The first hour of a ransomware incident sets the ceiling on how bad it gets. The instinct is to react fast and loud; the discipline is to act deliberately. Here is the sequence our responders run - and the mistakes that turn a bad day into a catastrophic one.

Print this. Keep it somewhere that doesn't depend on the network you're about to isolate. When encryption starts spreading, the difference between a contained event and a company-wide outage is usually decided by what the first responder does in the first sixty minutes.

Minutes 0-10: Contain, don't panic

Minutes 10-25: Preserve evidence

You will need this later - for scoping, for insurance, and possibly for law enforcement. Before anyone “cleans up”:

The goal of the first hour is not to recover. It's to stop the bleeding and preserve the story, so recovery is built on facts instead of guesses.

Minutes 25-40: Activate the right people

Minutes 40-60: Scope and stabilise

The mistakes that make it worse

The best first hour is the one you rehearsed

Teams that recover well aren't calmer by temperament - they've practised. A tested IR plan, an out-of-band comms tree, immutable backups, and a responder on retainer turn the first hour from improvisation into procedure. If you'd like us to pressure-test your ransomware playbook - or stand up a retainer so there's a number to call - that's what our incident-response team is for.

← Back to Insights