Ransomware Recovery: The First 24 Hours, Step by Step

You walk in Monday morning and every file on the server ends in a weird extension, and there's a text file demanding payment. If ransomware hits your business, the first 24 hours decide most of the outcome. The short version: disconnect infected machines from the network (don't wipe or power them off), call your cyber insurance carrier's breach hotline, don't pay or communicate with the attacker on your own, verify your backups are intact and offline, and bring in incident response help before you touch anything else. Here's the full playbook, hour by hour.

What should you do in the first hour of a ransomware attack?

Isolate first, investigate second. Physically disconnect infected machines from the network — pull Ethernet cables, disable Wi-Fi, and if it's spreading fast, shut down switch ports or the whole network segment. Leave machines powered on to preserve evidence. Then call your cyber insurance carrier's 24/7 breach line and your IT provider. Do not delete anything, do not reboot servers "to see if it helps," and do not email from potentially compromised accounts.

That last point matters more than people expect. Attackers frequently sit inside a compromised Microsoft 365 tenant reading email during an incident. If you need to coordinate response, use phone calls and personal cell numbers until someone verifies your email is clean.

Isolation is also why segmented networks and offline backups pay for themselves. Ransomware crews specifically hunt for backup servers and connected backup drives before they trigger encryption — if your only backup is a USB drive plugged into the infected server, assume it's encrypted too. This is the scenario a proper backup and disaster recovery setup is designed to survive.

The first 24 hours, step by step

Every incident is different, but for a typical 5–100 employee business, the first day looks like this:

Timeframe Action Why it matters
Hour 0–1 Disconnect infected machines from the network; leave them powered on Stops the spread while preserving forensic evidence in memory
Hour 0–2 Call your cyber insurance breach hotline; open a claim Late notice can void coverage; carriers supply IR firms and breach counsel
Hour 1–3 Notify your IT provider or internal IT; start an incident log A written timeline (who did what, when) is required for insurance and any legal process
Hour 2–6 Verify backups: are they intact, offline, and how recent? This single answer determines whether you restore or negotiate
Hour 3–8 Identify scope: which systems, which data, which ransomware strain Photograph the ransom note; the strain determines decryption options and data-theft likelihood
Hour 6–12 Reset credentials from a clean device: admin accounts, Microsoft 365, VPN, remote access Attackers keep stolen passwords; restoring without resets invites reinfection
Hour 8–16 Breach counsel assesses notification duties (state law, HIPAA, contracts) California and federal rules have deadlines that start ticking early
Hour 12–24 Begin restoring priority systems to clean hardware or isolated networks Restore only after the entry point is identified — otherwise you're rebuilding a house that's still on fire
Hour 12–24 Report to the FBI (IC3) and CISA Helps law enforcement, and insurers and regulators look for it

Notice what's not in the first 24 hours: paying, negotiating, or emailing the attacker. If negotiation ever happens, it happens through professionals your insurer engages.

Should you pay the ransom?

Treat payment as a last resort that only professionals put on the table. Industry data consistently shows a meaningful share of paying victims never get all their data back, and decryptors provided by criminals are often slow and buggy. Payment can also violate U.S. sanctions if the group is on the OFAC list — that's your legal problem, not the attacker's. And paying advertises that you pay.

The honest math: third-party reports in recent years have put median small-business ransom demands in the tens of thousands of dollars, while average total incident costs — downtime, recovery labor, lost revenue — routinely run several times the ransom itself. Paying doesn't make the expensive part go away. Refusing to pay is only realistic, though, if your backups actually work — which is a decision you make before the attack, not during it.

Not sure your backups would survive a real attack? Book a free IT assessment and we'll tell you where you stand.

How do you restore without getting reinfected?

Never restore onto a network the attacker still controls. Before restoring, you need three things: the entry point identified and closed (usually a phished account, exposed remote access, or an unpatched system), all credentials reset, and endpoint detection deployed so a lurking attacker gets spotted. Then restore priority systems first — the line-of-business app, email, file shares — onto cleaned or rebuilt machines, ideally on an isolated network segment while you verify.

Rushing this step is the most common self-inflicted wound we see. A business restores everything on day two, the attacker's backdoor is still on one forgotten workstation, and week later they're encrypted again — this time with the fresh backups poisoned too. A methodical restore with monitoring beats a fast one.

This is also where the difference between "we have backups" and "we have tested backups" shows up. If nobody has ever timed a full restore of your main server, you don't know your recovery time — you have a guess. Businesses in Sacramento's regulated sectors, like medical and dental practices, face notification deadlines that make that guess expensive.

How do you make sure this never happens again?

The post-incident fix list is remarkably consistent: multi-factor authentication everywhere (especially email and remote access), endpoint detection and response on every machine, patching on a real schedule, security awareness training so staff spot the phishing email that starts most of these incidents, and backups that are offline or immutable and tested quarterly. None of this is exotic — it's the standard small-business cybersecurity stack, and it's also what cyber insurers now require before they'll write or renew a policy.

The pattern behind most small-business ransomware cases is not a genius attacker. It's one reused password, one machine missing patches, or one remote-access tool nobody remembered was there. The businesses that recover in days instead of weeks are the ones that decided, in advance, that boring fundamentals were worth doing.

If you'd rather find your weak spots in a conference room than in a ransom note, that's exactly what an assessment is for. And if you already have IT staff who'd want backup during a crisis, a co-managed arrangement means the incident response muscle is already on your team before you need it.

Frequently asked questions

Should we pay the ransom?
In almost every case, no — at least not as a first move. Payment doesn't guarantee working decryption, it can create legal exposure if the attacker is on a sanctions list, and it marks you as a payer. Exhaust your backup and recovery options first, and let your cyber insurer and legal counsel drive any payment conversation, not panic.
Should we turn infected computers off?
Disconnect them from the network, but don't power them off unless encryption is actively spreading and you have no other way to stop it. Memory on a running machine can hold encryption keys and forensic evidence that investigators need. Pull the network cable or disable Wi-Fi, leave the machine running, and don't touch it further.
How long does ransomware recovery actually take?
For a small business with clean, tested backups, core systems often come back in one to three days, with full cleanup taking a week or two. Without reliable backups, industry reports put average downtime at roughly three weeks, and some businesses never fully recover. Backup quality is the single biggest factor.
When do we have to notify our cyber insurance carrier?
Immediately — ideally within the first few hours. Most policies require prompt notice and many require you to use the carrier's approved incident response and forensics vendors. Acting first and calling later can jeopardize your claim. Keep your policy number and the carrier's 24/7 breach hotline printed somewhere that isn't on your network.
Do we have to report a ransomware attack to anyone else?
Often, yes. If personal data of California residents was exposed, state breach notification law applies. Regulated businesses — medical, financial, legal — may have HIPAA or other obligations with strict timelines. Reporting to the FBI's IC3 and CISA is encouraged. Your insurer's breach counsel will map out exactly what applies to you.
Can our regular IT person handle a ransomware incident alone?
Usually not well. Ransomware response mixes forensics, negotiation, insurance requirements, and mass restoration — a specialist skill set most generalists touch rarely. The smart play is pairing your existing IT resource with an incident response team, whether from your insurer's panel or a managed security provider who has run this playbook before.

Find out what your IT should be doing for you

Get a free, no-obligation IT assessment — a plain-English report on your security, backups, and support gaps.

Get Your Free IT Assessment