Skip to content
    August 1, 2026| Top Floor Team| 11 min read

    What to Do in the First 24 Hours After a Ransomware Attack

    Isolate infected machines from the network, but do not power them off. Call your cyber insurer's claims hotline before you engage any vendor. Have outside counsel, not your IT director, hire the forensics firm. Those three moves, made in the first few hours, decide whether you recover in days or months, whether your insurance claim gets paid, and whether the evidence you'll need for the investigation survives until morning. Everything else in the first 24 hours flows from them.

    What follows is the war-room timeline we walk clients through when the call comes in at 2 a.m. Print it, argue with it, adapt it to your environment. Just have it on paper before you need it, because the version of you reading this calmly is not the version who will be executing it.

    Key takeaways

    • Isolate infected machines at the network layer. Do not power them off: a shutdown destroys the running process, resident keys, live connections and injected code, and there is no undo.
    • Call your cyber insurer's claims hotline before you engage any vendor. Policies typically require carrier consent before you incur response costs, and non-panel spend may never be reimbursed.
    • Have outside counsel, not your IT director, retain the forensics firm, so the work product has a plausible claim to legal privilege.
    • Assume data was stolen until forensics proves otherwise, and verify backups by test-restoring one meaningful system into an isolated environment rather than reading a green checkmark.
    • Do not decide on payment on day one. Do work out tonight which notification clocks started at discovery rather than at the end of your investigation.

    Hour 0 to 1: isolate, don't shut down

    The instinct when a ransom note appears on a screen is to pull the power. Resist it.

    Shutting down an infected machine destroys everything held in memory: the running ransomware process, encryption keys that occasionally remain resident in RAM, live network connections back to the attacker's infrastructure, and injected code that exists nowhere on disk. Modern incident forensics leans heavily on memory analysis, and RAM does not survive a reboot. Power down and that evidence is gone. There is no undo.

    What you want instead is isolation. Unplug the network cable, disable Wi-Fi, or trigger your EDR platform's network containment function if you have one. The machine stays powered, the malware keeps running inside a sealed box, and the encryption stops spreading because it can't reach anything new.

    While one person isolates, a second person should be preserving the other evidence that quietly expires on its own:

    • Export firewall, VPN, and DHCP logs now. Many appliances keep days of history, not weeks, and the initial access event may already be near the edge of the retention window.
    • Extend or export cloud audit logs (Microsoft 365, Google Workspace, AWS CloudTrail) before anyone touches retention settings.
    • If your team has memory-capture tooling, image RAM on the suspected patient-zero machines and your domain controllers before anything reboots.
    • Photograph every ransom note, on screen or printed to network printers, and record the time each was found.

    One more move in the first hour: get to your backups before the attacker does. Verify that offline or immutable copies actually exist, then sever any connection between backup repositories and the compromised network. Ransomware crews routinely encrypt or delete backups first, and if the intruder is still active, your backup server is the most valuable target left standing.

    And the do-not list, which matters as much as the do list. Do not reimage anything. Do not run antivirus "cleanup" on infected hosts before they've been imaged. Do not log into compromised systems with domain admin credentials (the attacker is likely harvesting exactly those). Do not discuss the incident over the corporate email tenant you can no longer assume is private.

    Hour 1 to 3: call your insurer before you call anyone else

    Here's the omission that costs companies real money, and it appears in almost none of the generic first-24-hours guides: the call to your cyber insurance carrier has to happen before you engage vendors, not after.

    Most cyber policies are built around a panel: a pre-approved roster of breach counsel, forensics firms, and ransom negotiators the carrier has vetted and priced. The policy language typically requires the carrier's consent before you incur response costs, and non-panel provisions that reduce or condition reimbursement when you hire firms the carrier hasn't approved are common. Read your own form rather than trusting a summary of anyone's, including ours. Sign a six-figure incident response retainer on Friday night, notify the carrier on Monday, and you may find that spend was never covered. We've watched that exact sequence play out, and the argument with the adjuster afterward is one you will not win.

    The claims hotline is staffed around the clock, and the call costs you nothing. Within an hour or two you'll typically be connected to a breach coach (an attorney from the panel), given your panel options for forensics, and told what the policy requires consent for. Ransom payments almost always require carrier sign-off, and some policies require consent even for notification decisions.

    A note on our own interests, since honesty is cheaper than the alternative: if your policy has a panel and Top Floor isn't on it, use the panel firm. Paying out of pocket for a non-panel responder is rarely worth it, and we'll tell you the same thing if you call us first. Where we add value in that scenario is alongside the panel, on recovery, hardening, and the compliance aftermath, not by replacing counsel-directed forensics your carrier won't reimburse.

    Hour 3 to 6: counsel engages forensics, and the order matters

    Once the breach coach is on, the next engagement runs through them: outside counsel retains the digital forensics and incident response (DFIR) firm, and the investigation proceeds at counsel's direction.

    This isn't lawyer theater. When counsel directs the investigation, the forensics work product has a plausible claim to legal privilege, meaning the report may be shielded from discovery if the incident turns into litigation or a regulatory enforcement action. When your IT manager hires the same firm directly and the report circulates as an operations document, courts have ordered those reports handed over to plaintiffs. The findings in a candid forensics report ("logs show the vulnerability was known and unpatched for 14 months") read very differently in a deposition.

    With the DFIR team engaged, their first hours mirror what your team started in hour zero, done properly: forensic memory and disk images of key systems, centralized log collection, identification of the ransomware variant. Then the two questions everything else depends on. How did they get in, and did data leave?

    Your job in parallel is to build the war room:

    • Stand up out-of-band communications. Personal cells, Signal, or a clean external email account. Assume the attacker can read the corporate tenant until forensics says otherwise.
    • Name the roster: one decision-maker with authority to spend money, an IT lead, counsel, a communications owner, and a scribe.
    • The scribe matters more than people expect. A timestamped log of every decision, action, and notification is something your carrier, your regulators, and your own incident response retrospective will all ask for, and nobody can reconstruct it accurately a week later.

    Hour 6 to 12: scope the damage

    By hour 12 you want defensible answers, even rough ones, to four questions: what's encrypted, what was taken, are the backups intact, and what does each day of downtime cost the business.

    Assume data was stolen until forensics proves otherwise. The Verizon DBIR 2026 describes the standard intrusion playbook as deploying ransomware and then "frequently follow[ing] up with the exfiltration of data for future leverage," with some actors skipping encryption and relying on extortion alone. Ransomware appeared in 48% of all breaches that year, up from 44%, and about 96% of the ransomware victims whose size was recorded were small and mid-sized businesses.

    That assumption isn't pessimism, it's what drives the legal analysis. Encrypted-but-not-exfiltrated and exfiltrated are entirely different incidents from a notification standpoint, and the stakes are large either way: IBM's 2026 Cost of a Data Breach report puts the average breach at $4.99 million globally and $11.5 million in the US (vendor-published figures, but the best longitudinal series available).

    On backups, verification means restoration, not a green checkmark in the console. Test-restore one meaningful system into an isolated environment and confirm the data is intact and recent. Two warnings here. First, check restore points against the intrusion timeline; attackers commonly dwell for days or weeks before detonating, and a backup from three days ago may already contain their tooling. Second, do not restore anything into a network the attacker may still occupy. Recovery into a live compromise just hands them the rebuilt systems.

    This window is also when you plan the credential reset with the DFIR team. If ransomware detonated across your environment, treat every domain credential as compromised. A mass password reset, KRBTGT rotation, and in bad cases a staged Active Directory rebuild all need sequencing, because resetting credentials while the attacker retains persistence just alerts them without evicting them.

    Hour 12 to 24: the two decisions

    By the back half of day one, the war room faces the two calls that generic guides skip past.

    The payment question. You don't have to decide today, and you shouldn't. But the framing starts now. Per the Verizon DBIR 2026, 69% of ransomware victims did not pay, and the median payment among those who did fell to $139,875 from $150,000 the previous year. The decision turns on facts your team is still developing: whether backups are viable, whether stolen data gives the attacker a second hold on you independent of decryption, whether the threat actor is on an OFAC sanctions list (paying a sanctioned entity is a federal violation regardless of duress), and whether your carrier consents. Remember what payment actually buys: a decryptor that may work slowly or partially, and a criminal's promise to delete your data. Nothing more.

    The notification clock. Reporting deadlines start running from discovery, not from when you finish investigating, and some are brutally short: 72 hours under GDPR and for covered entities under several US sector rules, less in a few cases. Counsel owns this analysis, but the war room needs to know tonight which clocks may already be ticking. We've mapped the deadlines in detail in our breach notification deadlines guide.

    Round out day one with a short holding statement, drafted with counsel and approved by the decision-maker. Say what you know, commit to updates, and skip the reflexive phrase "sophisticated attack" (it convinces no one and ages badly when the entry point turns out to be a phished password). Brief employees through the out-of-band channel; they'll hear something is wrong regardless, and rumor travels faster than your comms plan.

    Print this: the first-24-hours checklist

    Tape this inside a cabinet. If you're reading it mid-incident, work top to bottom.

    Immediately (hour 0 to 1):

    • Isolate affected systems at the network layer; do not power off or reboot
    • Sever backup repositories from the network; confirm offline/immutable copies exist
    • Capture memory on patient-zero candidates and domain controllers before any reboot
    • Export volatile logs: firewall, VPN, DHCP, cloud audit trails
    • Photograph ransom notes; note discovery times
    • Open a timestamped decision log and assign a scribe

    First calls, in this order (hour 1 to 6):

    1. Cyber insurer claims hotline (before any vendor engagement)

    2. Breach coach / outside counsel, usually assigned from the carrier's panel

    3. DFIR firm, engaged by counsel, not by IT

    4. Executive decision-maker and comms lead, via out-of-band channel

    Never, at any hour:

    • Reimage, wipe, or "clean" a machine that hasn't been forensically imaged
    • Use domain admin credentials on compromised hosts
    • Discuss the incident on the compromised email tenant
    • Contact the attacker or pay anything without counsel and carrier sign-off

    By hour 24:

    • Rough scope: what's encrypted, what's likely exfiltrated, backup status verified by test restore
    • Notification deadline analysis underway with counsel
    • Holding statement drafted; employees briefed out-of-band
    • Credential reset and recovery sequencing planned with forensics

    If you'd rather pressure-test this against your actual environment before it's 2 a.m., that tabletop conversation is exactly what our incident response and digital forensics teams do in peacetime, when it's cheap.

    Frequently asked questions

    Should we pay the ransom?

    Usually no, and never in the first 24 hours. Per the Verizon DBIR 2026, 69% of victims did not pay, and payment buys only a decryptor of uncertain quality plus an unenforceable promise to delete stolen data. The decision depends on backup viability, what data was actually stolen, OFAC sanctions exposure, and your carrier's consent, none of which you'll have settled on day one. Let counsel and your negotiator drive the timing; early silence is itself a negotiating position.

    Do we have to report the attack?

    Very likely yes, and the clock may already be running. Depending on the data involved and your sector, deadlines range from 72 hours (GDPR, and several US regulators) down to shorter windows in specific industries, measured from discovery rather than from the end of your investigation. This is counsel's call to make, but it's your job to raise it on day one. Our breach notification deadlines guide walks through the major regimes and their triggers.

    Can our internal IT team handle the response themselves?

    They can and should handle immediate containment; nobody knows your network better. But the forensic investigation should run through counsel and a specialist DFIR firm, for three practical reasons: privilege protection over the findings, insurance coverage that may hinge on using approved firms, and evidence handling that survives scrutiny. The most common way we see internal teams hurt an investigation isn't incompetence, it's well-intentioned cleanup (rebooting, patching, reimaging) that destroys the record of what happened.

    How long until we're back to normal?

    Longer than the first 24 hours will suggest. Containment happens in hours, but full recovery (credential resets, staged restoration, hardening the entry point, and the notification aftermath) typically runs weeks, and the compliance tail can run months. Plan communications and staffing for a marathon on day one and you'll avoid the credibility hit of repeatedly extending your own deadlines.

    Share Share on LinkedIn

    Need help with your compliance program?

    Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.

    Schedule a Free Consultation

    Get insights like this in your inbox

    Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.

    Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.