The first hour of a ransomware incident sets the ceiling on how bad it gets. The instinct is to react fast and loud; the discipline is to act deliberately. Here is the sequence our responders run - and the mistakes that turn a bad day into a catastrophic one.
Print this. Keep it somewhere that doesn't depend on the network you're about to isolate. When encryption starts spreading, the difference between a contained event and a company-wide outage is usually decided by what the first responder does in the first sixty minutes.
Minutes 0-10: Contain, don't panic
- Isolate, don't power off. Disconnect affected hosts from the network - pull the cable, disable Wi-Fi, or quarantine via EDR. Do not shut them down: a hard power-off can destroy volatile evidence and, with some strains, corrupt data further.
- Contain the spread path. Ransomware moves through shared drives, RDP, and privileged accounts. Disable the compromised accounts and cut off the file shares it's reaching.
- Protect your backups first. Attackers target backups before they detonate. Immediately verify your backups are isolated/immutable and disconnect any that are network-reachable, before they're encrypted too.
Minutes 10-25: Preserve evidence
You will need this later - for scoping, for insurance, and possibly for law enforcement. Before anyone “cleans up”:
- Capture what you can: EDR timelines, firewall and VPN logs, and the ransom note itself (it identifies the strain).
- Photograph screens showing the encryption and note exact timestamps.
- Resist the urge to reimage machines - that destroys the forensic trail that tells you how they got in and whether they're still inside.
The goal of the first hour is not to recover. It's to stop the bleeding and preserve the story, so recovery is built on facts instead of guesses.
Minutes 25-40: Activate the right people
- Convene the incident team on an out-of-band channel - phones or a separate messaging app, not the potentially-compromised email/Teams.
- Notify leadership with facts, not speculation: what's affected, what's contained, what's unknown.
- Engage your IR retainer or MDR provider now. Early expert involvement measurably reduces cost and downtime - don't wait until you've made it worse.
- Loop in legal and your cyber-insurer early - many policies require prompt notification and have approved responders.
Minutes 40-60: Scope and stabilise
- Establish blast radius: which systems, which data, and - critically - is this encryption only, or exfiltration too? Modern gangs steal data before encrypting and threaten to leak it, which changes your legal and notification obligations entirely.
- Identify the initial access vector if you can (phishing, exposed RDP, an unpatched edge device) so you don't restore straight back into the same hole.
- Begin a written incident log - decisions, times, and actions - from this point on.
The mistakes that make it worse
- Paying immediately. That's a leadership/legal decision made after scoping - not a first-hour reflex, and often not the fastest path to recovery.
- Restoring before you understand the intrusion. If the attacker still has access, you'll be re-encrypted within days.
- Communicating over compromised channels. Assume they're reading your email.
- Wiping evidence in a rush to “get back up.” You'll pay for it during the investigation and the insurance claim.
The best first hour is the one you rehearsed
Teams that recover well aren't calmer by temperament - they've practised. A tested IR plan, an out-of-band comms tree, immutable backups, and a responder on retainer turn the first hour from improvisation into procedure. If you'd like us to pressure-test your ransomware playbook - or stand up a retainer so there's a number to call - that's what our incident-response team is for.
← Back to Insights