Cybersecurity

Ransomware Recovery: What to Do in the First 24 Hours

In brief

In the first 24 hours of a ransomware attack, isolate affected systems from the network, preserve evidence, assemble your response team, identify the scope and strain, report to the FBI and CISA, notify your insurer, and restore from clean, offline backups. CISA advises isolation first, and only powering devices off if you cannot disconnect them. Work the steps in order and stay calm.

The first thing to do in the first 24 hours of a ransomware attack is isolate the affected systems from the network, not power them off or start deleting files. From there the correct order is preserve evidence, assemble a response team, scope the damage, report to law enforcement, notify your insurer, and recover from clean backups. Ransomware feels like chaos, but the response is a checklist, and the businesses that recover fastest are the ones that work that checklist calmly instead of reacting on instinct.

The stakes are highest in the opening hours because that is when the infection is still spreading and when the decisions you make either preserve your options or destroy them. Ransomware is now overwhelmingly a small-business problem. Verizon's 2026 Data Breach Investigations Report found that ransomware appeared in 48% of all breaches it analyzed, up from 44% the prior year, and that 96% of ransomware victims were small organizations. This guide walks the first day hour by hour, grounded in the response steps that CISA and the FBI publish, so you know exactly what to do before the panic sets in. If you would rather have this handled by a team that has done it before, that is what layered cybersecurity services exist to provide.

What should you do in the first 24 hours of a ransomware attack?

In the first 24 hours you follow a fixed sequence, and the order matters as much as the actions. Jumping ahead, wiping a machine before it is imaged, or paying before you understand the scope all remove options you cannot get back. The steps below map to the joint CISA, FBI, NSA, and MS-ISAC #StopRansomware Guide and to how experienced responders actually work an incident.

  • Isolate the affected systems from the network to stop the spread, before anything else.
  • Preserve evidence by imaging systems rather than powering them off or reinstalling.
  • Assemble the response team, including leadership, IT, legal, and your insurer.
  • Scope the incident, identifying which systems and data are affected and which strain hit you.
  • Report to the FBI and CISA, and notify anyone your contracts or regulations require.
  • Recover from clean, offline backups once the environment is contained.

None of this requires paying a ransom on day one, and rushing that decision is a common, expensive mistake. The sections below break the day into windows so a stressed team knows what to do in each one.

Hour 0 to 1: Isolate, do not power off

To contain a ransomware attack, isolate the affected systems from the network immediately, and only power them down if isolation is impossible. CISA's guidance is direct: determine which systems are impacted and isolate them at once, and if several systems appear affected, take the network offline at the switch level. Powering a machine off should be a last resort, used only when you cannot disconnect it, because a hard shutdown can destroy volatile evidence in memory that helps investigators identify the strain and how far it spread.

Practically, that means unplugging network cables, disabling Wi-Fi, and segmenting or shutting down the affected VLANs, while leaving the machines running. Disconnect shared drives and cloud sync so encryption cannot reach mapped storage. Do not log in and out repeatedly, do not run cleanup tools, and do not start restoring yet. The single goal of the first hour is to stop the blast radius from growing, because every additional encrypted system lengthens the recovery you will face later.

Hour 1 to 4: Preserve evidence and assemble the team

Once the spread is contained, protect the evidence and get the right people in the room. Preserving forensic evidence means capturing system images and logs before anything is rebuilt, because those artifacts identify the ransomware variant, the entry point, and whether data was stolen as well as encrypted. Reinstalling a machine to get it working again feels productive, but it erases the trail that tells you how the attackers got in, which is the one thing you must fix before you reconnect anything.

At the same time, activate your incident response plan and assemble the team: an executive who can authorize decisions, IT and security staff or your managed provider, legal counsel, and your cyber insurance carrier. Insurers often require notification within a set window and may direct you to approved forensics and legal partners, so calling them early protects your coverage. Assign one person to keep a running timeline of actions and decisions, since that record matters for insurers, regulators, and law enforcement later.

241 days Mean time for organizations to identify and contain a breach in 2025, the lowest in nine years per IBM. Full containment is a marathon, which is exactly why the disciplined first hours decide how long yours runs. IBM Cost of a Data Breach Report, 2025

Hour 4 to 8: Scope the damage and identify the strain

Scoping the incident answers three questions: which systems are encrypted, which data was accessed or exfiltrated, and which ransomware family is responsible. The ransom note usually names the group or links to a leak site, and services such as the No More Ransom project can match the strain to a free decryptor when one exists. Identifying the variant also tells you whether the attackers likely stole data before encrypting it, which changes your legal and notification obligations entirely.

Modern ransomware is rarely just encryption. Attackers increasingly steal data first and threaten to publish it, a double-extortion tactic that means restoring from backup alone does not end the incident if sensitive records were taken. Determine what was in the affected systems, whether it includes regulated data such as health or payment information, and who would need to be notified. This assessment shapes every decision that follows, from whether you must report a breach to how you communicate with customers.

Should you pay the ransom?

You should not pay the ransom as a first move, and most victims no longer do. The FBI and CISA advise against payment because it funds further criminal activity and never guarantees a working decryption key. Verizon's 2026 report found that 69% of ransomware victims declined to pay, and the deciding factor was reliable backups that let them restore instead of negotiate. Sophos's 2025 survey, by contrast, found 49% of affected organizations did pay, which shows how many are still cornered by inadequate backups.

69% Share of ransomware victims that did not pay the ransom in Verizon's 2026 DBIR. Tested, offline backups were the main reason they could refuse, and the median payment among those who did pay fell to $139,875. Verizon Data Breach Investigations Report, 2026

If backups fail and payment enters the conversation, treat it as a legal and business decision, not a technical one. Involve counsel, your insurer, and law enforcement, because payments to sanctioned entities can carry legal exposure of their own. Even when a victim pays, recovery is not instant or complete: decryptors are often slow and buggy, and some files never come back. Paying is the worst of the available options, which is why the entire first day is built to make it unnecessary.

Report the attack to the FBI, CISA, and your insurer

Report every ransomware attack to law enforcement, ideally within the first day. CISA and the FBI ask victims to report incidents to the FBI Internet Crime Complaint Center or a local FBI field office, and to CISA directly. Reporting is not just civic duty: it can unlock investigative help, decryption assistance, and threat intelligence about the group that hit you, and the FBI's IC3 has helped recover funds in some cases when victims report quickly.

Reporting obligations often go beyond law enforcement. Depending on your state, industry, and the data involved, breach-notification laws and regulations such as HIPAA may require notifying affected individuals and regulators within fixed deadlines, sometimes as short as 72 hours. Your cyber insurance policy will also have its own notice requirements. Miss those windows and you can face penalties on top of the breach itself, so mapping your obligations belongs in the first 24 hours, not the first week.

Hour 8 to 24: Recover from clean backups

Recovery begins only after the environment is contained and the entry point is understood, and the reliable path is restoring from clean, offline backups. Rebuilding onto systems that still contain the attacker's access simply invites reinfection, so the sequence is: confirm the intrusion is closed, rebuild or reimage affected systems from known-good media, restore data from backups that were isolated from the network, and reset credentials across the environment before reconnecting. Rushing to reconnect is how organizations get hit a second time in the same week.

97% Share of organizations that recovered their encrypted data in Sophos's 2025 survey of 3,400 ransomware victims, with 53% back within a week, up from 35% a year earlier. Recovery is achievable, and backups are the mechanism. Sophos State of Ransomware, 2025

The reason preparation matters so much is cost. Sophos put the average cost to recover from a ransomware attack, excluding any ransom, at 1.53 million dollars in 2025, down from 2.73 million the year before but still a figure that would end many small businesses. IBM's 2025 report placed the average data breach at 4.44 million dollars globally, with the United States average at an all-time high of 10.22 million dollars. Those numbers are the downside the first 24 hours exist to shrink.

$1.53M Average cost to recover from a ransomware attack in 2025, excluding any ransom paid, per Sophos. Even down 44% year over year, it dwarfs the cost of the backups and monitoring that prevent it. Sophos State of Ransomware, 2025

Why preparation, not heroics, decides recovery

The first 24 hours go well only when the groundwork is laid before the attack, because you cannot build an incident response plan or an offline backup while your files are encrypting. The organizations that recover fastest have three things ready in advance: isolated, restore-tested backups that ransomware cannot reach, a written response plan with named roles and contact numbers, and monitoring that catches an intrusion early enough to matter. Verizon's data shows exploited vulnerabilities are now a leading entry point, so prompt patching closes the door most attackers walk through.

This is where a managed partner earns its place. Compeint delivers layered cybersecurity services that put isolated backups, endpoint detection and response, multi-factor authentication, and 24/7 monitoring in place, then keeps them current, so a ransomware attempt meets a prepared environment instead of an open one. Our guide to the SMB cybersecurity threats that matter most covers the entry points behind these attacks, and multi-factor authentication closes the credential gap that fuels many of them. The first 24 hours are survivable, but they are far easier to survive when the work was done in the quiet months before.

Related reading

FAQ

What should you do in the first 24 hours of a ransomware attack?

In the first 24 hours, isolate the affected systems from the network, preserve evidence instead of wiping machines, assemble your response team, identify the scope and the ransomware strain, report the incident to the FBI Internet Crime Complaint Center and CISA, notify your cyber insurer, and begin recovery from clean, offline backups. CISA advises isolating impacted systems first and only powering devices down if you cannot disconnect them from the network. Working in that order keeps a bad day from becoming a business-ending one.

Should you turn off your computer during a ransomware attack?

No, do not simply power off machines as a first move. CISA's #StopRansomware Guide advises disconnecting affected systems from the network to contain the spread, and only powering devices down as a last resort if you cannot isolate them. Shutting a machine off can destroy volatile evidence in memory that helps investigators identify the strain and scope, so isolation, not a hard shutdown, is the correct first step.

Should you pay the ransom?

The FBI and CISA advise against paying, because payment funds further crime and never guarantees a working decryptor. Most victims now decline: Verizon's 2026 Data Breach Investigations Report found that 69% of ransomware victims did not pay the ransom, and reliable backups were the main reason they could refuse. Paying is a business and legal decision that should involve counsel, your insurer, and law enforcement, not a reflex made in the first hour.

How long does it take to recover from ransomware?

Recovery time varies widely by preparation. In Sophos's State of Ransomware 2025 survey of 3,400 organizations, 53% recovered within a week, up from 35% the year before, while others took a month or more. The first 24 hours rarely restore full operations, but they decide the trajectory: fast isolation and tested backups shorten recovery, while a hard-shutdown scramble and untested backups stretch it into weeks.

Do you have to report a ransomware attack?

Yes, you should report every ransomware attack to law enforcement, and many businesses face legal reporting duties as well. CISA and the FBI ask victims to report incidents to the FBI Internet Crime Complaint Center or a local FBI field office, which aids investigations and sometimes recovery. Depending on your state and industry, data-breach notification laws and regulations such as HIPAA may also require notifying affected individuals and regulators within set deadlines.

Can you recover ransomware-encrypted files without paying?

Yes. The reliable way to recover without paying is restoring from clean, offline backups that the attacker could not encrypt. In Sophos's 2025 survey, 97% of organizations that had their data encrypted got it back, and backups were a leading recovery method. Free decryptors from the No More Ransom project also work for some strains. Backups only help if they are isolated from the network and restore-tested, so ransomware cannot reach them alongside production data.

Be ready before the worst day

Make a ransomware attack survivable

We review your backups, monitoring, and response plan against the way real attacks unfold, then show you exactly where the gaps are, with no obligation.

Book Your Assessment