What to Do in the First Hour After a Ransomware Attack

What To Do In The First Hour

When ransomware hits, the first hour determines whether your business recovers in days or weeks. The key is to act quickly but methodically: disconnect affected systems, preserve evidence, assess the scope, and engage your incident response plan — not panic. This guide walks you through exactly what to do, minute by minute.

Minute Zero: Recognize the Signs

Time starts ticking the moment you notice something wrong. Ransomware doesn't always look the same, but there are common warning signs that every employee should know:

  • Encrypted files with strange extensions are one of the most obvious indicators. Files that once ended in .docx, .xlsx, or .pdf now carry extensions like .locked, .encrypted, or random strings of characters. Double-clicking them opens a ransom note instead of the document itself.
  • Ransom note pop-ups may appear on screen — full-screen messages demanding payment in cryptocurrency, often with countdown timers designed to create urgency and fear.
  • Sudden system slowdowns can also signal an attack in progress. If multiple machines across your office start running unusually slow at the same time, it could mean ransomware is actively encrypting files in the background.
  • Unusual network traffic — spikes in outbound data, connections to unknown IP addresses, or file-sharing activity at odd hours — may indicate the malware is communicating with command-and-control servers or spreading laterally across your network.
  • Multiple users reporting the same issue simultaneously can be a red flag. Train your team to recognize these signs and report them immediately. Every second of delay gives the attacker more time to spread.

Minutes 1–15: Contain the Threat

Once you suspect ransomware, containment is the single most important action you can take. Your goal is to stop the spread before the infection reaches more systems, more data, and more parts of your business.

  • Disconnect affected machines from the network immediately. Unplug Ethernet cables and disable Wi-Fi on any machine showing signs of infection. Do NOT shut down affected computers. Shutting down destroys volatile memory (RAM) that contains evidence of how the attacker entered, what tools they used, and where they've been.
  • If you have network segmentation in place, isolate the affected segment to prevent lateral movement. If you don't have segmentation, invest in it — it's one of the most effective defenses against ransomware.
  • Alert your IT team or managed service provider immediately. They have incident response playbooks ready to deploy and can begin containment actions remotely while you handle physical disconnections on-site.
  • A word about ransom payments: do not pay the ransom. There’s no guarantee the attacker will provide working decryption keys, and paying funds criminal operations, making future attacks more likely.

Minutes 15–30: Assess the Scope

With the immediate threat contained as much as possible, shift to understanding the full scope of the attack. You need answers to several critical questions before recovery planning can begin.

  • Determine which systems are affected. Check servers, shared drives, backup systems, and cloud services. Verify whether your backups are intact and accessible or if they've been encrypted or deleted.
  • Check for lateral movement. Determine whether the attacker accessed additional systems by reviewing logs, access patterns, and network traffic records.
  • Check cloud services for unauthorized access or changes.
  • Document everything. Take screenshots of ransom notes, error messages, and other relevant events for forensic investigation and regulatory breach notifications.

Minutes 30–45: Activate Your Incident Response Plan

If you have a documented incident response plan, now is the time to follow it. Your plan should outline:

  • Roles and responsibilities
  • Communication protocols
  • Escalation procedures
  • Specific actions for different types of security incidents If you don't have an incident response plan, this is where having a managed service provider pays off; they bring pre-built playbooks and trained responders.
  • Contact your cyber insurance carrier. Most policies require prompt notification of a claim.
  • Notify legal counsel if regulated data may be involved to ensure you meet obligations correctly.

Minutes 45–60: Begin Recovery Planning

By the end of the first hour, you should have a clear picture of what happened. Now it's time to start planning the recovery path.

  • Identify clean backup systems, using the 3-2-1 backup rule: three copies of data, on two different media types, with one copy stored offsite.
  • Prioritize critical business functions needed to resume operations.
  • Work with your IT team to rebuild affected systems from known-good images.
  • Begin the digital forensics process to understand how the attacker entered your network.

What Comes Next

The first hour buys you time and clarity, but full recovery is a marathon, not a sprint. Here is what follows in the days and weeks ahead:

  • Conduct a full forensic investigation.
  • Rebuilding systems involves wiping and reimaging all affected machines and restoring data from clean backups.
  • Enhanced security measures should be deployed as part of post-incident hardening.
  • Employee training addresses the human element to turn employees into an active layer of defense.
  • If regulated data was accessed, breach notification may be required.