Somebody in accounting cannot open a spreadsheet. Then the file server starts throwing errors. Then a text file appears on three desktops with an email address and a deadline. By the time a ransomware event is obvious, the attacker has usually been inside the network for days or weeks, and the encryption is the last step, not the first.
What happens in the next 24 hours decides how much of the business comes back, how much it costs, and whether the same attacker returns in a month. Here is the order that actually works.
Hour zero: contain before you investigate
The instinct is to start fixing. Resist it. The first job is cutting the attacker’s access, because every minute of continued access means more data leaving and more systems encrypted.
- Isolate, do not power off. Pull network cables, disable Wi-Fi, or shut the switch port. Powering a machine down wipes memory that may hold the only evidence of how the attacker got in and what they ran.
- Disconnect backup storage. If a backup target is reachable over the network right now, assume it is a target. Modern ransomware hunts for backups first because destroying them is what forces payment.
- Cut remote access. Disable VPN accounts and any remote desktop exposure at the firewall. Compromised credentials are the most common way back in.
- Assume email is compromised too. If the attack started with a mailbox takeover, your internal messages about the incident are being read. Move coordination to phone calls or a channel that does not touch the affected environment.
Do not do these things
Do not delete the ransom note. Do not run a consumer antivirus scan across the environment hoping it cleans up. Do not restore anything yet. Do not wipe and rebuild the first infected machine, because that machine usually holds the clearest record of what happened.
Hours one to four: notify the right people
Three calls need to happen early, and the order matters less than the fact that all three get made on day one.
- Your incident response resource. Whoever is going to run containment and forensics needs to be working, not scheduled for Thursday.
- Your cyber insurance carrier. Most policies require prompt notice, and many require you to use approved vendors or get approval before engaging anyone. Paying for response work your carrier has not approved is a common way to lose reimbursement.
- Legal counsel. Breach notification obligations depend on what data was reached and who it belonged to. Illinois has its own requirements, and industry rules may stack on top of them. Counsel also shapes how the investigation is documented.
Law enforcement reporting is worth doing, through the FBI’s IC3 portal or a local field office. It rarely recovers data, but it matters for insurance and for any regulatory conversation later.
Hours four to twenty-four: scope, then eradicate
Before anything gets restored, you need answers to two questions: what did they actually reach, and are they still in here?
Scoping means reviewing authentication logs, looking for accounts created or elevated, checking scheduled tasks and services that were added, and identifying which systems the attacker touched versus which ones merely share a subnet. Data exfiltration matters separately from encryption, because if data left the building, you have a notification problem whether or not you recover the files.
Eradication means removing persistence. Attackers routinely leave several ways back in. Cleaning only the obvious one is how a business gets hit twice inside a month. Credential resets need to cover every privileged account, service account, and anything cached where the attacker had access.
Day two onward: restore in the right order
Restoring to a network you have not cleaned reintroduces the compromise. Restoring from a backup that was reachable during the attack can restore the malware along with the data. Restore order should follow the business, not the file system: the systems that generate revenue come back first, on clean hardware or rebuilt machines, into a segmented network.
This is the point where most businesses discover the state of their backup and recovery setup. A backup is a theory until someone restores from it. Immutable offsite copies and tested restores are what turn a bad week into a manageable one.
What to have in place before it happens
The controls that shorten an incident are unglamorous and mostly boring. Multi-factor authentication on email, VPN, and administrative accounts. Endpoint detection and response that watches behavior rather than matching known signatures. Network segmentation so one compromised laptop cannot reach the server room, the finance systems, and the production floor. Current patching on operating systems, firmware, and network gear. A written plan naming who calls whom, readable by somebody who is not you.
Most of that lives in ordinary cybersecurity work and routine managed IT, done consistently, well before anyone needs it.
If you are dealing with an active incident right now, stop reading and make the call. Our incident response page explains what happens after you do, from containment through clean recovery and post-incident hardening. If you are reading this while nothing is on fire, that is the better time to find out whether your backups restore and whether MFA is actually enforced everywhere it should be.