Back to Blog
Guides

The First 60 Minutes of a Ransomware Attack on a McKinney Business

A ransomware attack is won or lost in the first hour. Here is the minute by minute response plan for McKinney and Collin County businesses, and who you actually call at 2am.

By Mark Sullivan Aug 10, 2026 2 views
ransomwareincident responsemckinneycollin county
Share:

The call almost never comes at a convenient hour. A property management company off Eldorado Parkway had a bookkeeper log in at 7:42 on a Tuesday morning, and instead of the accounting dashboard she saw a plain text file sitting where her shortcut used to be. Every file on the shared drive had picked up a new extension overnight. The server was still running. The internet still worked. Nothing looked broken in the way people expect broken to look.

That is the strange part about ransomware, which is an attack where criminals scramble your files with encryption and then demand payment for the key that unscrambles them. It does not arrive with sparks and sirens. It arrives as a quiet note and a countdown, and by the time somebody reads that note the attacker has usually been living inside the network for weeks.

What you do in the next sixty minutes will matter more than anything you do in the following sixty days. We published this timeline for Fort Worth businesses earlier this month and it became the most read piece on this site, which told us something useful. Owners do not want a lecture on threat actors. They want to know what to do with their hands in the first hour. So here is the version for McKinney and Collin County, where the answer to "who do I call at two in the morning" is genuinely different than it is an hour west.

What the First Sixty Minutes Actually Looks Like

Forget the movie version. There is no red progress bar. In almost every case we have worked in North Texas, the first hour looks like confusion, not crisis. One person cannot open a spreadsheet. Someone else assumes the network is slow. A manager reboots a workstation because rebooting usually helps. Ten minutes later a second person cannot open a file either, and somebody finally says the thing out loud.

That confusion is expensive, and it is the part you can fix cheaply. The encryption itself is often finished before anyone notices, but the spread is not. Ransomware moves from machine to machine using the same file shares and administrative accounts your staff use every day, and it keeps moving while people are still deciding whether this is a real problem. A twenty minute delay in a twelve person firm in Allen is the difference between losing one server and losing the backups too.

So the first decision is not technical. It is permission. Every person in your company needs to already know that they are allowed to declare an emergency without being sure, and without asking a manager first. If your staff believes they will look foolish for raising a false alarm, they will wait, and waiting is the single most expensive habit in this entire timeline. Tell them plainly that a false alarm costs nothing and a delayed alarm costs everything.

Minutes One Through Ten, Stop the Spread

The first goal is not to fix anything. It is to make the problem stop getting bigger. Disconnect affected machines from the network, which in practice means unplugging the network cable and turning off the wireless connection on that device. Do not power the machine off if you can avoid it, because shutting down destroys evidence sitting in memory that a responder can use to identify what got in and whether it is still running elsewhere.

If more than one machine is affected, or if a server is affected, disconnect the internet connection for the whole office rather than chasing individual computers. Losing an hour of email is a smaller loss than losing your file server. This is also the moment to physically disconnect any backup drive that is plugged in, because modern ransomware specifically hunts for backups. Attackers know that a company with clean backups does not pay, so destroying the backups is part of the job, not an accident.

Next, stop the money. Call your bank and your payroll provider on a phone, not by email, and place a verbal hold on outgoing transfers until further notice. Ransomware crews frequently pair encryption with wire fraud, because a finance team in the middle of a crisis approves payments it would normally question. We wrote about that pattern in detail in our guide to business email compromise, and it shows up in Collin County far more often than the encryption stories that make the news.

Finally, start writing things down. Time, who saw what, which machine, what the note said. A cheap notebook is fine. Your insurance carrier will ask for this timeline, and a reconstructed guess is worth far less to them than notes taken in the moment.

Minutes Ten Through Thirty, Protect What Is Still Clean

By now you have stopped the bleeding. The next twenty minutes are about protecting what the attacker has not reached yet, and that work is mostly about accounts rather than computers.

Force a password reset on every administrative account, and do it from a device you believe is clean. If the attacker got in through a stolen login, and most of them do, then resetting passwords is the only thing that actually closes the door. Turn on multi-factor authentication, which is the second step that texts or prompts you after a password, on any account that does not have it, starting with email and remote access. If you are not sure which accounts already have it, that uncertainty is itself a finding worth acting on once the dust settles, and it is exactly the sort of gap a security assessment is meant to surface before an incident rather than during one.

Then check your email tenant specifically. Attackers routinely create forwarding rules that quietly copy every incoming message to an outside address, and those rules survive password changes because they are settings, not credentials. Look for rules you did not create, and delete them. Our team hardened the guidance on this in our email security work because it is the most commonly missed step in the entire first hour.

Do not restore from backup yet. This is the most common expensive mistake we see. Restoring into a network where the attacker still has access simply hands them a fresh copy of your data to encrypt again, and it overwrites the forensic picture that tells you how they got in. Verify your backups exist and are readable, then leave them alone until someone has confirmed the network is clean.

Minutes Thirty Through Sixty, Make the Calls That Have Deadlines

The last half hour belongs to the people who need to be told, and some of those notifications carry legal clocks that start ticking whether or not you know about them.

Call your cyber insurance carrier before you call anyone else outside the company. Nearly every policy written for North Texas businesses requires you to notify the carrier promptly and to use their approved response vendors, and hiring your own consultant first is one of the more reliable ways to reduce or void a claim. The carrier will usually connect you to a breach coach, which is an attorney who runs the legal side of the response, within the hour. If you do not know where your policy number is right now, find it today and tape it inside a cabinet, because searching a shared drive you cannot open is not a plan.

Then engage a responder. If you have a relationship in place, that call is short. If you do not, this is where companies lose four to six hours shopping for help while the damage compounds, which is the argument for arranging incident response coverage before you need it rather than during. Retainers are inexpensive relative to the downtime they prevent, and the value is not the discount, it is that somebody already knows your network at two in the morning.

Regulatory clocks depend on what you hold. If you handle patient information, the federal health privacy rules are already running. If you take card payments, your merchant agreement almost certainly obligates you to notify the processor. Texas requires notification to affected residents without unreasonable delay and, when the incident touches at least two hundred and fifty Texans, notification to the Attorney General within thirty days. Those deadlines are why a compliance review is worth doing while nothing is on fire, and why guessing at them during hour one is a poor use of the hour.

Who You Actually Call at Two in the Morning in Collin County

This is the part the national checklists skip, and it is the reason a local answer matters.

The McKinney Police Department takes reports and will document the crime, which your insurer will want, but a municipal police department is not going to do forensics on your domain controller. Federal reporting goes to the FBI through the Internet Crime Complaint Center, and the Dallas field office covers Collin County. File the report, understand that it helps the broader case against the group rather than your Tuesday, and move on.

The practical answer is that at two in the morning you are calling three numbers. Your insurance carrier's twenty four hour claims line, your incident response provider, and your own leadership. Everyone else can wait until business hours. Write those three numbers on paper and put a copy at each site, because a contact list that lives only in the email system you just disconnected is not a contact list.

Distance matters more than people expect. A responder who can physically stand in your server room in Plano, Frisco, or McKinney within the hour can pull drives, image machines, and confirm containment in a way that a remote vendor working through a video call cannot. When a national firm quotes you a response window, ask where the person is flying from. Ours is a short drive up Highway 5, and on the night it matters that is not a marketing detail.

If you already have a managed IT provider, find out tonight whether their contract covers security incidents or only uptime. Many do not, and the discovery usually happens at the worst possible moment. We work alongside existing providers through our MSP integration practice specifically so that owners do not have to fire anyone to close that gap.

The Bill Shows Up Long After the Attack

The ransom is rarely the largest number. For a thirty person business in Collin County, a straightforward ransomware event with usable backups runs somewhere between four and seven days of degraded operations, and that is the number that actually hurts. Payroll still runs. Rent is still due. Your team still comes in and cannot bill anything.

Then come the costs nobody budgets for. Legal review of notification obligations. Credit monitoring for affected customers if personal data was taken. Overtime for the staff rebuilding records by hand. A cyber insurance renewal that comes back higher, or with a new requirement that you carry monitoring you did not have before. Customers who quietly do not renew and never tell you why, which is the loss that never appears on any invoice and is usually the biggest one.

Attackers also steal data before they encrypt it now, which changes the calculation entirely. Clean backups solve the availability problem and do nothing about the extortion problem, because the threat becomes publication rather than deletion. That stolen data frequently surfaces on criminal marketplaces weeks before anyone in the company knows, which is the entire argument for dark web monitoring as an early warning rather than a report you read after the fact.

What to Put in Place Before the Clock Ever Starts

Every action above gets faster if the work happens before the incident. Four things carry most of the weight.

Test a restore, not a backup. Backups that have never been restored are a hope, not a control. Pick one Saturday a quarter, restore a real folder to a real machine, and time it. The number you get is your actual recovery time, and if it is longer than your business can survive, you have found the problem while it is still cheap to fix. Our guide on why recovery plans fail without tested backups walks through what a real test looks like.

Know what is exposed. Regular vulnerability scanning tells you which of your systems are reachable from the internet and unpatched, which is how a large share of these attacks begin. A penetration test, where a hired expert tries to break in on purpose to find the gaps first, tells you what someone would actually do with those weaknesses. Both are cheaper than a single day of downtime, and our CyberOne platform exists to keep that picture current instead of annual.

Have someone watching overnight. Most ransomware detonates between midnight and four in the morning, on a holiday weekend when nobody is looking. That is not bad luck, it is targeting. A managed security operations center, which is a staffed team that watches your systems around the clock rather than software that emails an alert into an empty inbox, is what turns a sixty minute response into a six minute one.

Write the plan down and practice it once. One page. Who declares the emergency, who unplugs what, which three numbers get called, where the insurance policy lives. Read it aloud in a staff meeting for fifteen minutes once a year. That single exercise does more for your response time than most of the technology you could buy, and our first 24 hours guide covers what happens after the hour this article describes.

Get Your First Sixty Minutes on Paper

If you cannot say right now who in your company is allowed to unplug the server, or where your cyber policy number is written down, you do not have a plan yet. You have an intention. The gap between those two things is measured in downtime hours.

Innovation Network Design is based in McKinney and works with businesses across Collin County and the wider DFW area. We will sit down with you, walk your actual environment, and help you build the one page version of this timeline with your names and your numbers in it, before you need it. Start with a security assessment or reach us through our contact page, and if something is happening right now, call 512-518-4408 and ask for incident response.

Need Help With This?

Innovation Network Design helps businesses across McKinney, Dallas, and nationwide with expert cybersecurity services.

M

Mark Sullivan

Innovation Network Design

With nearly a decade in cybersecurity and IT infrastructure, our team delivers expert insights to help businesses in McKinney, Dallas, and across DFW make informed security decisions. Have a question? Get in touch.

Ready to Secure Your Business?

Get a free security assessment and find out where your organization stands.