Ransomware & ThreatsInformational

Hit by ransomware? A first 24-hour recovery playbook

What to do, who to call and what not to touch in the first day of a ransomware incident.

29 January 2026 7 min read
Hit by ransomware? A first 24-hour recovery playbook — Ransomware & Threats illustration

The first 24 hours of a ransomware incident shape the next 24 weeks. The decisions you make in the first hour — particularly what you turn off and who you call — often matter more than the technical recovery itself.

Hour 1 — Contain, don't panic

  1. Disconnect affected machines from the network (Wi-Fi off, cable out). Do not power them off — memory contents help investigation.
  2. Isolate, don't wipe. You'll need the evidence later.
  3. Engage your incident response provider or MDR partner immediately. If you don't have one, call your cyber insurer's hotline.
  4. Start a written timeline. Every action, with timestamp.

Hours 2–6 — Assess scope

  • Identify which systems are encrypted, which are merely affected, and which are clean.
  • Check cloud services (M365, Google Workspace, file sync) — many ransomware incidents now reach SaaS.
  • Review backup integrity. Confirm whether immutable copies survived.
  • Preserve logs from firewalls, EDR, identity providers and email gateways.

Hours 6–12 — Communicate

  • Brief the leadership team with what is known, what is unknown and what is assumed.
  • Engage legal counsel early — there are likely regulatory and contractual notification obligations.
  • Notify the ICO within 72 hours if personal data is affected. Don't wait for certainty.
  • Prepare a holding statement for staff and key clients. Silence is worse than a careful update.

Hours 12–24 — Plan recovery

  • Build a recovery sequence: identity first, then core business systems, then everything else.
  • Do not pay the ransom without legal, insurer and law enforcement input. Often it doesn't even decrypt cleanly.
  • Report to Action Fraud and the NCSC.
  • Begin restoring from clean backups into an isolated environment before reconnecting.

What NOT to do

  • Don't wipe machines before forensic capture.
  • Don't email the attacker from your normal account.
  • Don't restore straight back into the compromised network.
  • Don't promise customers a timeline you can't keep.

Next step

If you don't have an incident response partner in place today, that's the gap to close before you need one. Book a free 30-minute review and we'll talk you through a realistic IR setup for your size of business.

Related services

Free cyber security review

Get a plain-English view of where your business stands.

30 minutes with a UK specialist. No obligation, no sales pitch.

Book my free cyber security review