Your First Hour After a Ransomware Attack
Most ransomware guidance is written to be read before anything happens. This one is written for the hour it happens, when someone has just called to say files are encrypted and a note is on the screen, and the decisions being made in the next sixty minutes will shape how bad the next sixty days are.
If that is where you are right now: work down this page. If it is not, read it anyway, because the hardest part of this list is that several items require decisions you cannot make well under pressure.
Minutes 0 to 10: contain, do not investigate
The instinct is to understand what happened. Resist it. Every minute spent understanding is a minute encryption continues and spreads.
Disconnect affected machines from the network. Pull the ethernet cable, disable Wi-Fi. This stops lateral movement.
Do not power them off. This matters and it is counterintuitive. Shutting down destroys everything in memory, including, in some cases, encryption keys and the evidence needed to identify the variant and determine what was taken. Disconnect, do not shut down. The one exception is a machine you cannot get off the network. If you cannot isolate it and it is still encrypting, powering it down is the right call, and it is what CISA advises. You lose the memory evidence; you stop the spread.
Isolate your backups immediately. If backups are reachable from the network, disconnect them now. Modern ransomware specifically hunts backups before encrypting, and an attacker with domain admin rights will delete them if they can still reach them. Your backups are the single most valuable thing you own at this moment. Whether a backup drive that was plugged into the encrypted server is still a backup is the question people ask us first, and it is answered in our managed IT FAQs.
Do not start deleting anything or “cleaning up.” You are now inside an incident that may involve legal, insurance, and regulatory obligations. Altered evidence complicates every one of them.
Minutes 10 to 20: call the people who are contractually involved
Your cyber insurance policy is usually the first of those calls, and what it expects of you was decided at renewal rather than today. See what your cyber insurance renewal is actually asking for.
Two calls, in this order, and both earlier than feels natural.
Your cyber insurance carrier. This is the call people delay and should not. Most policies require prompt notification, and many require that you use their approved incident response vendors. Engaging your own forensics firm first can jeopardize coverage for that work. The carrier’s hotline number should be somewhere you can find it without access to your network, which is a good reason to check right now that you know where it is.
Your IT provider or internal team, if they are not already on it.
Both calls should happen before you make technical decisions with financial consequences.
Minutes 20 to 40: establish what you actually know
Now you can start assessing, on the assumption that containment is holding.
Questions worth answering, in rough priority:
- What is encrypted, and what is not? Scope determines everything downstream.
- Are the backups intact and reachable? Can you actually see them, and are they unencrypted?
- Is it still spreading? Watch for new machines reporting problems after containment. If it is still moving, containment failed and you go back to step one.
- How did it get in? Frequently a compromised remote access account, a phishing click, or an unpatched internet-facing system. You do not need certainty yet, but a working theory shapes what else you isolate.
- Was data taken before it was encrypted? This is the question with the longest tail. Most modern ransomware exfiltrates data first and threatens publication as leverage. That converts the incident from an availability problem into a disclosure and notification problem, with legal obligations attached.
Minutes 40 to 60: communication, deliberately
Two audiences, and getting the order wrong causes real damage.
Internally: tell staff what is happening, what they should not do, and where to direct questions. In the absence of information people improvise: reconnecting machines, forwarding the ransom note, discussing it publicly. A short, clear internal message prevents most of that.
Externally: say nothing substantive yet. You do not yet know what was taken, and an early statement that turns out to be wrong is worse than a slower accurate one. If clients must be told something immediately, keep it to the fact of a disruption and a commitment to follow up.
Assume email is compromised. Coordinate over phone or a channel that does not depend on the affected environment.
On paying
You will be asked this within the hour, so it is worth having thought about it before.
Considerations, none of which are simple:
- Payment does not guarantee a working decryption key, and decryption is frequently slow and partial even when the key works
- Payment does not undo exfiltration. If data was taken, it was taken
- There are sanctions implications depending on who the attacker is, which is one of several reasons this is a decision for your carrier and counsel rather than for you alone at 9pm
- Your insurance policy may have specific provisions about payment
This is not a decision to make in the first hour, and anyone pressing you to make it quickly, including the attacker’s countdown timer, is doing so for their benefit rather than yours.
What determines the outcome, and it is not the first hour
The pattern in published incident data is consistent: the businesses that recover quickly are almost never the ones that responded most cleverly during the incident. They are the ones who had already done four unglamorous things:
- Backups that were isolated and tested. Backups an attacker with domain admin could not reach, that somebody had actually restored from recently. This is the single largest determinant of recovery time.
- An incident contact list that exists offline. Carrier hotline, IT provider, legal contact, key staff. Stored somewhere reachable when the network is not, because the version on the encrypted file share is not available to you.
- MFA everywhere, with no quiet exceptions. Most of these incidents begin with a valid credential.
- Knowing which systems matter. If you have to choose a restore order under pressure, choosing well requires having thought about it before.
None of that helps during the incident. All of it determines how the incident ends.
The unwelcome question
If you read that list and could not confidently check all four, then the useful work is not memorizing the first-hour steps. It is fixing those four, in that order, starting with backups.
Restore testing in particular gets deferred indefinitely because it is tedious and nothing appears wrong when you skip it. Backup software reports success on backups that cannot be restored, and the discovery that yours are among them tends to happen at the worst available moment.
If you want an outside read on whether your backups would survive this scenario, or on the other three, that is a reasonable thing to ask us to look at. It is a better conversation to have on a normal Tuesday than during the hour this article is written for.
Sources
- #StopRansomware Guide: joint CISA, FBI, NSA and MS-ISAC guidance, and the source of the containment sequence above, including the power-down exception
- CISA: I’ve Been Hit By Ransomware
This is general guidance, not incident response. If you are in an active incident, your cyber insurance carrier’s hotline and the responders they appoint take precedence over anything written here.
Questions this post answers
Should I turn off computers that have been hit by ransomware?
No, with one exception. Disconnect affected machines from the network by pulling the ethernet cable and turning off Wi-Fi, which stops the attack from spreading. Leave them powered on. Shutting down destroys everything in memory, which in some cases includes encryption keys and the evidence needed to identify the ransomware variant and what was taken. The exception is a machine you cannot get off the network that is still encrypting. Powering that one down is the right call, and it is what CISA advises.
Who should I call first after a ransomware attack?
After disconnecting affected machines, call your cyber insurance carrier first, then your IT provider or internal team if they are not already on it. Make both calls before any technical decision with financial consequences. Most policies require prompt notification, and many require you to use the insurer’s approved incident response vendors. Hiring your own forensics firm first can risk coverage for that work. Keep the carrier’s hotline number somewhere you can find it without your network. TTS Cyber is not a law firm; this is not legal advice.
Should my business pay the ransom if ransomware hits us?
Paying a ransom is not a decision to make in the first hour. Payment does not guarantee a working decryption key, and decryption is often slow and partial even when the key works. Payment also does not undo data theft: if data was taken, it was taken. There can be sanctions implications depending on who the attacker is, and your insurance policy may have terms about payment. Make that decision with your carrier and counsel. TTS Cyber is not a law firm; this is not legal advice.
The Microsoft 365 Security Settings Most Small Businesses Miss
Legacy authentication, quiet MFA exceptions, silent forwarding rules and open app consent. Eight configuration gaps we expect to find in a tenant…