Ransomware Recovery: The First 24 Hours, Step by Step
You walk in Monday morning and every file on the server ends in a weird extension, and there's a text file demanding payment. If ransomware hits your business, the first 24 hours decide most of the outcome. The short version: disconnect infected machines from the network (don't wipe or power them off), call your cyber insurance carrier's breach hotline, don't pay or communicate with the attacker on your own, verify your backups are intact and offline, and bring in incident response help before you touch anything else. Here's the full playbook, hour by hour.
What should you do in the first hour of a ransomware attack?
Isolate first, investigate second. Physically disconnect infected machines from the network — pull Ethernet cables, disable Wi-Fi, and if it's spreading fast, shut down switch ports or the whole network segment. Leave machines powered on to preserve evidence. Then call your cyber insurance carrier's 24/7 breach line and your IT provider. Do not delete anything, do not reboot servers "to see if it helps," and do not email from potentially compromised accounts.
That last point matters more than people expect. Attackers frequently sit inside a compromised Microsoft 365 tenant reading email during an incident. If you need to coordinate response, use phone calls and personal cell numbers until someone verifies your email is clean.
Isolation is also why segmented networks and offline backups pay for themselves. Ransomware crews specifically hunt for backup servers and connected backup drives before they trigger encryption — if your only backup is a USB drive plugged into the infected server, assume it's encrypted too. This is the scenario a proper backup and disaster recovery setup is designed to survive.
The first 24 hours, step by step
Every incident is different, but for a typical 5–100 employee business, the first day looks like this:
| Timeframe | Action | Why it matters |
|---|---|---|
| Hour 0–1 | Disconnect infected machines from the network; leave them powered on | Stops the spread while preserving forensic evidence in memory |
| Hour 0–2 | Call your cyber insurance breach hotline; open a claim | Late notice can void coverage; carriers supply IR firms and breach counsel |
| Hour 1–3 | Notify your IT provider or internal IT; start an incident log | A written timeline (who did what, when) is required for insurance and any legal process |
| Hour 2–6 | Verify backups: are they intact, offline, and how recent? | This single answer determines whether you restore or negotiate |
| Hour 3–8 | Identify scope: which systems, which data, which ransomware strain | Photograph the ransom note; the strain determines decryption options and data-theft likelihood |
| Hour 6–12 | Reset credentials from a clean device: admin accounts, Microsoft 365, VPN, remote access | Attackers keep stolen passwords; restoring without resets invites reinfection |
| Hour 8–16 | Breach counsel assesses notification duties (state law, HIPAA, contracts) | California and federal rules have deadlines that start ticking early |
| Hour 12–24 | Begin restoring priority systems to clean hardware or isolated networks | Restore only after the entry point is identified — otherwise you're rebuilding a house that's still on fire |
| Hour 12–24 | Report to the FBI (IC3) and CISA | Helps law enforcement, and insurers and regulators look for it |
Notice what's not in the first 24 hours: paying, negotiating, or emailing the attacker. If negotiation ever happens, it happens through professionals your insurer engages.
Should you pay the ransom?
Treat payment as a last resort that only professionals put on the table. Industry data consistently shows a meaningful share of paying victims never get all their data back, and decryptors provided by criminals are often slow and buggy. Payment can also violate U.S. sanctions if the group is on the OFAC list — that's your legal problem, not the attacker's. And paying advertises that you pay.
The honest math: third-party reports in recent years have put median small-business ransom demands in the tens of thousands of dollars, while average total incident costs — downtime, recovery labor, lost revenue — routinely run several times the ransom itself. Paying doesn't make the expensive part go away. Refusing to pay is only realistic, though, if your backups actually work — which is a decision you make before the attack, not during it.
Not sure your backups would survive a real attack? Book a free IT assessment and we'll tell you where you stand.
How do you restore without getting reinfected?
Never restore onto a network the attacker still controls. Before restoring, you need three things: the entry point identified and closed (usually a phished account, exposed remote access, or an unpatched system), all credentials reset, and endpoint detection deployed so a lurking attacker gets spotted. Then restore priority systems first — the line-of-business app, email, file shares — onto cleaned or rebuilt machines, ideally on an isolated network segment while you verify.
Rushing this step is the most common self-inflicted wound we see. A business restores everything on day two, the attacker's backdoor is still on one forgotten workstation, and week later they're encrypted again — this time with the fresh backups poisoned too. A methodical restore with monitoring beats a fast one.
This is also where the difference between "we have backups" and "we have tested backups" shows up. If nobody has ever timed a full restore of your main server, you don't know your recovery time — you have a guess. Businesses in Sacramento's regulated sectors, like medical and dental practices, face notification deadlines that make that guess expensive.
How do you make sure this never happens again?
The post-incident fix list is remarkably consistent: multi-factor authentication everywhere (especially email and remote access), endpoint detection and response on every machine, patching on a real schedule, security awareness training so staff spot the phishing email that starts most of these incidents, and backups that are offline or immutable and tested quarterly. None of this is exotic — it's the standard small-business cybersecurity stack, and it's also what cyber insurers now require before they'll write or renew a policy.
The pattern behind most small-business ransomware cases is not a genius attacker. It's one reused password, one machine missing patches, or one remote-access tool nobody remembered was there. The businesses that recover in days instead of weeks are the ones that decided, in advance, that boring fundamentals were worth doing.
If you'd rather find your weak spots in a conference room than in a ransom note, that's exactly what an assessment is for. And if you already have IT staff who'd want backup during a crisis, a co-managed arrangement means the incident response muscle is already on your team before you need it.