The First 24 Hours: A Ransomware Incident Checklist
A step-by-step checklist for the moment everything is on fire — containment, communication, and who to call, in the order that actually matters.
9 min read
Before anything else: don't touch the ransom note, and don't reboot
The instinct in the first minutes of a confirmed ransomware event is to start clicking — reboot the affected machine, delete the note, try to open encrypted files to see how bad it is. Every one of those actions destroys evidence or gives the attacker more time inside your network.
The first correct action is almost always to isolate, not investigate. Pull the network cable or disable Wi-Fi on affected endpoints. Do not power them off — memory-resident forensic evidence is lost on shutdown, and modern IR teams can often work from a live, isolated machine.
Hour 0–1: Contain
- Isolate affected endpoints from the network (disconnect, don't shut down).
- Disable any automated backup jobs immediately — you don't want ransomware to encrypt your backup target too.
- Identify and lock down the blast radius: which segments, shares, and domain accounts touched the affected systems in the last 24–48 hours?
- Preserve logs — SIEM, EDR, firewall, and authentication logs are the first things attackers (and time) erase.
- Do not pay, negotiate, or communicate with the attacker until you have counsel and an IR firm engaged.
Hour 1–4: Activate your response team
This is the point where having pre-identified partners pays for itself many times over. If you don't already have an incident response retainer, this is when you need one — most reputable IR firms can mobilize within hours for an active incident, but pricing and priority are dramatically better if the relationship was established before the emergency.
- Engage your incident response provider (or find one — see our vetted directory below).
- Notify your cyber insurance carrier immediately; most policies require early notification to preserve coverage, and many carriers require you to use a panel IR firm to be reimbursed.
- Loop in outside breach counsel — privileged communications from this point forward matter for regulatory and litigation exposure.
- Establish an out-of-band communication channel (attackers who had network access may be reading your email or Teams/Slack).
Hour 4–24: Scope, assess, and stabilize
- Work with your IR team to determine the initial access vector and lateral movement path.
- Identify what was encrypted versus what was merely accessed or exfiltrated — these have very different notification and negotiation implications.
- Confirm backup integrity offline, on media the attacker could not have reached.
- Begin drafting an internal holding statement and a regulator/customer notification plan in parallel with technical response — you may be on a legal clock (e.g. 72-hour breach notification windows in several jurisdictions).
- Resist pressure to make a ransom decision in the first 24 hours. Understand your recovery options and legal exposure first.
What determines whether this costs you $50K or $5M
The single biggest cost driver in ransomware incidents isn't the ransom — it's downtime and the quality of your recovery position. Organizations with tested, offline backups and a rehearsed incident response plan typically recover in days; organizations without either can be down for weeks and face costs an order of magnitude higher.
This is exactly what our free readiness assessment is built to surface before it's an emergency — not after.