Ransomware Response: What to Do in the First 24 Hours

Ransomware incidents unfold with a speed and disorientation that no amount of reading about them ever fully prepares an organization for. The decisions made in the first 24 hours meaningfully shape the entire trajectory of recovery. A clear, pre-planned response reduces both the real chaos and the actual damage considerably compared to organizations improvising their response for the very first time in the middle of the actual crisis.

The First, Immediate Priority: Containment

The moment ransomware is confirmed, the immediate priority is containment – isolating affected systems from the rest of your network to prevent further, ongoing spread. This typically means disconnecting affected systems from the network entirely, not merely powering them off. Powering off can in some cases destroy evidence valuable for the subsequent investigation.

This containment decision needs to happen fast, and it needs pre-established authority – waiting for extended committee approval to disconnect a specific system while ransomware continues actively spreading across your network defeats the entire purpose of rapid containment. Effective incident response plans designate specific people with clear, pre-authorized authority to make this exact call immediately, without needing real-time additional approval in the heat of the moment.

Activating Your Incident Response Team Immediately

Your incident response plan should specify exactly who needs to be notified immediately. That list extends meaningfully beyond IT and security – legal counsel, executive leadership, and potentially external incident response specialists all need real, prompt notification. Decisions made in the first hours frequently carry legal and regulatory implications that pure technical staff cannot reasonably be expected to fully evaluate on their own.

Organizations without a pre-established incident response team structure lose critical, valuable time in the first hours simply figuring out who should be involved and, just as importantly, who has real authority to make which specific category of decision – time that a properly pre-planned structure would have saved entirely.

The Difficult Question of Whether to Pay

Whether to pay a ransom is a complex decision with real legal, ethical, and practical considerations that deserve serious, careful thought rather than a snap decision made under acute time pressure. Law enforcement consistently advises against payment. It provides no real guarantee of actual data recovery, and it directly funds further, ongoing criminal activity.

Some organizations do ultimately pay, particularly when the alternative is catastrophic business disruption without adequate, viable backups to fall back on instead. This decision should involve legal counsel. Paying a ransom can carry real legal risk depending on the specific attacking group’s known sanctions status, and the call should never be made purely by IT staff acting entirely alone without that broader input.

Preserving Evidence While Simultaneously Pursuing Recovery

Even while pursuing recovery, care needs to be taken to preserve evidence for the eventual investigation – both your own internal investigation and any potential law enforcement involvement. This means documenting the incident thoroughly as it unfolds, and where realistically possible, preserving forensic images of affected systems before beginning cleanup and restoration efforts.

Organizations that rush purely toward recovery without proper evidence preservation often struggle afterward to fully understand exactly how the attack occurred in the first place, a gap that meaningfully hampers their ability to prevent a comparable future incident from happening again down the road.

Communication: Internal and External, Both Necessary

Clear, honest internal communication keeps your organization functioning as effectively as realistically possible during a chaotic period. External communication – to customers, regulators, and potentially the public depending on the specific incident’s scope – requires genuine, careful coordination with legal counsel to ensure both regulatory compliance and appropriate transparency without prematurely disclosing details that could meaningfully compromise the ongoing investigation.

Organizations with a pre-drafted communication plan and pre-approved template language move considerably faster and more confidently here than those trying to draft appropriate, careful communication from scratch under real, active crisis pressure – one more concrete reason advance incident response planning matters so much more than it might initially seem worth the upfront investment.

Backups Are Only as Good as the Restore You Have Actually Tested

Every ransomware response plan leans heavily on the assumption that clean backups exist and can be restored quickly, and that assumption is tested far less often than it should be. It is common for organizations to discover, mid-incident, that their backup retention window did not go back far enough to predate the initial compromise. Sophisticated ransomware operators frequently sit inside a network for days or weeks before triggering encryption, quietly identifying and, where possible, corrupting or deleting backup systems first. A restore from a backup taken after the attacker already had access can mean restoring straight back into a still-compromised environment.

The organizations that recover fastest are the ones that run an actual test restore on a regular schedule, not just a backup job that reports success. A backup that completed without error and a backup that can actually rebuild a working system within an acceptable recovery time are not the same claim, and the gap between them only becomes visible at the worst possible moment if it has never been checked beforehand.

The Regulatory Clock Most Teams Forget Is Already Running

Depending on your jurisdiction and industry, a ransomware incident involving personal data can trigger a formal breach notification obligation with a strict deadline – 72 hours under GDPR, for instance, and various state and sector-specific rules elsewhere. That clock typically starts from when the organization becomes aware of the breach, not from when the full scope is finally understood. Legal counsel needs to be looped in early enough to make a genuinely informed call about notification timing. Treating the deadline as a parallel workstream from hour one avoids a mistake that compounds an already difficult situation with an entirely avoidable regulatory one: discovering it only on day three of an ongoing investigation.

Leave a Comment