All articles
Incident Response May 2026 10 min read

The First Hour of a Ransomware Incident: A Practical Checklist

What you do in the first sixty minutes shapes the entire recovery. A calm, step-by-step guide for the person who picks up the phone at 3am - written to be usable when you are tired, scared, and short on information.

JR Jacob RiggsChief Executive Officer, Cyse
Key takeaways
  • Do not power machines off - isolate them from the network instead, so you preserve evidence in memory.
  • Your first job is to stop the spread, not to understand everything; containment beats analysis in the first hour.
  • Assume the attacker has been inside for weeks and has your backups in their sights - verify the backups are intact and offline.
  • Communication is part of the response - a named incident lead and a single source of truth prevent chaos.
  • Paying is a business decision with legal weight, not a technical one - loop in leadership and counsel early.

It is 3am. A server is throwing errors, files have odd new extensions, and someone has found a note demanding payment. The next sixty minutes matter more than the next sixty hours, because almost every expensive mistake in ransomware recovery is made early, under pressure, by people acting on instinct.

This is the checklist we wish every organisation had taped to the wall. It assumes you are not a specialist, you are tired, and you do not yet know how bad it is.

Before you touch anything

Do not power the affected machines off. Pulling the plug destroys the memory-resident evidence responders need to understand what happened - and sometimes the encryption keys themselves. Isolate instead. There is a difference, and it matters.

Minutes 0-10: Contain the spread

Ransomware is usually still spreading when you discover it. Your first and only priority is to stop that, and you do it by cutting network paths, not by switching things off.

  • Isolate affected hosts from the network. Unplug the network cable, disable the switch port, or quarantine via your endpoint tool. Keep the machine powered on.
  • Sever the routes the malware travels. If you can, disable the specific network links between sites or segments rather than killing everything - but if in doubt, cutting broadly is the safe error.
  • Suspend, do not delete. Disable compromised accounts and revoke sessions rather than deleting anything. You will need the evidence later.

Minutes 10-20: Stand up the response

Technical containment and organisational response start in parallel. Incidents descend into chaos when ten people act on ten different assumptions.

  • Name an incident lead. One person owns decisions and the timeline. Everyone else reports to them.
  • Open one source of truth. A single document or channel where every action, time, and observation is recorded. This becomes your evidence, your handover, and your post-incident report.
  • Assume email and chat may be monitored. If the attacker is in your environment, they may be reading your response. Move sensitive coordination to an out-of-band channel - phones, a separate messaging app.
Why the log matters

In the calm afterwards, "when did we isolate the file server?" and "who disabled that account?" become critical questions - for insurers, regulators, and lawyers. A timestamped log written as you go is worth more than anyone's memory the next morning.

Minutes 20-35: Protect the backups

Modern ransomware crews know that backups are what stop you paying, so they go looking for them first. By the time they trigger encryption, they have often already deleted or encrypted every backup they could reach.

  • Verify your backups exist and are offline. Confirm you have copies the attacker could not touch - immutable, air-gapped, or in a separate identity domain.
  • Do not connect backup systems to the infected network to check them. Verify out of band. Plugging a clean backup into a live incident is how clean backups become infected ones.
  • Note the last known-good point. Even a rough sense of when the environment was clean will shape the entire recovery plan.

Minutes 35-50: Assess the blast radius

Now, and only now, you start to understand scope - enough to make decisions, not to complete the investigation.

  • Which systems are encrypted, and which are merely offline because you isolated them?
  • Is there evidence of data theft, not just encryption? Most crews now steal data before encrypting it and threaten to leak it. This changes your legal obligations entirely.
  • How did they get in? You may not know yet - but capture every clue, because if you rebuild without closing the entry point, you will be back here in a week.
The mistake that causes reinfection

Restoring systems before you have found and closed the initial access. If the attacker still has valid credentials or an unpatched way in, your freshly restored environment is encrypted again within days. Recovery and root-cause must proceed together.

Minutes 50-60: Escalate the decisions that are not yours

Some choices in a ransomware incident are business and legal decisions, and they need the right people awake.

  • Notify leadership. They own the risk decisions and external communications.
  • Engage legal counsel and your cyber-insurer. Many policies require early notification and may provide a specialist response team. Data theft may trigger mandatory breach-notification deadlines measured in hours, not days.
  • Do not communicate with the attacker or pay anything yet. Payment carries legal, regulatory, and sanctions implications, and rarely returns data cleanly. It is a leadership-and-counsel decision, never a panicked 3am one.
  • Bring in specialist responders if the scope is beyond your team. The earlier they join, the more evidence survives and the faster you recover.
The organisations that recover well are not the ones with no incidents. They are the ones who practised the first hour before they needed it.

The single best thing you can do today

Everything above is far easier if you have rehearsed it. Run a tabletop exercise: gather the people who would actually respond, describe this exact 3am scenario, and walk it through. You will discover the gaps - the backup nobody can find, the contact list that is out of date, the decision nobody knows who owns - while it is cheap to fix them rather than during a live crisis.

If you would like an experienced team on call for the hour you hope never comes, that is precisely what our incident response service exists for.

Need help putting this into practice?

Our practitioners deal with exactly these problems every week. A short conversation costs nothing and usually saves a lot.