The first 72 hours of a ransomware attack, hour by hour
Most ransomware advice is written before an incident. This is what the days after one actually look like.
Ransomware doesn't arrive the way people imagine. There's no countdown timer on a black screen at 9am. Usually someone can't open a file, then someone else can't, then the phones start.
By the time the ransom note appears, the attacker has typically been inside for days or weeks. Understanding that changes what you do next.
Hour 0 to 4: contain, don't investigate
The instinct is to work out what happened. Resist it. The first job is to stop the spread. Isolate affected machines from the network — physically pull the cable if you have to. Disable the accounts you suspect are compromised. Do not power machines off if you can avoid it; memory contains evidence you'll want later.
Critically, check your backups before doing anything else with them. If the backup system is reachable from the compromised network, assume the attacker has already looked at it.
Attackers go after backups first, precisely because they know that's what makes you able to say no.
Hour 4 to 12: work out the blast radius
Now the investigation starts. Which systems are encrypted, which are merely infected, which are clean. How did the attacker get in, and when. That date matters enormously, because it determines which backup you can safely restore from.
This is also when you notify. Your insurer, if you have cyber cover, usually needs to be told within a specific window or the policy is affected. Depending on the data involved, regulatory notification clocks may already be running.
Hour 12 to 48: recovery decisions
The business now needs to answer two questions honestly. What is the minimum set of systems we need to operate, and how far back can we go without losing something we can't rebuild?
Recovery is never everything at once. It's prioritised. Domain controllers and authentication first, because nothing else works without them. Then core business systems. Then the rest.
Restore into a clean environment, not on top of the old one. Scan every restore point for malware before bringing it online. Reintroducing the infection during recovery is a genuinely common and completely avoidable second disaster.
Hour 48 to 72: back online, carefully
Bringing systems back is not the end. Every restored machine gets patched and hardened before it rejoins the network. Every password gets changed, including service accounts nobody has touched in years. Multi-factor authentication goes on anything that doesn't have it.
Monitoring stays elevated for weeks. Attackers who got in once frequently try again, and they still know your environment.
About paying
We won't tell you what to do, but the honest picture: paying funds the next attack, offers no guarantee, and decryption tools supplied by criminals are often slow and incomplete. Many businesses that pay still spend weeks rebuilding. The businesses that don't pay are almost always the ones with tested backups.
What separates a bad week from a closure
It's rarely the sophistication of the attack. It's whether there was a plan, whether backups were isolated and tested, and whether someone was watching closely enough to catch it early rather than at the ransom note.
All three of those are decisions made on ordinary days, long before anything goes wrong.
Would you know what to do in hour one?
We'll walk through your response plan and show you where the gaps are.