A ransomware attack is a high-pressure moment. The actions you take in the first hour can help contain disruption, preserve critical evidence, and put your organization in a stronger position to respond.
The day you hoped would never come is here: you have been hacked, your files are locked, and a ransom note has appeared.
Take a breath. The goal is not to solve the incident alone. It is to limit the damage, protect evidence, and bring in the right people quickly.
If you suspect ransomware, isolate the affected device from the network if it is safe to do so, then contact your IT provider, cyber insurer, and incident response resources immediately. Avoid restarting, wiping, or “fixing” the device before qualified professionals can assess it.
Here are five essential actions to take during the first hour of a ransomware incident.
If it is safe to do so, disconnect the affected computer from the network.
Unplug its network cable. Turn off Wi-Fi. Disconnect it from shared drives, VPNs, and other network connections if you can do so without creating a safety issue or disrupting critical operations.
The purpose is simple: reduce the ransomware’s ability to spread to other devices, servers, and connected systems.
However, do not automatically power the computer off. A live system may contain volatile evidence, including information in memory and active processes, that can help incident responders understand what happened. Your IT team or incident response provider can advise on the next step.
Time matters after a ransomware attack.
Contact your managed IT provider or internal IT and security team right away. If you have cyber insurance, notify your insurer using the contact method in your policy. Many policies include specific incident-reporting requirements, approved legal counsel, forensic firms, or breach-response vendors. Delays can complicate coverage, so review the policy with your insurer or broker as soon as possible.
Depending on the incident and your organization’s response plan, you may also need to contact legal counsel, law enforcement, and key internal stakeholders.
The right managed intelligence support gives your organization a faster path to containment, investigation, and informed decision-making.
Do not restart the computer. Do not reinstall software. Do not run cleanup tools. Do not delete files or try random recovery steps.
Well-intentioned actions can destroy or alter evidence that responders need to determine how the ransomware entered the environment, what systems were affected, and whether data may have been accessed or removed.
Instead, document what you see.
Take clear photos of the ransom note, error messages, affected files, and any unusual extensions or file names. Record the date and time you discovered the issue. Save suspicious emails or messages without clicking links or opening attachments.
These details can help your IT provider, insurer, legal team, and law enforcement assess the incident.
A ransom demand creates pressure, but paying is not a guaranteed path to recovery.
Payment does not ensure that attackers will provide a working decryption key, restore all of your data, or refrain from releasing information they may have stolen. It can also encourage future attacks.
The FBI does not support paying a ransom because payment does not guarantee data recovery and can incentivize further criminal activity. Before any decision is made, involve your incident response team, insurer, legal counsel, and law enforcement. They can help assess available recovery options, legal considerations, sanctions risks, and the broader business impact.
Ransomware is not always limited to encrypted files. Attackers may also copy sensitive data before locking systems, a tactic often called data exfiltration.
If customer, employee, patient, financial, or other sensitive information may have been accessed or stolen, notification obligations may apply. Requirements vary based on the data involved, your industry, your contracts, and the jurisdictions in which you operate.
Do not send notifications before coordinating with legal counsel, your insurer, and your incident response team. They can help determine what happened, who may be affected, what laws apply, and when communication should occur.
The first hour of a ransomware incident is easier to manage when a response plan already exists.
Ferrum Technology Services delivers Managed Intelligence: proactive monitoring, cybersecurity expertise, and practical IT guidance to help businesses prepare for and respond to cyber risk. From incident response planning to stronger security controls and resilient backups, we help organizations build readiness before a crisis begins.
If you want help putting a cyberattack response plan in place, contact Ferrum Technology Services.
Should I turn off my computer after ransomware appears?
Usually, do not restart or power off the affected device unless your IT or incident response team directs you to. Isolate it from the network first, if safe, because the running system may contain valuable evidence.
Should we pay a ransomware demand?
Do not rush to pay. Payment does not guarantee recovery or prevent stolen data from being released. Involve your insurer, legal counsel, incident response team, and law enforcement before making any decision.
Who should I call after a ransomware attack?
Contact your IT provider or internal security team immediately, followed by your cyber insurer. Depending on the situation, engage legal counsel, law enforcement, and your organization’s designated incident-response leaders.
Ransomware Response Resources
For additional guidance during a ransomware or data-breach incident, consult these trusted resources:
Every incident is different. Work with your IT provider, cyber insurer, legal counsel, and incident response team to determine the appropriate next steps for your organization.