client organizations too. Recovery depends entirely on backup integrity, since a corrupted central file can take down every linked local file simultaneously, multiplying the damage well beyond a single workstation.

Federal Contract Data (CUI and FCI)

If your firm handles Controlled Unclassified Information under a defense contract, the reporting clock is not optional. Covered defense information includes unclassified technical data and other information that requires safeguarding under applicable law, regulation, and government policy, per the DFARS safeguarding clause. Report to the DoD contracting officer and through the required federal channel within 72 hours of discovery, not 72 hours of full assessment.

ITAR-Controlled Drawings

If ITAR-controlled drawings are compromised, your firm has a duty to inform the State Department’s Directorate of Defense Trade Controls. Initial notification should happen as soon as the violation is discovered, and if that notice does not include every required detail, a full disclosure must follow within 60 calendar days to preserve voluntary-disclosure treatment, per the ITAR voluntary disclosure rule.

TechProComp’s work made the client’s systems operate smoothly and efficiently. – Theo Crawford on Clutch

Firms preparing in advance often review signs your cybersecurity is behind before an incident forces the question.

Client Design Files and Data Processing Agreements

Client design files typically carry their own notification requirement under your firm’s data processing agreements. Check every active client contract for a breach-notification clause, since the deadline in that agreement may be shorter than any regulatory deadline you are already tracking.

Communication Templates You Can Use Now

Six templates cover the communications a ransomware incident forces you to write under pressure. Federal ransomware guidance treats a documented, regularly rehearsed incident communications plan, not an improvised one, as a baseline preparedness practice, per CISA’s StopRansomware Guide. Draft each one now, before an incident, so you are editing instead of writing from scratch during hour one.

Internal Staff Announcement

Keep this concise, non-panic, and action-oriented: what happened in one sentence, what changes for staff today, and who to contact with questions.

Affected Client Notification

This one needs legal review before it goes out. State what was affected, what you are doing about it, and what the client should watch for, in professional and regulatory-compliant language.

Key Client Phone Script

Reserve phone calls for your top clients rather than a mass email. A short script for the CEO covering what happened, what you are doing, and the next update time keeps the call focused.

Regulatory Notification Template (Texas SB 820)

Build this template around the individual and Attorney General notification deadlines above, with placeholders for the exact date of discovery so the 60-day and 30-day clocks are easy to calculate correctly.

Insurance Claim Notification

Draft this with your insurance broker in advance so the notification includes every field your specific policy requires, not a generic summary that triggers follow-up questions and delay.

Public Statement Template

Reserve this one for situations where the breach becomes public. Keep it factual, avoid speculation about scope before your investigation confirms it, and route every version through legal counsel first.

What TechProComp Does in an Active Incident

TechProComp’s 12-layer security framework integrates Endpoint Detection and Response (EDR), LAN Zero Trust, and SOC monitoring to prevent the attack vectors this playbook addresses, backed by SOC 2 certification.

24/7 Emergency Response and Forensic Triage

TechProComp runs a 24/7 emergency response line and begins forensic triage within the first two hours of an active incident. That early triage window is what determines whether containment happens in hours or days. TechProComp’s hybrid model also puts an on-site visit within reach when a physical step, like isolating a compromised Revit file server, needs hands on hardware.

Containment Guidance and Recovery Coordination

TechProComp provides containment guidance through direct MSSP escalation and coordinates recovery across your internal IT, your forensic firm, and your own team, rather than handling only one piece of the response. This is co-managed support, an extension of your existing IT person or MSSP relationship, not a stand-in for it.

TechProComp’s service level and responsiveness are impressive. – Keith Kelley on Clutch

Insurance and Regulatory Notification Support

TechProComp acts as a liaison to your insurance carrier and provides regulatory notification support across the CUI and Texas SB 820 requirements this playbook covers. TechProComp’s published response metrics include a 3-hour critical-issue response guarantee and a 96% same-day resolution rate (as published on techprocomp.com). Founder Slobodan Krsmanovic, who has 25+ years in the IT industry, stays personally involved in incident response relationships with clients.

Techprocomp Team 007

Frequently Asked Questions

What do you do during a ransomware attack?

Isolate affected systems from the network without powering them off, since powering off destroys forensic evidence investigators need. Notify your CEO, COO, IT lead, and MSSP immediately, then bring in your incident response team, including your MSSP, a forensic firm, and legal counsel. Document the detection time and affected systems as you go, since this detect-contain-notify-document sequence is the foundation of engineering firm ransomware recovery and should happen inside the first four hours.

Should I pay the ransom?

The FBI recommends against paying, since payment does not guarantee data recovery and can fund further attacks. Before deciding, verify whether your backups are clean and complete, confirm the attacker is not a sanctioned entity, and weigh the business cost of recovering without payment. If backups are solid, restore from them instead of paying, and if payment is still on the table, involve legal counsel and your cyber insurer first, since paying a sanctioned actor carries legal risk regardless of intent.

Who do I call first during a ransomware attack?

Call your MSSP or managed security provider first, since they can begin containment immediately. If your firm does not have one, call TechProComp’s 24/7 emergency line for Texas engineering firms. After that call, notify your CEO, COO, and internal IT lead so leadership knows within minutes, not hours, since getting the right people moving early shapes how the rest of the incident unfolds.

How do I contain a ransomware attack?

Isolate infected endpoints from the network immediately, but do not power them off, since that destroys the memory-resident evidence forensic investigators need. Disconnect affected file servers and shared storage, including Revit or CAD file servers, and disable VPN access to prevent further lateral movement. Federal containment guidance also recommends taking the network offline at the switch level when multiple systems are affected, and these steps together buy time before your response team fully arrives.

How long does ransomware recovery take?

Initial containment happens in the first four hours, and most engineering firms can begin restoring priority systems from backups within the first week. Full operational recovery, meaning every system, credential, and client-facing process back to normal, typically takes closer to 30 days, and recent industry data puts full recovery timelines even longer in many cases. Plan your staffing and client communications around 30 days, not one day, so you are not caught short.

What is a ransomware response plan?

A ransomware response plan is a documented, phase-by-phase set of actions your team follows from the moment ransomware is detected through full recovery and control hardening. It typically covers the first 4 hours, the following 24, the next 72, and the 30 days after that, with named roles, notification deadlines, and a ransom decision process built in. Texas engineering firms need a plan tailored to their own data, since federal contract data and ITAR drawings carry notification duties general guides skip entirely.

Key Terminology

Ransomware: Malware that encrypts a victim’s files and demands payment for the decryption key. Modern variants often steal data first and threaten to publish it, a tactic known as double extortion.

Incident Commander: The single person with authority to make decisions during a ransomware response, often the Operations Leader at engineering firms without a dedicated CISO. This person coordinates between IT, forensics, legal, and leadership so decisions do not stall.

Chain of Custody: The documented record of who accessed evidence, when, and how, starting the moment ransomware is detected. Courts and cyber insurers may require an intact chain of custody before accepting forensic findings or processing a claim.

RPO (Recovery Point Objective): The maximum amount of data your firm can afford to lose, measured in time since the last clean backup. A 15-minute RPO means losing up to 15 minutes of work, while a 24-hour RPO means losing a full day.

RTO (Recovery Time Objective): The maximum acceptable time between an outage and full system restoration. Engineering firms with active federal contracts often need a shorter RTO than firms without compliance deadlines tied to downtime.

Immutable Backup: A backup copy that cannot be altered, encrypted, or deleted, even by someone with administrator credentials, for a set retention period. Immutable copies let a firm restore clean data even when ransomware has already reached the backup server.

CMMC (Cybersecurity Maturity Model Certification): The Department of Defense’s program for verifying that contractors handling CUI meet required cybersecurity controls. CMMC does not itself set the incident-reporting clock. That obligation comes from the DFARS clause written into the contract.

CUI (Controlled Unclassified Information): Government-related technical or contract data that is not classified but still requires safeguarding under federal contract terms. Engineering drawings, specifications, and technical data tied to a defense contract commonly qualify.

ITAR (International Traffic in Arms Regulations): Federal export-control rules governing defense-related technical data and drawings. Firms whose ITAR-controlled files are compromised have a duty to inform the State Department’s Directorate of Defense Trade Controls.

OFAC Sanctions List: The U.S. Treasury’s Specially Designated Nationals list, naming individuals and entities U.S. persons are barred from paying. Sending ransom to a listed or embargoed actor can trigger civil liability even without knowledge of the sanction.

Talk to TechProComp’s 24/7 emergency response team, or request a free assessment of your ransomware readiness across all 12 security layers.


About the author

Slobodan Krsmanovic, the CEO of TechProComp, brings over 25 years of deep-rooted experience in the IT industry. As the author driving our insightful posts, Slobodan embodies a steadfast commitment to client-centric service, fostering respectful and secure collaborations across all business scales.