What should a business do in the first minutes of a possible ransomware incident?

Isolate affected devices from the network without deleting evidence, activate the responsible team, protect privileged identities and determine the scope before restoring. Coordinate technology, management, legal advice and communications according to the impact.

Risks to review

  • Shut down or reinstall all devices before preserving records and evidence.
  • Connect backups to the compromised environment before containing attacker access.
  • Communicate or negotiate from email accounts that may also be compromised.
  • Restore systems without correcting the initial access path.

Safe recommendations

  1. Disconnect the affected computers from the network and avoid connecting them to other media.
  2. Activate the incident plan and record hours, symptoms, decisions and those responsible.
  3. Review and secure administrative accounts from trusted devices.
  4. Preserve logs, ransom notes, headers, alerts, and samples without altering them.
  5. Validate the integrity and separation of backups before starting recovery.
  6. Communicate through alternative channels and evaluate legal and notification obligations.

Time-based response

First 15 minutes

  • Isolate affected devices from the network without deleting or altering evidence.
  • Alert the responsible people through an alternate, trusted channel.
  • Record the time, visible symptoms and systems initially affected.

First hour

  • Protect administrator accounts from trusted devices.
  • Preserve logs, ransom notes, alerts and traces without modifying them.
  • Determine which systems, locations and backups may be exposed.

First 24 hours and recovery

  • Validate backup integrity and separation before restoring.
  • Coordinate technical, legal and communication decisions according to scope.
  • Restore only after containing access and correcting the identified initial path.

When to seek specialized help

  • There is encryption, exfiltration, server unavailability or multiple affected computers.
  • Backups, hypervisors, email, or administrative accounts may be compromised.
  • The organization does not have a plan, preserved evidence, or personnel to contain the incident.

Reference sources

These public sources provide general good-practice guidance. They do not replace an assessment of your environment.