Someone calls you and says their files have weird new extensions, or there is a note on the screen demanding payment, or three machines just locked up at once. The next hour is the one that matters most. What you do, and just as importantly what you do not do, in the first sixty minutes shapes how bad this gets.
This is the playbook. Print it, save it somewhere offline, and hope you never need it.
First: do not panic, and do not pay anyone yet
Ransomware is designed to make you act fast and act scared. The countdown timer on the ransom note exists to short-circuit your judgment. Take a breath. The first hour is for containment and assessment, not for negotiating, not for paying, and not for trying to clean infected machines yourself.
Paying is a decision for much later, made with legal counsel and, if you have it, your cyber-insurance carrier, who often has incident-response specialists on retainer. It is not a first-hour move.
Minute 0 to 10: Contain the spread
Ransomware spreads across a network. The single most valuable thing you can do early is stop it from reaching machines and backups it has not hit yet.
- Disconnect infected machines from the network. Unplug the ethernet cable; turn off Wi-Fi. Do not power the machine off if you can avoid it. Powering off can destroy evidence and, in some cases, encryption keys still held in memory that a specialist could recover. Disconnect, do not shut down.
- Isolate the network if multiple machines are affected. If it is spreading, disconnecting your internet uplink or shutting down the affected switch buys time. Better to take everyone offline for an hour than to let it reach the server.
- Protect your backups first. If your backups are reachable on the network, ransomware will try to encrypt them too. If you can, physically disconnect backup drives or cut off access to backup storage right now. Backups are your way out; protect them before anything else.
Minute 10 to 25: Assess the scope
Now figure out how big this is, without touching the infected machines more than necessary.
- Which machines are affected? Walk the office, or check your monitoring. One machine is a contained problem; the file server is a different conversation.
- What got encrypted? Local files only, or shared drives and the server?
- Is the backup intact? Check whether your last good backup is recent and untouched. This single fact determines almost everything that comes next.
- Take photos. Photograph the ransom note and any error messages with your phone. This matters for insurance, for any law-enforcement report, and for the specialists who help you.
Minute 25 to 45: Make the calls
You should not be doing this alone past this point.
- Call your IT provider or incident-response contact. If you have a managed IT relationship, this is the call that matters; they should have your environment documented and a recovery path ready. If you are our client, this is when you call the number you already have.
- Notify your cyber-insurance carrier. Most policies require prompt notification and many provide an incident-response team. Calling them late can jeopardize coverage.
- Loop in leadership. Owners and managers need to know now, not after it is resolved, because decisions about downtime, customer communication, and possibly legal exposure are theirs to make.
Minute 45 to 60: Stabilize and decide the path
By now you should know the two things that drive every later decision: how far it spread and whether you have clean backups.
- If backups are clean and recent, the path is usually: wipe the affected machines completely, rebuild from known-good images, and restore data from backup. Painful, but a known, safe road. This is why we harp on tested backups; an untested backup discovered to be broken at this exact moment is the worst surprise in IT.
- If backups are compromised or nonexistent, the situation is far more serious, and the decisions (including whether paying is even on the table) need legal and specialist input. This is the scenario nobody wants to be in, and it is entirely preventable with proper backups.
What not to do, ever
- Do not pay impulsively. It funds the next attack, there is no guarantee you get a working decryption key, and it should never be a first-hour decision.
- Do not try to “clean” infected machines and put them back into service. Reinfection and lingering footholds are the rule, not the exception. Wipe and rebuild.
- Do not delete the ransom note or wipe machines before evidence is captured, if insurance or law enforcement may be involved.
- Do not stay quiet to avoid embarrassment. Speed and honesty shrink the damage; silence grows it.
The uncomfortable truth
Almost every ransomware disaster that becomes a business-ending event has the same root cause: no tested, isolated, recent backup. The attack is the trigger, but the backup gap is the reason it is fatal instead of merely awful. The work that makes the first hour survivable happens months earlier, quietly, when nothing is wrong.
That is the work we do for managed clients: tested backups, an isolated copy ransomware cannot reach, EDR that catches the attack before it spreads, and a documented recovery plan so the first hour is a procedure, not a panic. The free IT Health Check includes verifying that your backups would actually restore. If you are not certain they would, that is the most important thing you could find out this month.