The first 24 hours after a ransomware attack decide how fast and how fully you recover. Isolate infected systems without rebooting them, trigger your incident response plan, call your insurer and a forensics team, preserve evidence, and restore from clean offline backups. Work the steps in order, and do not rush to pay.
A ransomware attack is a timed event, and the clock starts the moment the first file locks. What you do in the opening 24 hours sets the ceiling on your recovery. Contain the spread quickly and preserve the evidence, and you keep every option open. React in a panic, reboot the wrong machine, or wipe a drive too soon, and you close doors you cannot reopen. This guide lays out an ordered, hour-by-hour plan for that first day, grounded in the response steps CISA and the FBI recommend.
The threat is not hypothetical for a smaller company. Ransomware now appears in 44 percent of all data breaches, up 37 percent in a single year, according to Verizon's 2025 Data Breach Investigations Report. That same report found ransomware present in 88 percent of breaches at small and mid-sized organizations, against 39 percent at large enterprises. Attackers reach for smaller firms precisely because their response plans are thin. Strong cybersecurity services shorten the 24-hour scramble by making most of these steps automatic instead of improvised.
In the first 24 hours of a ransomware attack, isolate every infected system without powering it off, activate your incident response plan, and bring in your cyber insurer and a forensics team before you touch recovery. Then preserve logs and evidence, confirm the scope and the strain, and only afterward begin restoring from clean, offline backups. The order matters as much as the actions, because each step protects the one that follows.
The plan below maps the response to a rough timeline. Real incidents rarely run this cleanly, but the sequence holds even when the hours blur together.
To contain ransomware in the first hour, disconnect infected systems from the network without shutting them down. Unplug the ethernet cable, disable Wi-Fi and VPN, and, if several machines are hit, take the network offline at the switch. The goal is to stop the malware from reaching shared drives, servers, and cloud sync folders while it is still spreading. Speed here decides how much of your environment the attack ever touches.
Resist the instinct to power everything down. CISA's #StopRansomware Guide is explicit that rebooting can destroy the encryption keys and forensic artifacts held in a machine's volatile memory, and some strains damage boot files or delete partially encrypted data the moment they detect a restart. Isolate the device and leave it running. Fast, careful containment pays off directly: Sophos found that 44 percent of organizations managed to stop the attack before their data was encrypted in 2025, a six-year high, which is only possible when someone pulls the affected machines off the network in time.
Once the spread is contained, activate your written incident response plan and start the calls, because the next hours are about people, not tooling. Notify executive leadership, legal counsel, and your communications lead so decisions are made deliberately rather than in a hallway. Then contact your cyber insurer without delay, since most policies impose tight reporting windows and route you to an approved forensics and legal panel. If you keep an incident response firm on retainer, this is the moment you are paying for.
Report the attack to the authorities in parallel. CISA's "I've Been Hit By Ransomware" guidance directs victims to report to the FBI through the Internet Crime Complaint Center, and the reason is scale. Ransomware complaints to the FBI rose 9 percent to 3,156 in 2024 and were named the most pervasive threat to US critical infrastructure. Reporting feeds the intelligence that helps investigators track the groups behind these campaigns, and it can open access to decryptors that are already public.
Before you rebuild anything, preserve the evidence and map what the attack actually reached. Investigators need system and firewall logs, memory captures from isolated machines, a copy of the ransom note, and any suspicious files or accounts. Do not delete the malware, wipe drives, or start reimaging in the first rush, because those actions erase the trail that identifies the strain, the entry point, and whether data was stolen before it was encrypted. Forensics is what turns a chaotic incident into a documented one your insurer and regulators will accept.
Confirming scope answers three questions: which systems are encrypted, which backups the attacker touched, and how they got in. That last question matters most for stopping a repeat, and the data points to an obvious first place to look. Sophos reports that exploited vulnerabilities were the number one technical root cause of ransomware attacks for the third year running in 2025, so an unpatched, internet-facing system is the leading suspect. Identify the entry point now, or you will restore your data straight back into the same open door.
For most businesses, the answer is no. Paying funds the criminal operation, carries legal and sanctions risk, and buys only a promise from an attacker. Even a successful payment rarely delivers a clean, complete recovery, and it marks you as a business that pays. The decision belongs to leadership, legal, and your insurer together, made with full knowledge of your backup position, not in the first panicked hour.
The wider trend has turned firmly against paying. Sophos found that 49 percent of organizations that were hit paid the ransom and got their data back in 2025, while Verizon reports that 64 percent of victims now refuse to pay, up from 50 percent two years earlier. The median ransom payment recorded by Verizon fell to $115,000. Those numbers reflect a simple realization: a tested, offline backup is a more dependable route to your files than a decryption key sold by the people who locked them.
To recover safely, restore from clean, offline backups only after the environment is contained and confirmed free of the attacker. Rebuild in a defined order: verify backups are uninfected, restore critical systems first, reset credentials across the environment, and patch the vulnerability that let the attack in before you reconnect anything. Restoring into a network that still contains the intruder is how businesses get encrypted a second time within days.
Backups are the difference between a hard week and an existential crisis, yet they are also a target. Only 54 percent of companies used backups to restore their data in 2025, the lowest rate Sophos has recorded in six years, in part because attackers now go after backup repositories first. Immutable or air-gapped backups the ransomware cannot reach are what make a no-pay recovery possible. When those backups exist and have been tested, recovery is genuinely fast.
Everything you do in the first day feeds the final bill, and the bill is large. The cost of a ransomware incident is not the ransom. It is the downtime, the recovery labor, the lost business, and the long tail of remediation. Contain the attack quickly and restore from backups, and you keep that number in check. Lose the first hours to confusion, and the costs compound while systems stay dark.
The broader breach economics reinforce the point. IBM put the global average cost of a data breach at $4.44 million in 2025, with the US average reaching an all-time high of $10.22 million. The same research ties cost directly to speed: the mean breach lifecycle ran 241 days from detection to containment, and breaches contained faster cost dramatically less. A disciplined first 24 hours is one of the cheapest forms of insurance a business can buy.
The best time to write your first 24 hours is before an attack, not during one. A rehearsed plan turns the panic-driven decisions above into a checklist your team already knows. Preparation is also what separates the businesses that recover in a week from the ones that stay down for a month.
Most small teams cannot build and maintain all of this alone, which is the case for a managed partner. A provider bakes the monitoring, backups, patching, and response plan into everyday operations, so the first 24 hours are already scripted before an attacker ever arrives. That is preparation you use every day, not a binder you hope never to open.
Isolate infected systems from the network without powering them off. Pull the ethernet cable, disable Wi-Fi and VPN, and, if several systems are hit, take the network offline at the switch. CISA advises against rebooting, because a restart can wipe the encryption keys and forensic evidence held in a machine's volatile memory, and some strains damage boot files when they detect one.
No. Disconnect infected machines from the network, but do not shut them down or reboot them. Rebooting erases the RAM that holds encryption keys and forensic artifacts a response team needs to identify the strain, and some ransomware families corrupt the boot configuration or delete partially encrypted files when they detect a restart. Isolate the device and leave it running.
For most businesses the answer is no. Paying funds the criminal operation, carries legal risk, and does not guarantee a full recovery. Sophos found that 49 percent of organizations paid and got data back in 2025, while Verizon reports that 64 percent of victims now refuse to pay, up from 50 percent two years earlier. A tested, offline backup is a more reliable path than an attacker's decryption key.
Recovery time depends on preparation. Sophos reports that 53 percent of organizations fully recovered within a week in 2025, up from 35 percent the year before, while a smaller share still needed more than a month. Businesses with clean, tested offline backups and a rehearsed response plan recover fastest, because they spend the first day restoring rather than deciding what to do.
Yes, in most cases you should report it. Notify your cyber insurer promptly, because policies set tight reporting windows, and report the incident to the FBI through the Internet Crime Complaint Center and to CISA. Depending on your industry and the data involved, breach-notification laws may also require you to inform regulators and affected individuals, so involve legal counsel early.
Yes. The most reliable recovery path is restoring from clean, offline backups after the environment is contained and verified free of the attacker. Sophos found that 54 percent of companies used backups to restore their data in 2025. Immutable or air-gapped backups that the ransomware cannot reach are what make recovery without payment possible, which is why testing restores in advance matters.
Be ready before the clock starts
We review your backups, endpoint security, and response plan, then show you exactly where the gaps are, with no obligation.
Book Your Assessment