🔴 Under active attack? Get connected to an incident response team now — Get Emergency Help →
🔴Active Incident

If you're mid-incident, start here.

Get connected to a vetted incident response team below, and work through the first-24-hours checklist while you wait. Don't reboot affected machines, don't pay or negotiate yet, and don't delete the ransom note — all three destroy options you may need later.

?0-A_<_E[ENCRYPTING…

Get connected to an incident response team

Tell us what's happening. No cost to submit — we'll route you to a vetted partner suited to your situation.

The First 24 Hours: A Ransomware Incident Checklist

Before anything else: don't touch the ransom note, and don't reboot

The instinct in the first minutes of a confirmed ransomware event is to start clicking — reboot the affected machine, delete the note, try to open encrypted files to see how bad it is. Every one of those actions destroys evidence or gives the attacker more time inside your network.

The first correct action is almost always to isolate, not investigate. Pull the network cable or disable Wi-Fi on affected endpoints. Do not power them off — memory-resident forensic evidence is lost on shutdown, and modern IR teams can often work from a live, isolated machine.

Hour 0–1: Contain

  • Isolate affected endpoints from the network (disconnect, don't shut down).
  • Disable any automated backup jobs immediately — you don't want ransomware to encrypt your backup target too.
  • Identify and lock down the blast radius: which segments, shares, and domain accounts touched the affected systems in the last 24–48 hours?
  • Preserve logs — SIEM, EDR, firewall, and authentication logs are the first things attackers (and time) erase.
  • Do not pay, negotiate, or communicate with the attacker until you have counsel and an IR firm engaged.

Hour 1–4: Activate your response team

This is the point where having pre-identified partners pays for itself many times over. If you don't already have an incident response retainer, this is when you need one — most reputable IR firms can mobilize within hours for an active incident, but pricing and priority are dramatically better if the relationship was established before the emergency.

  • Engage your incident response provider (or find one — see our vetted directory below).
  • Notify your cyber insurance carrier immediately; most policies require early notification to preserve coverage, and many carriers require you to use a panel IR firm to be reimbursed.
  • Loop in outside breach counsel — privileged communications from this point forward matter for regulatory and litigation exposure.
  • Establish an out-of-band communication channel (attackers who had network access may be reading your email or Teams/Slack).

Hour 4–24: Scope, assess, and stabilize

  • Work with your IR team to determine the initial access vector and lateral movement path.
  • Identify what was encrypted versus what was merely accessed or exfiltrated — these have very different notification and negotiation implications.
  • Confirm backup integrity offline, on media the attacker could not have reached.
  • Begin drafting an internal holding statement and a regulator/customer notification plan in parallel with technical response — you may be on a legal clock (e.g. 72-hour breach notification windows in several jurisdictions).
  • Resist pressure to make a ransom decision in the first 24 hours. Understand your recovery options and legal exposure first.

What determines whether this costs you $50K or $5M

The single biggest cost driver in ransomware incidents isn't the ransom — it's downtime and the quality of your recovery position. Organizations with tested, offline backups and a rehearsed incident response plan typically recover in days; organizations without either can be down for weeks and face costs an order of magnitude higher.

This is exactly what our free readiness assessment is built to surface before it's an emergency — not after.

Frequently asked questions

Should I pay the ransom?

Don't decide this alone or under time pressure. Payment doesn't guarantee working decryption or that stolen data is actually deleted, and if the attacker is a sanctioned entity, paying can carry legal exposure. Get a vetted incident response team and legal counsel involved before making this call.

Should I reboot or shut down affected systems?

No — don't power them off. Isolate affected machines from the network (pull the cable or disable Wi-Fi) instead. Shutting down loses memory-resident forensic evidence that responders can often use to work from a live, isolated machine.

Should I delete the ransom note?

No. Keep it exactly as found — don't delete, rename, or move it. It's often needed for identifying the ransomware variant, for negotiation if that path is chosen, and as evidence for law enforcement and insurance.

How fast can I get connected to an incident response team?

Submit the form on this page with what's happening — no cost, no sales call. We route your request to a vetted incident response partner suited to your situation, and they'll reach out directly to the email and phone number you provide.

Does it cost anything to submit an emergency request?

No — submitting the request through this page is free. Any actual incident response engagement is a separate arrangement directly with the partner you're connected to.

We respect your privacy

We use analytics cookies to understand how visitors use this site and improve our defense resources. No advertising or cross-site tracking. Privacy Policy