The First Hour of a Ransomware Attack: What to Do
What to do in the first sixty minutes of a ransomware incident — and the three common reactions that destroy evidence or make recovery harder.
Ransomware is unusual among IT emergencies in that the first hour meaningfully changes the outcome — and the instinctive reactions are frequently the wrong ones.
This is the sequence we walk clients through.
1. Disconnect. Do not power off.
Pull the network cable, or disable the wireless adapter, on every affected machine. This stops encryption spreading to network shares and other hosts.
Do not shut the machine down. This is the single most common damaging mistake. Volatile memory often holds encryption keys, active process details, network connections and other forensic evidence. Some ransomware families have been decrypted precisely because keys were recovered from memory. Shutdown destroys that permanently.
Isolation stops the bleeding. Power-off throws away the chart.
2. Do not delete anything
Not the ransom note, not the suspicious files, not the strange scheduled task, not the unfamiliar admin account.
Everything is evidence. It establishes how they got in, how long they were inside, and what they accessed. You will need that for your insurer, for legal obligations under Law 25, and for making sure the same door is not still open when you restore.
3. Do not restore yet
The instinct is to get back up immediately. Restoring into a compromised environment usually means re-encryption within days, because the attacker’s access persists.
Scope first, eradicate second, restore third. In that order.
4. Assume credentials are compromised
By the time ransomware deploys, attackers have typically been inside for days or weeks and have harvested credentials. Assume every password in the blast radius is known — including service accounts, saved browser credentials, and anything reused personally.
Rotation happens as part of eradication, not before scoping, or you tip off an attacker who still has access.
5. Check whether backups are actually isolated
Find out now whether your backups were reachable from the compromised network. If they were on a mapped drive or accessible via the same credentials, assume they are encrypted too.
This determines everything that follows, and it is the question most organisations cannot answer quickly.
6. Notify the right people, in order
Leadership, legal counsel, and your cyber insurer — most policies require prompt notification and many will void coverage if you engage responders without approval. Check the policy before hiring anyone, including us.
On paying
Almost never as a first move.
Payment funds the operation, does not guarantee a decryptor that works, and identifies you as an organisation that pays — a meaningful factor in repeat targeting. Decryptors supplied by attackers are frequently slow, buggy, or partial.
It is a decision for leadership with legal and insurance advice, after recovery options are genuinely exhausted. It should never be the first hour’s decision.
The uncomfortable truth
Whether this is a bad week or an existential event was determined months ago, by whether someone tested a restore.
The organisations that recover well are not the ones with the best tooling. They are the ones that had offline backups, knew their recovery time because they had measured it, and had a written plan that did not depend on one person’s memory.
If you are reading this out of curiosity rather than necessity: go test a restore. That is the whole lesson.
Active incident? Email us with URGENT in the subject line and we prioritise it ahead of scheduled work. See cybersecurity and ransomware recovery.
- Ransomware
- Incident Response
- Cybersecurity