Ransomware attack: what to do in the first 24 hours

A calm, practical checklist for the first day of a ransomware incident: containment, evidence, backups, notifications and recovery options.

Ransomware is designed to cause panic, and panic leads to decisions that destroy evidence and recoverable data. Use this checklist for the first 24 hours. It isn't legal advice; bring in your counsel, insurer and an incident-response firm as early as you can.

Hour 0–1: contain, don't destroy

  1. Disconnect affected systems from the network. Unplug network cables, disable Wi-Fi and isolate VLANs. The goal is to stop the encryption spreading.
  2. Don't power systems off unless your responders tell you to. Memory can hold encryption keys and evidence. Shutting down can also interrupt encryption mid-file in ways that complicate recovery.
  3. Don't wipe, reinstall or "clean up". Reimaging servers destroys evidence and the partially encrypted data recovery engineers can often rebuild.
  4. Protect your backups. Take any backup repository that's still intact offline immediately, and change the credentials it uses. Attackers routinely go after backups.

Hour 1–4: assemble the response

  • Cyber insurer: many policies require prompt notice and have approved vendors you must use.
  • Legal counsel: to direct the investigation and handle notification duties.
  • Incident-response firm: to find how the attackers got in and confirm they're gone.
  • Law enforcement: in the US, report to the FBI via ic3.gov. Other countries have national cyber agencies.
  • Data recovery specialists: to assess what can be restored without the attacker's key.

Hour 4–12: understand what you're dealing with

Write down the ransom note's exact text, the file extensions added to encrypted files, and the time encryption started. These identify the strain. Check the No More Ransom project for a free decryptor: some older or flawed strains have one.

Then take an inventory: which systems are encrypted, which backups exist, and which of them were touched. Encryption is often less complete than it looks. Large files such as virtual disks and databases are frequently only partly encrypted, because the malware is built for speed.

Hour 12–24: decide on the recovery path

You'll usually be weighing three options: restore from clean backups, recover data forensically without the key, or (as a last resort, decided with counsel) negotiate. Paying carries real risks. Decryptors are often slow or broken, and in the US, paying a sanctioned group can violate Treasury (OFAC) rules.

Why call a recovery lab early: we often find intact data you didn't know you had, such as unencrypted parts of virtual disks, snapshots the attacker missed, or deleted backup files we can rebuild. That can change the decision completely.

After the first day

Bring systems back in priority order onto rebuilt, patched infrastructure, not the machines that were compromised. Rotate every credential. Then fix the gaps the incident exposed: offline or immutable backups, MFA everywhere, and a tested response plan.

Under attack right now? See our ransomware recovery service, call our 24/7 line, or start a live chat and mark it Emergency.

This guide is general information, not a diagnosis of your device. Every case is different; a free evaluation tells you exactly what's wrong.

Every hour matters. Contact us now.

Stop using the device, then talk to an engineer. Evaluation is free and your quote is fixed before we start.