The first 24 hours: what to do in the moment everything is on fire
Key takeaways
- Isolate, don't power off — pulling network access contains spread while preserving the forensic evidence a shutdown destroys.
- Don't delete the ransom note or reboot affected machines; both erase options you may need for identification, recovery, and claims.
- Engage IR, legal, and your insurer in parallel in the first hours — the order you notify them affects privilege and coverage.
First move: isolate, don't investigate
The instinct in the first minutes is to start clicking — reboot the affected machine, delete the note, open an encrypted file to see how bad it is. Resist all of it. The first correct action is almost always to isolate, not investigate: disconnect affected endpoints from the network by pulling the cable or disabling Wi-Fi, and cut off the pathways an active attacker is using. Isolation contains spread; investigation on the live host can tip the attacker off or trigger the very destruction you're trying to prevent.
Don't destroy what you'll need later
Do not power off affected machines — memory-resident forensic evidence is lost on shutdown, and modern IR teams can often work from a live, isolated system. Do not delete the ransom note; it identifies the variant, may enable a known decryptor, and is needed for insurance and law enforcement. Do not reboot in hopes it 'fixes' things. Each of these instinctive actions destroys evidence, recovery options, or both, and they can't be undone once done.
Mobilize the right people in parallel
The first hours are about parallel notification, not a serial checklist. Engage your incident response firm (or your insurer's panel), legal counsel, and your cyber insurer — the order matters, because notifying counsel early can preserve legal privilege over the investigation, and engaging the insurer promptly protects coverage that many policies condition on early notice. If you have a retainer, this is what you're paying for; if you don't, this is the call you make first.
Establish command and preserve the clock
Stand up a single incident bridge with a clear incident commander, and start a timeline — who did what, when — from the first minute. Decisions made in the fog of hour one look very different in the post-incident review and in any regulatory filing, and a contemporaneous log is worth more than anyone's memory. The goal of the first 24 hours isn't to fix the problem; it's to contain the damage and preserve every option — recovery, negotiation, legal, insurance — that a panicked reaction would have closed off.