Skip to content
Digital Security Consulting

The First Hour of a Ransomware Attack: What to Do

What to do in the first sixty minutes of a ransomware incident — and the three common reactions that destroy evidence or make recovery harder.

Published 3 min read

Ransomware is unusual among IT emergencies in that the first hour meaningfully changes the outcome — and the instinctive reactions are frequently the wrong ones.

This is the sequence we walk clients through.

1. Disconnect. Do not power off.

Pull the network cable, or disable the wireless adapter, on every affected machine. This stops encryption spreading to network shares and other hosts.

Do not shut the machine down. This is the single most common damaging mistake. Volatile memory often holds encryption keys, active process details, network connections and other forensic evidence. Some ransomware families have been decrypted precisely because keys were recovered from memory. Shutdown destroys that permanently.

Isolation stops the bleeding. Power-off throws away the chart.

2. Do not delete anything

Not the ransom note, not the suspicious files, not the strange scheduled task, not the unfamiliar admin account.

Everything is evidence. It establishes how they got in, how long they were inside, and what they accessed. You will need that for your insurer, for legal obligations under Law 25, and for making sure the same door is not still open when you restore.

3. Do not restore yet

The instinct is to get back up immediately. Restoring into a compromised environment usually means re-encryption within days, because the attacker’s access persists.

Scope first, eradicate second, restore third. In that order.

4. Assume credentials are compromised

By the time ransomware deploys, attackers have typically been inside for days or weeks and have harvested credentials. Assume every password in the blast radius is known — including service accounts, saved browser credentials, and anything reused personally.

Rotation happens as part of eradication, not before scoping, or you tip off an attacker who still has access.

5. Check whether backups are actually isolated

Find out now whether your backups were reachable from the compromised network. If they were on a mapped drive or accessible via the same credentials, assume they are encrypted too.

This determines everything that follows, and it is the question most organisations cannot answer quickly.

6. Notify the right people, in order

Leadership, legal counsel, and your cyber insurer — most policies require prompt notification and many will void coverage if you engage responders without approval. Check the policy before hiring anyone, including us.

On paying

Almost never as a first move.

Payment funds the operation, does not guarantee a decryptor that works, and identifies you as an organisation that pays — a meaningful factor in repeat targeting. Decryptors supplied by attackers are frequently slow, buggy, or partial.

It is a decision for leadership with legal and insurance advice, after recovery options are genuinely exhausted. It should never be the first hour’s decision.

The uncomfortable truth

Whether this is a bad week or an existential event was determined months ago, by whether someone tested a restore.

The organisations that recover well are not the ones with the best tooling. They are the ones that had offline backups, knew their recovery time because they had measured it, and had a written plan that did not depend on one person’s memory.

If you are reading this out of curiosity rather than necessity: go test a restore. That is the whole lesson.


Active incident? Email us with URGENT in the subject line and we prioritise it ahead of scheduled work. See cybersecurity and ransomware recovery.

Frequently asked questions

Should I power off a machine hit by ransomware?

No. Disconnect it from the network, but leave it running. Volatile memory frequently contains encryption keys, process details and forensic evidence that are lost permanently on shutdown. Isolation stops the spread; powering off destroys information you may need.

Should I pay the ransom?

Almost never as a first move. Payment funds the attacker, does not guarantee a working decryptor, and marks you as a paying target. Exhaust restoration from clean backups first, and take legal and insurance advice before considering payment at all.

How long does ransomware recovery take?

For an organisation with tested, offline backups, typically days. For one whose backups were reachable from the network and got encrypted too, it can be weeks, or never. The difference is decided months before the attack, not during it.

Do I have to report a ransomware attack in Quebec?

If personal information was compromised, Quebec's Law 25 imposes obligations including notifying the Commission d'accès à l'information and affected individuals where there is a risk of serious injury. Establishing scope early matters for this, which is one more reason not to destroy evidence in the first hour.

Tell us what is breaking — or what you are trying to build.

You get a senior engineer on the first call, not a salesperson. If we are not the right fit, we will say so and point you somewhere better.

Active incident? Write “URGENT” in your message and we prioritise it.