
Ransomware attack response starts the moment you see the ransom note, not after you’ve lost a week of project schedules or payroll records. When Kruse Construction recently fell victim to the Akira ransomware gang, sensitive corporate and employee data leaked online because the response window closed before containment could happen. For construction firms running on tight margins, every hour of downtime means missed deadlines, idle crews, and clients questioning whether their project data is safe.
What should you do in the first hour after discovering ransomware?
Your first hour determines whether you lose three days of work or three months of trust. Immediately disconnect the infected device from your network. Pull the ethernet cable, disable Wi-Fi, turn off network shares. Ransomware spreads by finding other computers, servers, and especially backup drives connected to your system.
Do not shut down the computer yet. Powering off can sometimes trigger encryption to accelerate or destroy forensic evidence your IT team (or law enforcement) will need. Instead, photograph the ransom screen with your phone. Capture the wallet address, the contact method, and the countdown timer if one exists. This evidence matters for insurance claims and FBI reporting.
Next, notify your IT contact or managed service provider immediately. If you’re handling IT in-house, loop in whoever manages your backups and your cyber insurance broker. The clock is ticking, and most policies require notification within 24 hours to maintain coverage.
How do you stop ransomware from spreading to other systems?
Isolation is everything. After the first infected machine is disconnected, audit every device that shares your network. Construction firms often overlook field tablets, job-site laptops, and mobile hotspots that sync project plans or timesheets.
If you have a server (physical or cloud), check whether ransomware has already jumped there. Look for unusual file extensions (.akira, .locked, random strings), missing files, or system slowdowns. Akira and similar gangs move laterally through networks in minutes, encrypting everything they touch.
Disable remote access tools (Remote Desktop Protocol, VPNs) until you confirm they weren’t the entry point. Weak or reused passwords on RDP are the number one way ransomware gets into construction companies. If your crew uses the same login for the office and the field, you’ve handed attackers a universal key.
Check your backups now, not later. Verify that your most recent backup is offline (tape, external drive stored off-site, or immutable cloud storage). Ransomware hunts for backups first. If your backup drive was mounted and connected, assume it’s encrypted too.
Should you pay the ransom or try to recover from backups?
Paying ransom is a business decision, not a technical one, and it’s almost always the wrong choice. Even if you pay, there’s no guarantee you’ll get a working decryption key. The FBI and CISA (Cybersecurity and Infrastructure Security Agency) both recommend against payment because it funds future attacks and marks your firm as someone who pays.
If you have verified, offline backups, recovery is slower but safer. Expect 24 to 72 hours to rebuild servers, restore files, and validate data integrity. During that window, your team can work on paper, use mobile apps offline, or shift to manual processes. It’s painful, but it’s finite.
If you don’t have backups (or they’re encrypted too), you face a harder choice. Engage a ransomware negotiation firm or forensic recovery service before making any payment. They can sometimes recover files without paying or negotiate the ransom down by 40-60%. Document everything for your cyber insurance claim, which may cover some or all of the cost.
Remember that paying ransom doesn’t erase the breach. Akira and other gangs exfiltrate (steal) your data before encrypting it. Even if you decrypt your files, they still have your employee Social Security numbers, client contracts, and bid documents. You’ll still need to notify affected parties and potentially face regulatory consequences under state breach laws.
Who do you need to notify after a ransomware attack?
Notification isn’t optional. If personal data was accessed (employee records, client information, subcontractor details), most states require you to notify affected individuals within 30 to 90 days. Connecticut, for example, mandates notification without unreasonable delay.
Start with your internal stakeholders: executive team, project managers, HR, and finance. They need to know which systems are down, how long recovery will take, and what data may be compromised.
Next, notify clients and subcontractors whose data you handle. A simple, honest message works: “We experienced a cybersecurity incident on [date]. We are working with forensic experts to determine what data was accessed. We will update you within [timeframe] and provide resources if your information was involved.” Silence breeds distrust. Transparency, even when the news is bad, preserves relationships.
Report the attack to the FBI via the Internet Crime Complaint Center (IC3) and to CISA. This isn’t just for large companies. Federal agencies track ransomware trends, and your report can help them disrupt future attacks or issue decryption tools. Plus, some cyber insurance policies require law enforcement reporting to process claims.
If you hold certain certifications (ISO, CMMC for defense contractors, or compliance frameworks like the FTC Safeguards Rule for financial data), you may have additional reporting deadlines. Miss those, and you risk losing certifications or facing fines on top of recovery costs.
How do you prevent the next ransomware attack?
Once you’ve recovered, the hard work begins. Ransomware isn’t a one-time event; it’s a symptom of gaps in your defenses. Start with the basics: multi-factor authentication (MFA) on every login, especially email and remote access. If Akira got in through a stolen password, MFA would have stopped them cold.
Segment your network. Your accounting software doesn’t need to talk to your job-site project management tool. If ransomware hits one system, segmentation keeps it from hitting everything. For construction firms, this often means separating office networks from field devices and isolating backup storage.
Test your backups monthly. A backup you haven’t tested is a hope, not a plan. Run a restore drill: pick a random file or folder, restore it from backup, and confirm it opens correctly. Time the process. If it takes six hours to restore one folder, you’ll need days or weeks to restore your entire operation.
Train your team to recognize phishing emails. Ransomware often arrives via a malicious link or attachment disguised as an invoice, delivery notice, or contract update. Run quarterly simulated phishing tests and reward (don’t punish) employees who report suspicious messages.
Finally, document your ransomware attack response plan before you need it. Who do you call first? Where are the backup passwords stored? What’s the phone number for your cyber insurance broker? When you’re staring at a ransom screen at 6 a.m., you won’t remember. A one-page checklist can save days of confusion.
What does a ransomware attack cost a construction firm?
Direct costs include ransom payments (if you choose to pay), forensic investigation fees, legal notifications, credit monitoring for affected individuals, and IT recovery labor. For a mid-sized construction company, these can easily reach $100,000 to $500,000.
Indirect costs hurt worse: lost productivity while systems are down, delayed projects triggering penalty clauses, reputational damage that costs you the next bid, and increased cyber insurance premiums (expect 20-40% hikes after a claim). One contractor we spoke with lost a $2 million municipal contract because they couldn’t demonstrate adequate cybersecurity controls after a breach.
Regulatory fines add another layer. If you handle data subject to HIPAA (employee health records), the FTC Safeguards Rule (financial information), or state breach laws and you fail to notify on time or demonstrate reasonable security, fines can reach tens of thousands per violation.
The hidden cost is opportunity. Every hour your team spends on recovery is an hour not spent estimating, managing projects, or building client relationships. For firms operating on 3-5% net margins, that lost time can turn a profitable quarter into a loss.
Do small construction firms really need a formal incident response plan?
Yes, because you can’t afford not to have one. Incident response isn’t about the size of your company; it’s about the speed of your reaction. Kruse Construction, a small to mid-sized firm, learned this the hard way when Akira published their stolen data online.
A formal plan doesn’t mean hiring a full-time security team. It means writing down, in plain language, what happens when something goes wrong. Who unplugs the server? Who calls the insurance company? Who talks to clients? When everyone knows their role, you cut response time from hours to minutes.
Your plan should include contact information for your IT provider or MSP, your cyber insurance broker, a forensic incident response firm (get quotes now, not during an emergency), and your attorney. It should list where backups are stored, how to access them, and who has the decryption keys or passwords.
Review the plan twice a year. Technology changes, staff turns over, and new threats emerge. A plan written in 2022 probably doesn’t account for AI-powered phishing or supply chain attacks targeting construction software vendors.
If you’re not sure where to start, model your plan on the NIST Cybersecurity Framework or the CISA Cyber Essentials guide. Both are free, written for non-technical audiences, and designed for small and mid-sized businesses. Your managed service provider can help you adapt them to your specific tools and workflows.
Keep reading
- cybersecurity breach risks facing construction firms
- construction and real estate cybersecurity
- IT downtime and business disruption
Sources
Source: Akira has just published a new victim: Kruse Construction