Skip to content
Stop Ransomware

Resource Center · Ransomware response

Hit by Ransomware? The First Hours, Step by Step

Published 3 July 2026 · Updated 3 July 2026 · 8 min read

The short answer

Immediately isolate affected systems from wired, wireless, VPN and shared-storage connections. Keep a system powered on when safe isolation is possible and evidence preservation is important; if it cannot be isolated promptly and encryption or propagation is continuing, powering it down may be necessary. Protect your recovery options, preserve everything (including the ransom note), move communications off the compromised environment, and get professional responders and your legal/reporting track moving in parallel. Do not pay, promise or negotiate in the first hours — and do not wipe the one machine that can explain what happened.

Minute 0–15: contain, without destroying evidence

“Do we restart? Do we shut down?” — Isolate first.

The decision logic, in order:

  1. Isolate first. A machine cut off from every network can do little further harm — and it still holds its evidence.
  2. Preserve evidence when safe. Keep isolated systems powered on where possible: memory can hold the running malware, attacker tooling and, in some cases, material that later helps recovery. A reboot can also overwrite forensic artifacts.
  3. If isolation is impossible and encryption is actively spreading, follow your incident responder's instructions. CISA recommends powering the device down as a last resort to prevent further spread, while recognizing that volatile forensic evidence may be lost.
  4. Do not reconnect the system once isolated or powered down — not “just to check something”.
  5. Coordinate high-impact decisions with an incident responder. Servers, hypervisors, storage platforms and identity infrastructure are not laptop-grade decisions; a wrong move there multiplies the damage.

Minute 15–60: protect recovery options, scope the damage

The panic mistakes that cost weeks

In parallel: the clocks that may already be running

The first-hours checklist

  1. Isolate affected systems from wired, wireless, VPN and shared-storage connections; keep them powered on when safe isolation is possible.
  2. Record exact times; start an incident log (who did what, when).
  3. Restrict access to backup and recovery infrastructure; preserve its logs; no destructive changes without the response team.
  4. Preserve ransom notes and filenames, encrypted samples, screenshots where safe, and EDR, firewall, authentication, backup and cloud logs. Delete nothing.
  5. Move team communications out-of-band.
  6. Protect privileged accounts; stage resets with your responder.
  7. Call professional response, your insurer and legal — in parallel, not in sequence.
  8. Assess NIS2/GDPR duties against their legal tests; report when the criteria are met.
  9. Do not start restoration before containment and recovery planning; do not run random decryptors; do not reconnect isolated devices.
  10. Make no contact and no promises to the attackers.

And if this is not a drill: our 24/7 response line — free, and you do not need to be a client.

This is general incident-response guidance, not advice for a specific incident — real attacks differ, and a responder who can see your environment beats any checklist. Legal reporting duties (NIS2, GDPR, sector rules) depend on your situation and jurisdiction.

Under attack right now?

Do not work through this alone while the clock runs. Our incident response line is free, answers 24/7, and you do not need to be a client.

Get emergency ransomware help