Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

Ransomware

Ransomware Response Playbook: The First Hours

When a ransomware attack is live, the worst thing you can do is improvise. There is a right order to the response, and most of the damage that turns a contained incident into a company-wide disaster happens in the first hour, when people act on instinct instead of a plan.

Response playbookFirst-hour actionsIn orderReport timelines4 min readUpdated Jun 2026

When a ransomware attack is live, the worst thing you can do is improvise. There is a right order to the response, and most of the damage that turns a contained incident into a company-wide disaster happens in the first hour, when people act on instinct instead of a plan.

This is that plan, condensed. Run the steps in order, because skipping ahead almost always means missed evidence or reinfection.

01

The playbook, step by step

1
Isolate infected systems immediately: pull network cables, disable Wi-Fi, and kill VPN tunnels on the affected segment.
2
Isolate, do not shut down. Powering off erases volatile memory that may hold evidence and even encryption keys.
3
Activate the response team over an out-of-band channel, because email on a compromised network is an open mic.
4
Preserve evidence: image disks, capture memory, photograph ransom notes, and start the chain of custody.
5
Lock down credentials: reset all administrative and service accounts, which attackers often have staged.
6
Report to law enforcement and regulators within the required windows.
7
Eradicate completely: hunt every foothold, remove persistence, and reset all credentials before recovery.
8
Recover from clean backups, prioritize critical systems, and run a blameless post-incident review.

The single most important idea here is sequence. Containment comes before investigation, evidence comes before eradication, and clean backups are confirmed before anything is restored.

02

Who to notify, and when

Who to notifyWithin
SEC (material incident, US public companies)4 business days of a materiality determination
Regulators under GDPR72 hours
Law enforcement / cybercrime unitsAs early as possible, to get intel and possible decryptors

Reporting is not optional, and the clock starts at detection. Knowing your deadlines in advance keeps a hard call from becoming a missed one.

[[INSIGHT: The instinct to power off an infected machine is the instinct to destroy your own evidence. Isolate it from the network instead. Volatile memory can hold the forensic trail, and sometimes the encryption keys themselves, both gone the moment you shut down.]]

See it in action: the first 60 minutes

The first hour decides how much of your environment stays clean. The scenarios below are illustrative.

Illustrative scenarios
Encryption starts spreading at 9 a.m.
Without a framework
  • Staff debate what to do while files keep locking.
  • Machines are powered off, destroying evidence.
  • The whole network is hit.
Spread: environment-wide
With a playbook
  • IsolateAffected segment is pulled from the network within minutes.
  • PreserveDisks are imaged and memory captured before changes.
  • ActivateThe team coordinates on a pre-agreed out-of-band channel.
Spread: contained
Key takeaways
  • The first hour of containment decides how much of your environment stays clean.
  • Isolate infected systems from the network, but do not power them off.
  • Coordinate over an out-of-band channel, never compromised email.
  • Preserve evidence before eradicating, and reset all credentials before recovering.
  • Know your reporting deadlines in advance: four business days for the SEC, 72 hours under GDPR.
FAQ

Frequently asked questions

What is the first thing to do in a ransomware attack?

Isolate the affected systems from the network immediately: pull cables, disable Wi-Fi, and kill VPN tunnels. The first hour of containment decides how much of your environment stays clean.

Should we shut down infected machines?

Isolate them from the network rather than powering them off. Volatile memory can hold forensic evidence and sometimes the encryption keys, which are lost on shutdown.

When do we have to report a ransomware incident?

It depends on jurisdiction. US public companies report material incidents to the SEC within four business days of a materiality determination, and GDPR requires notifying regulators within 72 hours. Set your thresholds in advance.

Why reset all credentials before recovering?

Attackers stage secondary and tertiary credentials for persistence. If even one survives, reinfection is almost guaranteed, so reset service accounts, VPN keys, and privileged accounts before reconnecting.

Written and reviewed by Tech Jacks Solutions Security Practice. Incident response and GRC practitioners.
Primary source: Ransomware response playbook (containment through review). Last reviewed June 2026.

Author

Tech Jacks Solutions

Leave a comment