It is 9:15 on a Tuesday morning.
An employee calls because the files on their computer will not open.
Another employee reports the same problem.
Someone notices an unfamiliar message demanding payment.
Then a shared folder stops responding.
This is the point where preparation matters.
When ransomware appears, the instinct may be to start clicking, rebooting computers, deleting suspicious files, or immediately trying to restore everything from backup.
Some of those actions can make the situation worse.
The first objective is not to get every system working again as quickly as possible.
It is to contain the incident, understand what is happening, preserve the information needed to investigate it, and begin recovery in a controlled way.
The Cybersecurity and Infrastructure Security Agency's #StopRansomware guidance recommends a structured response beginning with identifying affected systems and immediately isolating them, followed by investigation, containment, eradication, and carefully prioritized recovery.
Every incident is different, and businesses should follow their established incident response plan and the direction of qualified cybersecurity, legal, insurance, and other appropriate professionals.
But every organization should know what the first hour could look like before that hour arrives.
First 10 Minutes: Isolate the Affected Systems
The first priority is containment.
If ransomware is actively spreading, every minute affected systems remain connected can matter.
CISA recommends determining which systems have been impacted and immediately isolating them. If only one workstation appears affected, that may mean disconnecting its Ethernet cable or removing it from Wi-Fi.
If multiple systems or network segments are involved, IT or the organization's incident-response team may need to isolate larger portions of the network.
This is not the time for an employee to explore.
Do not click through unfamiliar windows to “see what happens.”
Do not connect USB drives.
Do not start copying files to another computer.
And do not reconnect the device just because the visible ransomware message disappears.
The goal is to stop communication between potentially compromised systems and everything else.
Should You Turn the Computer Off?
Not necessarily.
This is an important detail that surprises many business owners.
CISA notes that shutting down a device can destroy information stored in volatile memory that may be useful during an investigation. Its guidance recommends powering down affected systems when they cannot otherwise be disconnected from the network.
In other words:
Disconnect first when possible. Power down when necessary to prevent further spread.
Employees should not be expected to make complex forensic decisions themselves. This is why the response plan should tell them exactly whom to contact.
10–20 Minutes: Activate the Response Team
Once immediate isolation begins, the incident needs a coordinator.
That might include:
Internal leadership
Your IT provider or security team
Cyber insurance contacts
Legal counsel
A cybersecurity incident-response provider
Other appropriate external resources
Who needs to be involved will depend on the organization and the scope of the incident.
The important thing is that the contact list already exists.
A ransomware event is a terrible time to discover that nobody knows the cyber insurance carrier's breach hotline or that the only person with the IT provider's emergency number is on vacation.
The response plan should identify:
Who has decision-making authority?
Who coordinates technical response?
Who communicates with employees?
Who contacts insurance or legal resources?
Who documents what is happening?
Clear ownership helps prevent five different people from taking five different actions at the same time.
20–30 Minutes: Communicate Through a Trusted Channel
If attackers gained access to the organization's systems before deploying ransomware, there is a possibility they can monitor normal communication channels.
That is why CISA recommends coordinated isolation and the use of out-of-band communication during a ransomware response.
The phrase sounds technical, but the concept is simple.
It means communicating through a channel separate from the environment that may be compromised.
Depending on the incident, that may mean phone calls or another predetermined communication method instead of company email or internal messaging.
Your response plan should answer this before an incident:
If we cannot trust our normal email or messaging platform, how will the response team communicate?
Employees also need basic instructions.
They may need to know not to reconnect affected devices, not to open unusual messages, not to use specific applications, or not to discuss technical response details through potentially compromised systems.
Simple communication can prevent accidental actions that expand the incident.
30–40 Minutes: Determine the Scope and Priorities
Once immediate containment is underway, responders need to understand what is affected.
Questions may include:
Which computers are showing signs of compromise?
Are servers affected?
Are cloud systems involved?
Are multiple office locations affected?
What security alerts occurred before encryption was discovered?
Which critical business systems are unavailable?
Are backups accessible and protected?
Is there evidence that information may have been accessed or removed?
This is also where a predefined critical-asset list becomes valuable.
CISA recommends identifying systems that are essential to health and safety, revenue generation, and other critical services so organizations can prioritize restoration when an incident occurs.
Not every device has the same priority.
A receptionist's secondary workstation, payroll system, production server, patient database, and file server may all be important, but they do not necessarily have the same business impact.
Your recovery priorities should already be defined whenever possible.
40–50 Minutes: Preserve Evidence
Modern ransomware incidents are often more complicated than “a virus encrypted our files.”
Attackers may have been inside the environment before the ransomware became visible.
They may have stolen credentials.
Created new accounts.
Moved between systems.
Accessed sensitive information.
Disabled security tools.
Or attempted to reach backup systems.
The ransom note may be the first thing employees notice, not the first thing the attacker did.
CISA's response guidance recommends preserving relevant system images, memory captures, logs, malware samples, and other available evidence during investigation and containment.
That is another reason to avoid immediately wiping, rebuilding, or aggressively cleaning every affected machine.
You could destroy information responders need to understand:
How did the attackers get in?
How long were they there?
What did they access?
Are they still present somewhere else?
Could a clean-looking system actually still be compromised?
Evidence preservation should be handled by people with the appropriate expertise, but employees and business leaders can help by avoiding unnecessary changes.
50–60 Minutes: Begin Planning a Clean Recovery
By the end of the first hour, the organization may not be ready to restore systems yet.
That is okay.
Speed matters, but restoring too quickly into an environment that is still compromised can create another incident.
CISA recommends reconnecting systems and restoring data from offline, encrypted backups according to the priority of critical services while taking precautions not to reinfect clean systems.
Before recovery, responders may need to determine:
Whether the original entry point has been closed
Whether credentials need to be reset
Which systems are safe to rebuild
Which backups are known to be good
Whether the backup environment was affected
Which systems should return first
How clean systems will remain separated from compromised ones
This is where backup testing becomes extremely important.
Having a backup and having a usable recovery path are not necessarily the same thing.
Backups can fail.
Credentials can be missing.
Storage can become corrupted.
Required hardware may no longer be compatible.
And if attackers were able to reach the backup environment, the backup itself may have been encrypted or deleted.
CISA recommends maintaining offline, encrypted backups and regularly testing their availability and integrity.
What Employees Should Know Before Ransomware Happens
Your employees do not need to become cybersecurity investigators.
They do need a short, clear set of instructions.
For example:
If you suspect ransomware:
Stop working on the affected computer.
Disconnect it from the network if your company's response procedure instructs you to do so.
Contact the designated IT or security resource immediately.
Do not reconnect the device.
Do not delete files or attempt to “clean” the system.
Use the designated alternative communication method if instructed.
Write down what you observed and approximately when it occurred.
The exact procedure should be designed for your environment.
What matters is that employees are not forced to invent one during the incident.
Build the First-Hour Plan Before You Need It
The most valuable ransomware checklist is not the one someone searches for after files have already started encrypting.
It is the one the business has prepared and practiced ahead of time.
Before an incident, the organization should know:
Who makes decisions
Who calls IT
Which systems are most critical
How affected systems will be isolated
How the team will communicate outside normal channels
Where insurance and legal contact information is stored
Where critical documentation is kept
Which backups should be used first
When backups were last successfully restored
What employees should and should not do
No checklist can make a ransomware incident simple.
But preparation can remove some of the uncertainty at exactly the moment the organization can least afford it.
The first 60 minutes should not be about improvising.
They should be about following a plan: contain the incident, communicate carefully, understand the scope, preserve what matters, and recover deliberately.
At STS, we encourage businesses to build and test that plan before the ransom note ever appears.
Because when something serious happens, knowing what to do next is just as important as having the technology to do it.
