Ransomware, viruses and malware

First 60 Minutes of a Ransomware Attack: Isolate, Preserve, Call

Ransomware is loud. Files rename themselves, shares fill with ransom notes, and the phone starts ringing. The temptation is to fix it immediately. The first hour is not about fixing. It is about stopping the spread, keeping evidence intact, and getting the right people involved so the recovery that follows is clean.

This is the checklist we use. Print it and keep a copy off the network, because when you need it your file server may already be encrypted.

Minute 0 to 10: stop the spread

Ransomware spreads over the network. Every minute a compromised machine stays connected is another share, another server, another backup target it can reach. Isolation comes first, and isolation means the network, not the power.

Do not shut machines down. Powering off destroys memory, which holds running processes, injected code and sometimes the encryption keys the responders will want. Pull the cable or disable the switch port instead.

  1. Unplug the network cable on any machine showing ransom notes or files being renamed. On Wi-Fi laptops, turn the radio off.
  2. If the spread is broad, shut down the uplink on the core switch or the firewall LAN interface. Losing internet for an hour is cheaper than losing a second site.
  3. Disable the WAN so the attacker loses remote access. Leave the firewall itself running so its logs survive.
  4. Disconnect backup storage: unplug the NAS, pause replication, and revoke the backup service account's session if the backup server is domain joined.
  5. Change the passwords on Domain Admin and any account that touches backups, from a machine you trust.

Minute 10 to 30: preserve what the responders will need

Everything you do from here on will be asked about later, by insurance, by a forensics firm, possibly by law enforcement. Start a written timeline now. Time, action, who did it. A notes app on a phone is fine.

Collect the ransom note and keep one encrypted sample file. The note usually identifies the group, and that identity drives the rest of the response: whether a decryptor exists, whether sanctions apply, what the group typically does with stolen data.

  • Photograph screens before anyone closes windows. Capture the note, the wallpaper, the file extension.
  • Copy the ransom note text file and one small encrypted file to a USB drive. Do not run anything from that drive on a clean machine.
  • Note which machines were touched and in what order. The first machine to show symptoms is often not patient zero, but it is a clue.
  • Export firewall and VPN logs to a clean laptop now, before any retention window rolls them off.
  • Leave the affected machines on and disconnected. Do not run antivirus scans, do not reboot, do not start restoring.

Minute 30 to 45: make the calls

Ransomware response is a team sport and most of the team is outside the building. If you carry cyber insurance, call the carrier's hotline before you engage anyone else. Most policies require you to use their approved incident response and legal firms, and a well-meaning call to your own consultant can complicate the claim.

The order matters. Insurance first, because they fund and direct the rest. Then legal counsel, because from this point communications should be privileged. Then your IT provider, if you have one, to start scoping.

  1. Cyber insurance hotline. Have the policy number and the ransom note ready.
  2. Breach counsel, usually assigned by the carrier. They decide who talks to whom.
  3. Your managed service provider or internal IT lead. Share the timeline so far.
  4. Ownership or executive leadership. Short, factual, no speculation about cause.
  5. If you handle regulated data, note the clock. Reporting windows for HIPAA, state breach laws and contractual obligations start now, not when you finish cleanup.

Minute 45 to 60: set up to work

By the end of the first hour the fire is contained and the right people are on the way. Use the last fifteen minutes to set up the environment you will work from for the next several days.

Assume email is compromised. Attackers who deployed ransomware often had mailbox access first and will read your recovery plans. Move coordination to a channel they cannot see: a phone bridge, a personal Signal group, or a fresh Microsoft 365 tenant if you have one available.

  • Build a clean laptop from known-good media, not from your imaging server.
  • Decide who is allowed to touch what. During an incident, one person changing a firewall rule without telling anyone can undo an hour of work.
  • Start an inventory: every server, every workstation, every backup copy, with a status column. This becomes the recovery plan.
  • Pull your backup reports from the last two weeks. You need to know the last verified good restore point before anyone asks.

Frequently asked questions

Should I turn off the affected server to stop the encryption?

No. Disconnect it from the network instead. Powering off wipes memory that forensic responders use to identify the malware and, in some cases, recover keys. Encryption of that one machine is already underway; your goal is to stop it reaching others.

Can I start restoring from backup right away?

Not until the entry point is closed and the backups are confirmed clean. Restoring into a network the attacker still controls means restoring twice. Use the first hour to contain, not to rebuild.

What if we do not have cyber insurance or a response firm on retainer?

Contain the spread exactly the same way, then engage an incident response firm directly. RackLedge can take that first call and help you scope what is affected while you line up counsel.

Takeaway

The first hour decides how long the rest of the recovery takes. Disconnect rather than power off, write everything down, and call insurance before you call anyone else. Fixing comes later, and it goes faster when the evidence is intact and the attacker has been locked out.

Related posts

More ransomware, viruses and malware

Need a hand with this?

Tell us what you are running and what is slowing you down. You get a straight assessment and a plan, with no obligation. Support desk is staffed 24/7.

Get in touch