Cybersecurity
The Clock Starts Now
When you detect ransomware, the decisions you make in the first 24 hours will determine how well you recover. Here's what to do.
Hour 0–2: Contain the Incident
Isolate affected systems immediately — Disconnect from the network but do not shut down (memory forensics may be needed).
Alert your incident response team — Activate your IR plan and engage external support if needed.
Preserve evidence — Take snapshots of affected systems before any remediation.
Hour 2–6: Assess the Damage
- Identify the ransomware variant (check ID Ransomware)
- Determine the blast radius — which systems are encrypted?
- Check if data exfiltration occurred before encryption
- Identify the initial access vector
Hour 6–12: Notify Stakeholders
- Brief executive leadership and legal counsel
- Assess regulatory notification obligations (GDPR, NCA, etc.)
- Engage cyber insurance if applicable
- Do NOT pay the ransom without legal advice
Hour 12–24: Begin Recovery
- Start restoring from clean backups
- Rebuild affected systems from known-good images
- Patch the vulnerability that allowed initial access
- Monitor for persistence mechanisms
Prevention is Better than Response
The best ransomware response is one you never need. Invest in offline backups, endpoint detection, and employee awareness training.
#Cybersecurity