Hit by Ransomware What To Do in the First 24 Hours

Hit by Ransomware? What To Do in the First 24 Hours

Share:

Table of Contents

If you’re being hit by ransomware right now: disconnect affected machines from the network immediately, but do not power them off. Don’t delete anything. Don’t pay yet. Call your IT provider and your cyber insurance carrier before you take any further action contacting the insurer first is often a policy requirement, and acting without them can void your coverage.

Need emergency help in Los Angeles or Orange County? Call (213) 855-3506.

If you’re reading this during an active incident, skip to the checklist below. If you’re reading it beforehand — good. That’s the version of this article that actually helps.

The first hour

What you do in the first sixty minutes determines how much of this you recover and how much it costs.

Disconnect, don’t shut down

Pull affected machines off the network. Unplug the ethernet cable. Turn off Wi-Fi. Isolate them.

 

Do not power them off.

 

This trips up almost everyone, because shutting down feels like stopping the attack. It doesn’t. What it does is wipe the machine’s memory — and memory often holds encryption keys, running process details, and forensic evidence that determines whether recovery is possible at all.

 

Disconnect. Leave it running. Let the responders decide what happens next.

Isolate your backups immediately

Modern ransomware hunts backups first. It knows that a company with clean backups doesn’t pay.

 

If your backups are reachable from the infected network, disconnect them now. Cloud backups — revoke access or disable the sync. Physical backup devices — unplug them.

 

Every minute they stay connected is a minute they might get encrypted too.

Do not delete anything

Not the ransom note. Not suspicious files. Not the strange emails.

 

The instinct to clean up is strong and it’s the wrong instinct. That material tells responders which variant hit you, how it got in, and whether a decryptor exists. Delete it and you’ve destroyed your own case — for recovery, for the insurance claim, and for any legal exposure that follows.

Write down the time

Start a log. Timestamp everything: when you noticed, what you saw, what you did, who you called.

 

You’ll need this for the insurance claim. You may need it for regulators. And two days into a stressful incident, nobody remembers the sequence accurately.

Hours 1–4: Who to call, and in what order

Order matters here.

1. Your IT provider or internal IT lead

They need to start containment and determine the scope. If your provider offers 24/7 emergency response, this is what you pay for.

2. Your cyber insurance carrier

Do this before you engage any outside vendor.

 

Most policies require notification within a specific window — often 24 to 72 hours. Many also require you to use their approved incident response firms. Hire your own forensics team first, and the carrier may refuse to reimburse it.

 

The carrier will typically assign a breach coach — usually a specialized attorney who coordinates everything from there. Let them.

3. Legal counsel

Your carrier’s breach coach often fills this role. If you don’t have cyber coverage, get your own attorney involved early. Data breaches carry notification obligations under California law, and the deadlines are real.

4. Leadership

Whoever needs to make decisions about operations, communication, and money. They should hear it from you, not from a customer.

Who not to call yet

Don’t post about it. Don’t email your whole customer base. Don’t tell staff more than they need to operate safely.

 

Notification obligations are legally specific and time-sensitive. Get advice before you communicate externally — an early, inaccurate statement can create problems that outlast the attack.

Hours 4–12: Working out how bad it is

Your responders will be answering three questions:

 

How did they get in? Usually a phishing email, exposed remote desktop, a stolen password, or an unpatched system. Until you know, you can’t be confident you’ve closed it.

 

How far did they get? Which systems, which data, which accounts. This determines your notification obligations.

 

Is data stolen as well as encrypted? Most modern ransomware groups steal data before encrypting it, then threaten to publish. This is “double extortion,” and it changes everything — because clean backups don’t solve a data leak.

 

Meanwhile, don’t wait to start operating. Get your team on clean devices. Set up temporary communication. Work out what you can run manually.

The question everyone asks: should we pay?

Nobody can answer this for you, and anyone who gives you a fast answer either way isn’t thinking hard enough.

 

Arguments against paying:

 

  • No guarantee. Decryptors are frequently slow, buggy, or partially broken.
  • You’re funding the next attack, on someone else.
  • Paying marks you as a payer. Repeat targeting is common.
  • Payments to certain sanctioned groups can carry legal exposure.

 

Why companies pay anyway:

 

  • Backups failed or got encrypted too.
  • Downtime cost exceeds the ransom, quickly.
  • Stolen data will be published otherwise.

 

What actually decides it: whether your backups are clean and restorable. Companies with tested, isolated backups rarely pay. Companies that discover their backups were also encrypted usually have a much harder conversation.

 

If you have cyber coverage, your breach coach handles negotiation. There are firms that do only this. Don’t negotiate directly.

Hours 12–24: Starting recovery

Recovery isn’t restoring files. It’s rebuilding trust in your environment.

 

Rebuild, don’t clean. Restoring a compromised machine risks leaving the attacker’s access in place. Standard practice is to rebuild from known-good images.

 

Reset every credential. All of them. Assume anything stored on a compromised machine is now in someone else’s hands.

 

Close the entry point first. Restoring before you’ve fixed how they got in is how businesses get hit twice in a month. It happens more than you’d think.

 

Restore in priority order. Whatever gets you operating comes first. Not everything at once.

What this actually costs

Beyond any ransom:

 

  • Incident response and forensics: $20,000 to $100,000+
  • Downtime: highly variable, often the largest number
  • Legal and notification costs
  • Regulatory exposure, depending on your industry
  • Customer churn and reputational damage
  • Insurance premium increases at renewal

 

The full cost typically runs several times whatever the ransom demand was.

The prevention that actually works

Every item below is cheaper than the incident. All of them are also now standard cyber insurance requirements.

 

Offline, immutable backups — tested. The single biggest factor in whether ransomware is a bad week or an existential event. Test restores quarterly and document them.

 

MFA everywhere. Email, VPN, remote desktop, admin accounts, cloud apps. Enforced, not merely available.

 

EDR, not just antivirus. Behavior-based detection catches encryption patterns that signature-based tools miss entirely.

 

Patch fast. Especially anything internet-facing. Attackers scan for known vulnerabilities within days of disclosure.

 

Close or protect remote desktop. Exposed RDP remains one of the most common entry points. If you need it, put it behind a VPN with MFA.

 

Segment your network. So one infected machine in accounting can’t reach your servers.

 

Train your people. Most attacks start with someone clicking. Ongoing training and simulated phishing, not an annual video.

 

Write the incident response plan now. Nobody thinks clearly during a crisis. Decide the sequence while everyone is calm.

 

Frequently asked questions

Should I turn off the infected computer? No. Disconnect it from the network but leave it running. Powering off destroys memory-based evidence that may be needed for recovery and for the insurance claim.

 

How long does ransomware recovery take? With clean, tested backups: often two to seven days for core systems. Without them: weeks, and sometimes the business doesn’t fully recover.

 

Will insurance cover the ransom? Many policies do, but only if you follow the process — notify promptly and use approved vendors. Going off-script can void coverage.

 

Do we have to notify customers? Depends on what data was accessed and which regulations apply. California has specific breach notification requirements. Get legal advice before you decide.

 

Can we just restore from backup and move on? Only if the backups are clean and you’ve closed the entry point. Restoring into a still-compromised environment usually results in a second attack.

 

How do most ransomware attacks start? Phishing emails, exposed remote desktop, stolen or reused credentials, and unpatched internet-facing systems. Those four cover the large majority.

 

Under attack right now?

Call (213) 855-3506.

 

WinC Services provides emergency incident response and ransomware recovery for businesses across Los Angeles and Orange County. Based in Pasadena.

 

Not under attack — want to make sure you’re ready?

 

We’ll assess your backup integrity, test whether a restore actually works, review your MFA and endpoint coverage, and give you a written readiness report.

 

Request a ransomware readiness assessment →

 

Related reading:

 

GROWING TOGETHER SINCE 2023
The latest in IT, cybersecurity, and business tech. Straight to your inbox.
Related Articles

IT Helpdesk Support in Los Angeles: What It Covers, What It Costs You Without It, and How to Choose the Right Partner

Office Network Setup in Pasadena: A Local Guide

Office Network Setup in Anaheim: Offices, Warehouses, and Guest Wi-Fi

Office Network Setup in Irvine: Building for Open-Plan Offices