More Categories

Ransomware Response: What to Do in the First 24 Hours

If you’re asking what to do after a ransomware attack, do these three things right now: disconnect affected machines from the network (unplug the cable or kill Wi-Fi), do NOT...

10 min read
Cyber insurance requirements for businesses including MFA, EDR, backups, training, and patching

If you’re asking what to do after a ransomware attack, do these three things right now: disconnect affected machines from the network (unplug the cable or kill Wi-Fi), do NOT power them off, and call your IT provider and insurer’s breach hotline before touching anything else. Wiping, rebooting, or “trying one thing” destroys evidence and can make recovery impossible.

Everything below is the hour-by-hour version of that answer. Print it. The worst time to read a response plan for the first time is while the ransom note is on the screen. We’ve walked businesses through these 24 hours, and the difference between the companies that recover in days and the ones that struggle for months is almost entirely decided by the first few moves.

First 60 minutes: contain and preserve

1. Isolate, don’t shut down

Pull the network cable or disable Wi-Fi on every machine showing the note or acting strangely. Isolation stops the spread. Powering off is different and worse: memory contents that forensics teams use to identify the strain and find the entry point vanish the moment the machine loses power, and some ransomware variants corrupt files further on an interrupted encryption run. Isolated and running is the state you want. If you can’t tell which machines are affected, isolating your switches or disconnecting the whole office from the internet is a legitimate blunt instrument for hour one.

2. Protect the backups before anything else

Modern ransomware crews hunt backups deliberately, because deleted backups are what make victims pay. If your backup system has any connection to the network, disconnect or lock it down now, before assessing anything. If your backups are already immutable or offline, this step took ten seconds and probably just saved the company. If this sentence made your stomach drop, that’s tomorrow’s project, and it’s the core of backup and disaster recovery done properly.

3. Start a log

One person, one notebook or phone note. Times, actions, who was called, what was observed. Your insurer, forensics team, and possibly lawyers will ask for this timeline repeatedly. Memory under stress is terrible. Write it down as it happens.

4. Make the two calls

Your IT/security provider first, your cyber insurer’s breach hotline second, ideally within the first hour. The insurer call matters more than most owners realize: policies frequently require prompt notification and carrier approval of the forensics and recovery vendors, and self-directed spending can go unreimbursed. Ask the carrier explicitly which vendors you’re authorized to engage. Then let the professionals run point. This is exactly what incident response support retainers exist for.

Hours 2–8: assess the blast radius

With spread stopped, the questions shift from “make it stop” to “what exactly happened.” Your response team (internal or hired) works through:

Which systems are encrypted, and which are merely exposed? The note might be on three machines while the attacker’s access touched thirty. Every credential used on affected systems should be treated as stolen. Domain admin passwords, Microsoft 365 accounts, banking portals, VPN logins: rotate them from a known-clean device, not from anything inside the affected network.

What strain is it, and is data theft involved? The note itself, file extensions, and memory captures usually identify the family. This matters because most crews now steal data before encrypting, then threaten publication. Whether data left the building changes your legal obligations entirely, which is why the next call is often to a breach attorney, typically arranged through the insurer.

How did they get in? Phishing, an exposed remote desktop port, a VPN appliance missing a patch, a vendor’s compromised account. Recovery without answering this question is how businesses get hit twice in one quarter. We are not exaggerating; repeat victimization of unrepaired entry points is well documented in CISA’s guidance (CISA #StopRansomware).

Our take: resist the overwhelming urge to start restoring in hour three. Restoring onto a network the attacker still has access to hands them your clean copies too. Confirmed containment first, entry point identified and closed, then restoration. The half-day of patience routinely saves a week of doing everything twice.

Hours 8–24: decisions and notifications

The ransom question

The FBI advises against paying, and reports both the practical reasons and the mechanism to file at IC3 (FBI IC3): payment doesn’t guarantee working decryption, marks you as a payer for future targeting, and funds the next wave of attacks. There’s also a legal tripwire many owners don’t know: payments to sanctioned entities can create OFAC liability, which is one more reason this decision runs through the insurer and breach counsel rather than a panicked Zelle-adjacent transaction. In practice, the businesses that never seriously face this decision are the ones whose backups survived. That’s the whole game.

Report it

File with the FBI at IC3 and review CISA’s reporting channels. Beyond civic duty, an official report number is something insurers ask for, and law enforcement occasionally holds decryption keys for specific strains from prior takedowns.

Know your notification clock

If sensitive personal information was accessed, Texas law requires notifying affected individuals within 60 days, and notifying the Texas Attorney General when 250 or more Texans are affected (Tex. Bus. & Com. Code § 521.053, Texas statutes). Healthcare data, financial data, and multi-state customers each add their own regimes. Breach counsel sequences all of this; your job in the first 24 hours is simply not to make statements (to customers, staff, or social media) that counsel hasn’t reviewed. “We’re investigating a network incident and will update you” is a complete sentence.

Begin clean restoration

Once containment is confirmed and the entry point is closed: rebuild from known-good images, restore data from the protected backups, and bring systems back in order of business criticality, scanning as you go. This is where restore testing pays off. A worked example: a 35-person dental group in Frisco we’ll keep anonymous in the details got hit on a Sunday night through a phished login. Their backups were immutable and their last restore test was six weeks old, so the sequence was containment Monday morning, entry point closed by noon, patient scheduling restored Tuesday, full operations Thursday, ransom paid: zero. The identical attack with deletable backups is a different story measured in weeks and five to six figures. Practices like that one are why our IT support in Frisco conversations start with backups before anything shiny.

Talking to your team and customers on day one

Communication is the part of the first 24 hours nobody rehearses, and it’s where otherwise well-run responses create their own second crisis. Three audiences, three different scripts.

Your employees need instructions, not explanations. “Don’t power machines off, don’t log into anything from office computers, forward any strange customer emails to this address, and route all outside questions to [name].” Say less than you’re tempted to. Staff speculation screenshots travel fast, and a text thread saying “we got hacked, everything’s gone” will reach a customer before your official statement does.

Your customers get contacted when there’s something accurate to say, through one designated voice. If systems they interact with are down, a short, honest note beats silence: service interruption, being addressed, updates coming. What you must not do is state “no data was accessed” before forensics can support it. Companies get held to those early sentences later, by regulators and by plaintiffs’ lawyers, and walking back a false reassurance costs more trust than the incident itself.

Your bank deserves a same-day call whenever business email or finance workstations are in scope. Ask them to flag the account for verbal confirmation on outgoing wires and ACH changes for the next few weeks. Attackers who’ve read your email know your payment rhythms, and the fraud attempt often comes after the visible incident, aimed at a distracted office.

What to do after a ransomware attack: the 24-hour checklist

WindowDoDon’t
0–1 hrIsolate machines, protect backups, start log, call IT + insurerPower off, wipe, reboot, pay, email the whole company
2–8 hrRotate credentials from clean device, identify strain + entry point, engage forensics via carrierStart restoring before containment is confirmed
8–24 hrFile IC3 report, loop in breach counsel, plan notification clock, begin clean restore by priorityMake public statements counsel hasn’t seen

How to prevent ransomware from getting this far

The honest answer is that prevention is cheaper than every line item above by an order of magnitude. The stack that stops most of these incidents: MFA on everything, EDR with someone watching it (here’s how 24/7 detection catches attacks before encryption, during the hours-to-days attackers spend inside before pulling the trigger), immutable and tested backups, patched edge devices, and trained employees. Each layer is covered in the full owner’s security playbook.

Two planning concepts turn “we have backups” into “we’ll be fine.” First, backup and disaster recovery are different disciplines: one is a copy of your data, the other is a rehearsed plan for running the business while systems come back, and confusing them is how companies with backups still lose a week.  Second, put numbers on your tolerance before you need them: how many hours of downtime can you absorb, and how much recent work can you afford to re-create? Those two figures, your recovery time and recovery point objectives, decide what your backup architecture should look like and what it should cost.  A dental practice that can’t lose a day of charts and a landscaping company that can run from paper for a week should not be buying the same recovery setup, and shouldn’t be paying the same for it either.

If it were our building: the two controls we’d fund before any others are immutable backups with a monthly tested restore, and monitored detection. The first makes the ransom demand irrelevant. The second usually means there’s never a ransom note at all, because the 2 a.m. foothold gets cut off at 2:09.

Frequently Asked Questions

What should you do immediately after a ransomware attack?
Disconnect affected machines from the network without powering them off, cut any network path to your backup systems, start a written timeline, and call your IT provider and cyber insurer’s breach hotline. Don’t wipe, reboot, or pay anything before forensics and your carrier are engaged.
Should you turn off your computer during a ransomware attack?
No. Disconnect it from the network but leave it powered on. Shutting down erases the memory evidence forensics teams use to identify the strain and entry point, and interrupting some variants mid-encryption can corrupt files beyond recovery. Isolated-but-running is the correct state.
Should a business pay the ransomware ransom?
The FBI advises against paying: decryption isn’t guaranteed, payment funds future attacks, and paying can even create sanctions liability if the crew is a designated entity. Run the decision through your insurer and breach counsel. Businesses with intact, tested backups rarely face the question at all.
Do you have to report a ransomware attack in Texas?
If sensitive personal information was accessed, Texas requires notifying affected individuals within 60 days and the Texas Attorney General when 250 or more Texans are involved. Federal reporting to the FBI’s IC3 is strongly encouraged, and regulated industries like healthcare carry additional notification duties.
How long does ransomware recovery take?
With immutable, recently tested backups and a known entry point, core systems commonly return in two to five days. Without survivable backups, recovery stretches to weeks and may involve negotiation, and some data typically stays lost either way. Backup quality is the single biggest predictor of downtime.

The best day to pressure-test your ransomware plan is any day you’re not living it. Ask our team for a free recovery-readiness review through our incident response support page, and we’ll tell you plainly whether your backups would survive contact.

 

Share:

Table of Contents

Related Post