Ransomware Response for Rural ISPs: What to Do in the First 72 Hours

When ransomware hits a rural ISP, the impact isn't measured in inconvenience — it's measured in communities losing internet access during fire evacuations, farms losing SCADA connectivity, and 911 centers losing data systems. Here's how to respond when it happens.

Rural ISPs and small telecom operators are among the most consequential ransomware targets in America — yet they're consistently among the least prepared for incident response. The downstream effects of a rural ISP going offline extend far beyond the business itself: agricultural operations lose remote monitoring, small businesses lose connectivity during their peak season, and in fire country like Central Oregon, a connectivity outage during an active fire event is genuinely dangerous.

Why Rural Telecom Operators Are Prime Ransomware Targets

Rural ISPs combine the worst aspects of high-value target and low-defense posture. They serve critical infrastructure — often including rural hospitals, tribal governments, 911 dispatch centers, and public schools — which creates significant pressure to pay ransoms quickly to restore services. At the same time, they typically have small IT teams, limited security budgets, aging management systems, and sometimes no written incident response plan at all.

CISA and FBI have documented multiple ransomware campaigns in 2025–2026 specifically targeting rural broadband providers, rural electric cooperatives, and municipal utility networks — all for the same reason: critical dependencies, high ransom motivation, and limited defenses. The days when ransomware groups focused exclusively on large enterprises are long past. Automated scanning finds vulnerable systems regardless of company size, and a rural ISP with 3,000 subscribers represents a meaningful ransom opportunity if those subscribers are dependent enough on service to pressure the operator to pay.

Hour 0–4: Stop the Bleeding

The first priority in any ransomware event is containment — stopping the spread before more systems are encrypted. Every minute of delay during active encryption is more data lost and more systems compromised.

Isolate affected systems immediately: The moment ransomware is detected — usually by someone seeing encrypted files, a ransom note, or anomalous behavior — the affected system must be isolated from the network. Pull the network cable. Disable the switch port. Shut down the Wi-Fi access point it's connected to. Do not simply power off the machine without network isolation first — some ransomware variants have mechanisms that trigger on shutdown, and you want to preserve forensic evidence while cutting the network path.

Don't trust your own network: Assume that any system that had network access to the initially infected machine may also be compromised. Most modern ransomware performs lateral movement — spreading from the initial infected host to other reachable systems — before triggering the visible encryption phase. The ransomware you're seeing may have been in your network for days or weeks. The visible encryption event is the end of the attack, not the beginning.

Preserve evidence before touching anything: Take photos of ransom notes, error messages, and affected screens. Export available logs from systems that are still accessible — firewall logs, authentication logs, email server logs. This evidence matters for the FBI report, insurance claims, and understanding how the attacker got in. Do not wipe and rebuild systems before forensics are complete.

Call your incident response contacts: If you don't have a retainer with a cybersecurity incident response firm, call CISA (1-888-282-0870) immediately. CISA provides free technical assistance to critical infrastructure operators including rural ISPs. If you have cyber insurance, call your insurer's breach hotline — they typically have IR firm relationships and the clock starts on their coverage obligations the moment you report.

The single most common mistake in ransomware response is not calling for help fast enough. Operators try to handle it internally, spend 48 hours attempting to restore from backups that may themselves be compromised, and lose critical forensic evidence in the process. Call CISA and your insurer immediately.

Hour 4–24: Assess and Communicate

Once initial containment is underway, the focus shifts to understanding the scope of the compromise and managing communications.

Map the blast radius: Work with your incident response support to identify which systems are confirmed compromised, which are potentially compromised, and which are clean and can continue operating. This typically involves reviewing authentication logs, network flow data, and endpoint detection telemetry. For rural ISPs without endpoint detection deployed, this process is much harder and slower — another argument for deploying EDR before an incident.

Assess backup integrity: Before attempting to restore from backups, verify that your backups are clean. Modern ransomware routinely targets backup systems first — deleting Volume Shadow Copies, encrypting NAS backup shares, and hitting cloud sync destinations that contain encrypted versions of the original files. An offline, air-gapped backup that was last verified within the past 30 days is what you're looking for. If your only backups are on network-accessible shares, assume they're compromised until proven otherwise.

Communicate with affected parties: Your subscribers, your partner agencies, and your upstream providers all need to know what's happening. Be honest about the situation. Rural communities are tight-knit — they'll know something is wrong before you announce it. A transparent communication that says "we've had a cybersecurity incident, we're working to restore service, here's what we know, here's our estimated timeline" is far better received than silence followed by a delayed admission. Tribal governments, rural hospitals, and public safety agencies that depend on your network need to activate their contingency plans, and they can't do that without information.

File the FBI report: Report ransomware incidents to the FBI Internet Crime Complaint Center (IC3.gov) immediately. This is separate from the CISA report. The FBI collects data on ransomware groups and in some cases has decryption keys for specific ransomware variants — filing the report is a prerequisite for accessing that assistance. Several rural operators have recovered without paying ransom because the FBI had decryption tools for the specific variant they were hit with.

Hour 24–72: Recovery

Recovery from ransomware without paying the ransom is possible if backups are intact — but it takes time and discipline. The typical rural ISP recovery sequence:

  • Rebuild core infrastructure first: RADIUS/AAA, DHCP/DNS, network management, and billing systems are the operational backbone. Restore these from verified clean backups to a clean network segment that is isolated from the potentially-compromised production environment until you're confident in its security.
  • Restore subscriber management: Subscriber database, provisioning system, and billing records. If your subscriber database backup is clean, subscriber service can often be restored relatively quickly even if other systems remain offline.
  • Harden before reconnecting: Every system restored from backup must be hardened before it's connected back to the production network — default credentials changed, patches applied, unnecessary services disabled, and endpoint protection installed. Restoring a vulnerable system to the network before hardening it invites reinfection.
  • Restore other business systems in priority order: Email, accounting, HR, and other back-office systems follow after core network operations are restored.

Recovery timelines vary enormously. With clean backups, clear documentation of your systems, and experienced IR support, a rural ISP can restore core operations in 48–96 hours. Without clean backups or documentation, recovery can take weeks.

Building the Incident Response Plan Before You Need It

The time to build an incident response plan is not during an active incident. Oregon and Alaska rural ISPs should have a written IR plan that covers:

  • Defined roles: who makes the call to isolate systems, who calls the insurer, who communicates with subscribers
  • Contact list: CISA (1-888-282-0870), FBI IC3 (ic3.gov), cyber insurer breach hotline, IR firm retainer
  • Backup verification schedule: when backups were last tested and confirmed clean
  • Offline backup location: where the air-gapped backup is and who has access
  • Subscriber communication template: pre-drafted language for a service outage notification
  • Upstream provider contacts: transit and peering partners to notify if you anticipate extended downtime

CISA publishes free incident response plan templates specifically for small and rural critical infrastructure operators — available at cisa.gov/resources-tools/resources/cyber-incident-response. Oregon's Office of Emergency Management and the Alaska Division of Homeland Security also have resources for small telecom operators.

Cybersecurity for Rural Telecom Operators

Richesin Engineering provides cybersecurity assessments, incident response planning, and managed security services for rural ISPs, tribal networks, and telecom operators across Oregon, Alaska, and Hawaii. Don't wait for an incident to find the gaps.

Learn More

Questions about this topic? Contact our engineering team for a free consultation.