Cybersecurity

Ransomware Recovery: What to Do in the First 24 Hours

In brief

In the first 24 hours of a ransomware attack, isolate affected systems from the network, preserve evidence, assemble your response team, identify the scope and strain, report to the FBI and CISA, notify your insurer, and restore from clean, offline backups. CISA advises isolation first, and only powering devices off if you cannot disconnect them. Work the steps in order and stay calm.

The first thing to do in the first 24 hours of a ransomware attack is isolate the affected systems from the network, not power them off or start deleting files. From there the correct order is preserve evidence, assemble a response team, scope the damage, report to law enforcement, notify your insurer, and recover from clean backups. Ransomware feels like chaos, but the response is a checklist, and the businesses that recover fastest are the ones that work that checklist calmly instead of reacting on instinct.

The stakes are highest in the opening hours because that is when the infection is still spreading and when the decisions you make either preserve your options or destroy them. Ransomware is now overwhelmingly a small-business problem. Verizon's 2026 Data Breach Investigations Report found that ransomware appeared in 48% of all breaches it analyzed, up from 44% the prior year, and that 96% of ransomware victims were small organizations. This guide walks the first day hour by hour, grounded in the response steps that CISA and the FBI publish, so you know exactly what to do before the panic sets in. If you would rather have this handled by a team that has done it before, that is what layered cybersecurity services exist to provide.

What should you do in the first 24 hours of a ransomware attack?

In the first 24 hours you follow a fixed sequence, and the order matters as much as the actions. Jumping ahead, wiping a machine before it is imaged, or paying before you understand the scope all remove options you cannot get back. The steps below map to the joint CISA, FBI, NSA, and MS-ISAC #StopRansomware Guide and to how experienced responders actually work an incident.

  • Isolate the affected systems from the network to stop the spread, before anything else.
  • Preserve evidence by imaging systems rather than powering them off or reinstalling.
  • Assemble the response team, including leadership, IT, legal, and your insurer.
  • Scope the incident, identifying which systems and data are affected and which strain hit you.
  • Report to the FBI and CISA, and notify anyone your contracts or regulations require.
  • Recover from clean, offline backups once the environment is contained.

None of this requires paying a ransom on day one, and rushing that decision is a common, expensive mistake. The sections below break the day into windows so a stressed team knows what to do in each one.

Hour 0 to 1: Isolate, do not power off

To contain a ransomware attack, isolate the affected systems from the network immediately, and only power them down if isolation is impossible. CISA's guidance is direct: determine which systems are impacted and isolate them at once, and if several systems appear affected, take the network offline at the switch level. Powering a machine off should be a last resort, used only when you cannot disconnect it, because a hard shutdown can destroy volatile evidence in memory that helps investigators identify the strain and how far it spread.

Practically, that means unplugging network cables, disabling Wi-Fi, and segmenting or shutting down the affected VLANs, while leaving the machines running. Disconnect shared drives and cloud sync so encryption cannot reach mapped storage. Do not log in and out repeatedly, do not run cleanup tools, and do not start restoring yet. The single goal of the first hour is to stop the blast radius from growing, because every additional encrypted system lengthens the recovery you will face later.

Hour 1 to 4: Preserve evidence and assemble the team

Once the spread is contained, protect the evidence and get the right people in the room. Preserving forensic evidence means capturing system images and logs before anything is rebuilt, because those artifacts identify the ransomware variant, the entry point, and whether data was stolen as well as encrypted. Reinstalling a machine to get it working again feels productive, but it erases the trail that tells you how the attackers got in, which is the one thing you must fix before you reconnect anything.

At the same time, activate your incident response plan and assemble the team: an executive who can authorize decisions, IT and security staff or your managed provider, legal counsel, and your cyber insurance carrier. Insurers often require notification within a set window and may direct you to approved forensics and legal partners, so calling them early protects your coverage. Assign one person to keep a running timeline of actions and decisions, since that record matters for insurers, regulators, and law enforcement later.

241 days Mean time for organizations to identify and contain a breach in 2025, the lowest in nine years per IBM. Full containment is a marathon, which is exactly why the disciplined first hours decide how long yours runs. IBM Cost of a Data Breach Report, 2025

Hour 4 to 8: Scope the damage and identify the strain

Scoping the incident answers three questions: which systems are encrypted, which data was accessed or exfiltrated, and which ransomware family is responsible. The ransom note usually names the group or links to a leak site, and services such as the No More Ransom project can match the strain to a free decryptor when one exists. Identifying the variant also tells you whether the attackers likely stole data before encrypting it, which changes your legal and notification obligations entirely.

Modern ransomware is rarely just encryption. Attackers increasingly steal data first and threaten to publish it, a double-extortion tactic that means restoring from backup alone does not end the incident if sensitive records were taken. Determine what was in the affected systems, whether it includes regulated data such as health or payment information, and who would need to be notified. This assessment shapes every decision that follows, from whether you must report a breach to how you communicate with customers.

Should you pay the ransom?

You should not pay the ransom as a first move, and most victims no longer do. The FBI and CISA advise against payment because it funds further criminal activity and never guarantees a working decryption key. Verizon's 2026 report found that 69% of ransomware victims declined to pay, and the deciding factor was reliable backups that let them restore instead of negotiate. Sophos's 2025 survey, by contrast, found 49% of affected organizations did pay, which shows how many are still cornered by inadequate backups.

69% Share of ransomware victims that did not pay the ransom in Verizon's 2026 DBIR. Tested, offline backups were the main reason they could refuse, and the median payment among those who did pay fell to $139,875. Verizon Data Breach Investigations Report, 2026

If backups fail and payment enters the conversation, treat it as a legal and business decision, not a technical one. Involve counsel, your insurer, and law enforcement, because payments to sanctioned entities can carry legal exposure of their own. Even when a victim pays, recovery is not instant or complete: decryptors are often slow and buggy, and some files never come back. Paying is the worst of the available options, which is why the entire first day is built to make it unnecessary.

Report the attack to the FBI, CISA, and your insurer

Report every ransomware attack to law enforcement, ideally within the first day. CISA and the FBI ask victims to report incidents to the FBI Internet Crime Complaint Center or a local FBI field office, and to CISA directly. Reporting is not just civic duty: it can unlock investigative help, decryption assistance, and threat intelligence about the group that hit you, and the FBI's IC3 has helped recover funds in some cases when victims report quickly.

Reporting obligations often go beyond law enforcement. Depending on your state, industry, and the data involved, breach-notification laws and regulations such as HIPAA may require notifying affected individuals and regulators within fixed deadlines, sometimes as short as 72 hours. Your cyber insurance policy will also have its own notice requirements. Miss those windows and you can face penalties on top of the breach itself, so mapping your obligations belongs in the first 24 hours, not the first week.

Hour 8 to 24: Recover from clean backups

Recovery begins only after the environment is contained and the entry point is understood, and the reliable path is restoring from clean, offline backups. Rebuilding onto systems that still contain the attacker's access simply invites reinfection, so the sequence is: confirm the intrusion is closed, rebuild or reimage affected systems from known-good media, restore data from backups that were isolated from the network, and reset credentials across the environment before reconnecting. Rushing to reconnect is how organizations get hit a second time in the same week.

97% Share of organizations that recovered their encrypted data in Sophos's 2025 survey of 3,400 ransomware victims, with 53% back within a week, up from 35% a year earlier. Recovery is achievable, and backups are the mechanism. Sophos State of Ransomware, 2025

The reason preparation matters so much is cost. Sophos put the average cost to recover from a ransomware attack, excluding any ransom, at 1.53 million dollars in 2025, down from 2.73 million the year before but still a figure that would end many small businesses. IBM's 2025 report placed the average data breach at 4.44 million dollars globally, with the United States average at an all-time high of 10.22 million dollars. Those numbers are the downside the first 24 hours exist to shrink.

$1.53M Average cost to recover from a ransomware attack in 2025, excluding any ransom paid, per Sophos. Even down 44% year over year, it dwarfs the cost of the backups and monitoring that prevent it. Sophos State of Ransomware, 2025

Why preparation, not heroics, decides recovery

The first 24 hours go well only when the groundwork is laid before the attack, because you cannot build an incident response plan or an offline backup while your files are encrypting. The organizations that recover fastest have three things ready in advance: isolated, restore-tested backups that ransomware cannot reach, a written response plan with named roles and contact numbers, and monitoring that catches an intrusion early enough to matter. Verizon's data shows exploited vulnerabilities are now a leading entry point, so prompt patching closes the door most attackers walk through.

This is where a managed partner earns its place. Compeint delivers layered cybersecurity services that put isolated backups, endpoint detection and response, multi-factor authentication, and 24/7 monitoring in place, then keeps them current, so a ransomware attempt meets a prepared environment instead of an open one. Our guide to the SMB cybersecurity threats that matter most covers the entry points behind these attacks, and multi-factor authentication closes the credential gap that fuels many of them. The first 24 hours are survivable, but they are far easier to survive when the work was done in the quiet months before.

How do you know how far the ransomware has spread?

You gauge the spread by checking your highest-value systems first, because modern ransomware moves laterally through a network before it reveals itself. Start with the domain controllers, file servers, network-attached storage, and shared drives, then your backup systems, since attackers target these before they encrypt workstations. Multiple machines showing ransom notes, encrypted files across different departments, or shared folders that suddenly will not open all point to a network-wide compromise rather than a single infected device. Look for the entry point, often called patient zero, and trace how the attacker moved, typically through Active Directory, Remote Desktop Protocol, VPN sessions, or synced cloud storage. Assume the whole environment is compromised until forensics proves otherwise, because a machine that looks clean can still be encrypting files silently. Do this checking over out-of-band channels such as phone calls, not the affected network, so you do not tip off an attacker who is still watching. The scope you confirm here sets the size of the recovery ahead.

How to communicate during a ransomware attack

You communicate deliberately and over out-of-band channels, because the network you normally use may be monitored by the attacker. CISA advises using phone calls or other off-network methods so that isolating systems does not alert intruders who could then spread the ransomware faster or destroy evidence. Notify your internal team first with clear instructions on what not to touch, so no one unknowingly reconnects an infected device or restores over a live threat. Bring in leadership, legal counsel, and your cyber insurance carrier early, since insurers often require prompt notice and may direct you to approved forensics partners. External communication with customers, partners, and regulators needs more care: state what you are doing to protect their data and restore service, and avoid technical detail that helps the attacker or creates legal exposure. Assign one spokesperson and keep a single documented timeline. Honest, coordinated messaging protects trust better than silence, and it keeps the response aligned while a stressed team works the checklist.

Which backups actually survive a ransomware attack?

The backups that survive are the ones the attacker cannot reach or alter, which means immutable and air-gapped copies kept off the production network. Immutable backups cannot be changed, encrypted, or deleted once written, even by an administrator account, so compromised credentials do not compromise your recovery. Air-gapped or vaulted copies sit in an environment fully separated from live systems. The 3-2-1 backup rule captures the baseline: keep three copies of your data, on two different media types, with one stored offline and offsite. Just as important, restore-test those backups on a schedule and recover into a clean room, an isolated environment where you scan and validate data before returning it to production, so you do not carry the infection back in. Backups only count if they have been proven to restore, because an untested backup is a hope, not a plan.

94% Share of ransomware victims who said attackers tried to compromise their backups during the attack, per Sophos, and those attempts succeeded 57% of the time. Immutable, air-gapped backups are what defeat that tactic. Sophos State of Ransomware, 2024

Common first-day mistakes that make ransomware worse

The most costly first-day mistakes come from rushing, and each one removes options you cannot get back. Avoid the errors listed below, because they are the ones that turn a contained incident into a repeat attack or a failed recovery.

  • Restoring before eradication, which reinfects clean systems the moment they reconnect to an environment that still holds the attacker's access.
  • Wiping or reimaging machines before capturing a system image, which destroys the forensic trail that tells you how the attackers got in.
  • Paying the ransom fast without exploring backups, decryptors, and counsel, which funds crime and rarely returns all your data.
  • Reconnecting systems too soon, before credentials are reset and the entry point is closed, which reopens the door you just shut.
  • Handling it alone, when your insurer, an incident response team, and law enforcement can shorten recovery and protect your coverage.

Speed matters for isolation, but not for restoration. Move fast to contain, then move carefully to recover, and confirm the intrusion is closed before you declare the incident over.

Related reading

FAQ

What should you do in the first 24 hours of a ransomware attack?

In the first 24 hours, isolate the affected systems from the network, preserve evidence instead of wiping machines, assemble your response team, identify the scope and the ransomware strain, report the incident to the FBI Internet Crime Complaint Center and CISA, notify your cyber insurer, and begin recovery from clean, offline backups. CISA advises isolating impacted systems first and only powering devices down if you cannot disconnect them from the network. Working in that order keeps a bad day from becoming a business-ending one.

Should you turn off your computer during a ransomware attack?

No, do not simply power off machines as a first move. CISA's #StopRansomware Guide advises disconnecting affected systems from the network to contain the spread, and only powering devices down as a last resort if you cannot isolate them. Shutting a machine off can destroy volatile evidence in memory that helps investigators identify the strain and scope, so isolation, not a hard shutdown, is the correct first step.

Should you pay the ransom?

The FBI and CISA advise against paying, because payment funds further crime and never guarantees a working decryptor. Most victims now decline: Verizon's 2026 Data Breach Investigations Report found that 69% of ransomware victims did not pay the ransom, and reliable backups were the main reason they could refuse. Paying is a business and legal decision that should involve counsel, your insurer, and law enforcement, not a reflex made in the first hour.

How long does it take to recover from ransomware?

Recovery time varies widely by preparation. In Sophos's State of Ransomware 2025 survey of 3,400 organizations, 53% recovered within a week, up from 35% the year before, while others took a month or more. The first 24 hours rarely restore full operations, but they decide the trajectory: fast isolation and tested backups shorten recovery, while a hard-shutdown scramble and untested backups stretch it into weeks.

Do you have to report a ransomware attack?

Yes, you should report every ransomware attack to law enforcement, and many businesses face legal reporting duties as well. CISA and the FBI ask victims to report incidents to the FBI Internet Crime Complaint Center or a local FBI field office, which aids investigations and sometimes recovery. Depending on your state and industry, data-breach notification laws and regulations such as HIPAA may also require notifying affected individuals and regulators within set deadlines.

Can you recover ransomware-encrypted files without paying?

Yes. The reliable way to recover without paying is restoring from clean, offline backups that the attacker could not encrypt. In Sophos's 2025 survey, 97% of organizations that had their data encrypted got it back, and backups were a leading recovery method. Free decryptors from the No More Ransom project also work for some strains. Backups only help if they are isolated from the network and restore-tested, so ransomware cannot reach them alongside production data.

How do you know if ransomware has spread across your network?

You check your highest-value systems first, because ransomware usually moves laterally before it shows itself. Ransom notes on several machines, encrypted files across departments, or shared drives that will not open point to a network-wide compromise rather than one infected device. Inspect domain controllers, file servers, network-attached storage, and backup systems, since attackers reach those early, and trace the entry point, or patient zero, through Active Directory, RDP, VPN, or synced cloud storage. Assume the whole environment is affected until forensics proves otherwise, and do the checking over out-of-band channels so you do not alert an attacker who is still watching.

Which systems does ransomware target first?

Ransomware targets your servers and backups first, not individual workstations. Domain controllers, file servers, network-attached storage, and shared drives hold the most valuable data and are the primary targets, and attackers often go after backup systems early to remove your ability to recover without paying. Cloud storage connected through local sync folders can encrypt rapidly as well. Workstations often show visible symptoms first, but the real business impact comes from server and infrastructure compromise, so prioritize checking and protecting those critical systems immediately.

What are the most common mistakes to avoid after a ransomware attack?

The most common mistakes come from rushing recovery. The biggest is restoring from backups before the ransomware is fully removed, which reinfects clean systems the moment they reconnect. Others include wiping or reimaging machines before capturing a forensic image, paying the ransom before exploring backups and free decryptors, reconnecting systems before credentials are reset and the entry point is closed, and trying to handle the incident alone instead of involving your insurer, an incident response team, and law enforcement. Move fast to isolate, then move carefully to recover.

When is it safe to reconnect systems after a ransomware attack?

It is safe to reconnect only after the intrusion is closed, affected systems are rebuilt from known-good images, credentials are reset, and the environment has been scanned and validated for reinfection. Rebuilding onto systems that still hold the attacker's access simply invites a second attack, so confirm the entry point is fixed before you restore data or bring machines back online. Restore into a clean, isolated network segment, add only verified clean systems to it, and let your IT or security authority formally declare the incident over based on defined criteria rather than reconnecting under pressure to resume operations.

Be ready before the worst day

Make a ransomware attack survivable

We review your backups, monitoring, and response plan against the way real attacks unfold, then show you exactly where the gaps are, with no obligation.

Book Your Assessment