Regulatory Note: OCR fines and state AG investigations can follow a single patient complaint or breach notification. Compliance is not optional.
If ransomware is running in your environment: call immediately — do not restart, do not pay. If you're assessing your preparedness: book a ransomware readiness assessment and find out whether your backup is truly immutable, whether your EDR would stop encryption mid-execution, and what your notification obligations would be if an incident occurred today.
No disruption. No lengthy onboarding. A fast, smooth transition to a partner that has your back from day one.
For active incidents: immediate containment response — call 866-710-0308. For preparedness: a ransomware readiness assessment audits your backup architecture (is it truly immutable?), EDR coverage, network segmentation, and notification obligations — and identifies exactly what recovery would look like if ransomware hit today.
For active incidents: full incident response — containment, forensic assessment, recovery, notification coordination, and post-recovery hardening. For preparedness: implement immutable backup, EDR, network segmentation, and the controls that make recovery without payment possible.
Our engineers deploy, configure, and meet your team — typically live within 1–2 weeks without disrupting daily operations.
Post-recovery or post-implementation: enrollment in the managed security program — 24/7 SOC monitoring, continuous EDR, immutable backup with tested recovery, and quarterly security reviews — so ransomware is stopped before it encrypts, and recovery is possible without payment if it isn't.
Immediately: disconnect affected systems from the network — unplug the network cable or disable Wi-Fi, do not restart the computer. Do not pay the ransom demand. Do not delete the ransom note — it contains information needed for forensic assessment and insurance claims. Call Gradius at 866-710-0308 for immediate incident response. If you have cyber insurance, notify your carrier as soon as possible — most policies have timely notification requirements. Do not attempt to decrypt files yourself or use untrusted decryption tools. The steps taken in the first hour of a ransomware incident significantly affect the recovery outcome — getting experienced incident responders engaged immediately is the most important action after containment.
Yes — but only if the right infrastructure was in place before the attack. Immutable backup that was not connected to the compromised network and cannot be encrypted by the ransomware is the primary path to full recovery without payment. If immutable backup exists and is intact, recovery is a matter of restoring from that backup after the environment is cleaned. If standard backup was connected to the network and was encrypted along with everything else, options are more limited — partial recovery from cloud sync history, shadow copy restoration (if not deleted by the ransomware), or working with the attacker. Gradius implements immutable backup before incidents occur to ensure the no-ransom recovery path exists. For businesses that don't have it when an attack hits, we assess what recovery options remain.
Yes, in many circumstances. HIPAA requires covered entities to treat ransomware as a presumptive breach — unless a risk assessment demonstrates a low probability that PHI was acquired or viewed, it must be reported as a breach. This means HIPAA-covered healthcare organizations must notify affected individuals, HHS, and potentially media after a ransomware incident. NJ, NY, and CT each have state data breach notification laws that are triggered if personal information was accessed or potentially accessed. The SEC requires registered investment advisors to report material cybersecurity incidents within defined timeframes. Cyber insurance carriers require timely notification as a condition of coverage. The notification obligations triggered by a ransomware incident depend on what data was in the affected systems — Gradius identifies and coordinates all applicable obligations as part of incident response.
The general guidance from CISA, the FBI, and most cybersecurity professionals is: do not pay the ransom. Reasons: payment does not guarantee file recovery — decryption keys provided by attackers frequently fail to decrypt all files or work unreliably; payment funds criminal operations and incentivizes further attacks against your organization and others; paying a ransom to certain threat actors may violate OFAC sanctions and create legal liability; and payment does not address the security gaps that allowed the attack — unresolved gaps mean reinfection is likely. The cases where payment becomes a consideration are those where no backup exists and the encrypted data is existential to the business. The right answer is to never be in that situation — which requires immutable backup before an incident. Gradius does not negotiate with ransomware actors on behalf of clients, but does help businesses understand their recovery options honestly.
Ransomware resilience requires five controls working together: immutable backup that the ransomware cannot reach or encrypt (the most critical — without this, paying is often the only option); EDR on every device that detects and stops encryption behavior before it completes (reduces the impact of a successful initial access); network segmentation that limits lateral spread (reduces the number of systems encrypted if ransomware does execute); MFA on all systems to prevent credential-based initial access (stops a common ransomware delivery vector); and email security that stops phishing delivery (stops the most common initial access method). A ransomware readiness assessment from Gradius evaluates whether all five controls are in place and functioning correctly — and identifies the specific gaps that would affect your recovery options if an attack occurred today.
No long-term lock-ins for the managed security program. We offer month-to-month and annual agreements. Active incident response is engaged as needed — there's no requirement to be a managed IT client to receive incident response assistance, though managed IT clients receive priority response. Post-incident, most businesses enroll in the managed security program to maintain the hardened posture — preventing reinfection is far less expensive than recovering from a second incident.
Gradius IT Solutions serves businesses throughout the Tri-State area. Headquartered in Hackensack, NJ with coverage across Bergen, Hudson, Passaic, Essex, Union, Morris, Middlesex, Somerset, Sussex, Westchester, Rockland, and Fairfield Counties.