Ransomware Recovery: What To Do in the First 24 Hours
By Daniel Agyemang Prempeh, Founder, DefendVistaLast reviewed:
A practical hour by hour guide for SME leaders, from first alert through to a controlled recovery path, with the mistakes that turn a bad day into a bad year.
The first 24 hours of a ransomware incident set the trajectory of the entire recovery. Good decisions early shorten the outage, reduce the cost and protect the customer relationships that took years to build. Bad decisions in the first six hours can extend the damage by weeks and turn a recoverable incident into the kind that ends businesses. This guide is the hour by hour we use in real engagements.
Hour zero: detect and declare
Most ransomware is discovered by a staff member who cannot open their files, or by the morning shift arriving to a printer spitting ransom notes. The first decision is whether this is genuinely an incident. Duty manager declares, the incident response plan comes out of the safe, and the response team is convened on the out of band channel (not Teams, because Teams may be compromised). Start the written log: every action, every decision, with timestamps. The log will matter to the insurer, the ICO and any later litigation.
First hour: contain, do not destroy
Isolate affected systems from the network by pulling cables or disabling switch ports. Do not power systems off: memory contents are forensically valuable and powering off can destroy evidence about how the attacker got in. Disable VPN and remote access at the perimeter to prevent further attacker movement. Notify your cyber insurer now: most policies require notification within hours and unauthorised remediation can void cover.
Hours 2 to 6: assess the scope
Identify what is encrypted, what is intact, and critically what has been exfiltrated before encryption (modern ransomware groups almost always steal data first to use as leverage). Engage your incident response partner if you have a retainer, or activate one now if you do not. Resist the very strong urge to start rebuilding before you understand what happened. Premature rebuild is the single most common reason for reinfection within 72 hours.
Hours 6 to 12: decide the recovery path
Three realistic options. Restore from clean offline backups if you have them and they are genuinely uncompromised. Rebuild from gold images if backups are insufficient. Engage specialist ransomware negotiators if a ransom decision is genuinely on the table, and never negotiate directly with the threat actor. By this point the senior leadership team should be briefed, a customer holding statement issued, and ICO notification under active preparation if personal data is involved. The 72 hour ICO clock starts from the moment you become aware, not from when you finish investigating.
Hours 12 to 24: controlled recovery
Bring critical systems back in a controlled sequence into a hardened environment, never back into the compromised one. This usually means a fresh Active Directory, new admin credentials for every privileged account, EDR deployed on every machine before it touches the network, and validated patching. Continue logging every decision. Communications to customers, staff and (if a public statement is needed) the press are handled by a small named group, not ad hoc by whoever picks up the phone.
What not to do
Do not pay the ransom without expert legal and forensic advice (and never without checking sanctions exposure: payments to OFAC or HMT listed groups are illegal). Do not wipe systems before forensics. Do not announce recovery before you are confident the attacker is genuinely no longer in the network. Do not let well meaning IT staff start cleaning machines before the incident response partner has triaged them. Do not communicate sensitive information on the same email system that may still be compromised.
A worked example: 90 vehicle haulier, 2024
Ransomware detected by morning shift at 05:40 when run sheets failed to print. Duty manager declared at 05:55, IR retainer activated at 06:20, insurer notified at 07:10. Paper run sheets distributed for the next 24 hours of work, dispatch operating manually. Backups confirmed clean by 14:00. ICO notification filed at 19:30 (driver personal data in scope). Critical systems restored into hardened environment by 38 hours. Total outage 48 hours, total economic loss approximately £180,000, no contracts lost. The difference from a worst case scenario was a tested plan, an active retainer and a calm duty manager who followed the playbook.
Frequently asked questions
Should we ever pay the ransom?+
Sometimes unavoidable, always last resort, always with specialist legal and forensic advice. Payments to sanctioned actors are illegal in the UK. Paying does not guarantee decryption (roughly 30 percent of paid decryptors do not work cleanly) and significantly increases the chance of being targeted again.
Do we need to tell the ICO?+
If personal data has been affected and the breach is likely to result in a risk to individuals, you must notify the ICO within 72 hours of becoming aware. For most ransomware involving employee or customer data, the answer is yes. The ICO is generally constructive with operators who notify promptly and have a credible response in progress.
Will our insurer pay?+
Only if you meet the policy conditions. Document everything from minute one, follow the insurer's panel IR firm requirements, and avoid taking remediation action they have not approved. The most common reason for partial or denied claims is unilateral action by the policyholder in the first 24 hours.
How long until we are genuinely safe again?+
Operational recovery in 1 to 2 weeks. Forensic close out, root cause and remediation in 2 to 4 months. Full post incident hardening (new identity model, segmentation, supplier review) often runs 6 to 12 months.
Next step
Want to talk this through?
Book a free 30 minute consultation. No sales pitch, just clear answers.
Book free consultation