The first hour after you find ransomware

The first hour decides how bad the week will be. This page is a calm order of operations, drawn from the response checklist in the joint CISA and FBI guide, written so that a non-specialist can follow it with a phone in one hand.

Last reviewed 10 October 2026.

Before you do anything: three rules

Do not wipe or reinstall a machine yet. Do not pay or reply to anyone yet. Do not discuss the incident on email or chat that the attacker could be reading. Everything else on this page follows from those three.

The reason for the last rule is easy to miss. The CISA guide warns that after an initial compromise, attackers may monitor your activity and communications to see whether they have been detected. If they notice, they may move quickly to spread further or to launch the encryption widely before you have contained anything. The guide's advice is to isolate systems in a coordinated way and to use out-of-band channels, such as phone calls, for the discussion.

Step by step

1. Work out what is affected, and cut it off

Find the machines showing ransom notes, renamed files or strange extensions, and disconnect them. The CISA checklist puts it simply: determine which systems were impacted and immediately isolate them. If several machines or a whole subnet look affected, the guide suggests taking the network offline at the switch. If that is not possible, unplug the network cable or turn off Wi-Fi on the affected devices. Put the most important systems first, meaning the ones the business cannot operate without.

2. Think before you power anything off

Pulling the plug feels decisive, but it destroys information. The CISA guide includes powering down as a fallback, only if you cannot disconnect a device from the network, and notes it will cost you evidence held in memory. If you can disconnect it, do that and leave it on. If you cannot, power it down and write down why.

3. Move the conversation to the phone

Call people rather than email them. Tell your team in person or by phone, and ask them not to log in to anything new from affected machines. If your email is hosted with a provider, assume a compromised account could be reading it until you know otherwise.

4. Start a written log

Use paper or a device that is not involved. Record the time, who noticed, what they saw, what was disconnected and when. This log is more valuable than it feels in the moment. Insurers, investigators and regulators will all ask what happened in what order, and memory is unreliable after a long day.

5. Preserve what you can

Photograph the ransom note. Keep copies of any note files, and do not delete suspicious files yet. For cloud resources, the CISA guide advises taking a snapshot of volumes to keep a point-in-time copy for later review. If you have a professional response firm, they will tell you what to capture. If you do not, collect only what you can without altering the machine.

6. Look for the attacker's footprints, if you have the skill

The CISA checklist suggests examining your existing protection tools and logs for earlier-stage malware and signs of tampering. One example it gives is misuse of built-in Windows tools that attackers use to damage backups and shadow copies, including vssadmin, wbadmin and bcdedit. If you do not have a technical person, this is where an incident response provider earns their fee.

7. Call for help

That means your IT provider if you have one, your cyber insurer if you have a policy, and the authorities. The reporting page sets out who and how. UK organisations can start at the NCSC's ransomware attack page, which also points to assured incident response providers. In the US, the CISA guide lists CISA, the FBI and the Secret Service as places to report, and the government's StopRansomware.gov site collects further resources and alerts.

The first-hour order on one table

First-hour actions in order
StepActionWho usually does itSource
1Isolate affected systems; prioritise the critical onesWhoever is on siteCISA and FBI guide, detection and analysis
2Disconnect rather than power off, unless disconnection is impossibleIT lead or ownerCISA and FBI guide, note on volatile memory
3Switch to phone calls; do not tip off the attackerOwnerCISA and FBI guide, out-of-band communication
4Start a paper log of times, symptoms and actionsAnyone not otherwise busyOur suggestion; it supports the reporting steps in the guide
5Photograph notes; snapshot cloud volumes; keep evidenceIT lead or responderCISA and FBI guide, containment and eradication
6Check protection tools and logs for earlier compromiseTechnical person or responderCISA and FBI guide, detection and analysis
7Notify insurer, IT provider and the relevant authoritiesOwnerCISA and FBI guide, reporting and notification

What you will want to do, and why to resist

You will want to restore from backup immediately. Resist until you know how they got in. The CISA guide cautions that attackers sometimes drop ransomware to obscure earlier activity, and says care must be taken to identify any precursor malware before rebuilding from backups, to avoid continuing compromises. A restore into a still-compromised network can be encrypted again within the hour.

You will want to reset every password at once. Do it, but in the right order. The guide's containment steps say to reset passwords for all affected systems once the environment has been cleaned and rebuilt, and to address vulnerabilities and gaps that let the attacker in. If you reset first, an attacker who still has access can simply read the new ones.

You will want to ask the attacker for proof or negotiate. Do not do that alone, and not in the first hour. The next two sections of this guide explain why, and the reporting page lists what the agencies say.

After the first hour

By the end of the hour you want three things: affected systems isolated, the right people on the phone, and a written log. After that the work shifts to triage. The CISA checklist asks you to decide which systems can be restored first, using a pre-agreed list of critical systems, and to confirm what kind of data lived on the affected machines. If you have not made that list, make it now with the readiness checklist and keep a copy in a drawer.

Recovery is its own phase, and the NCSC has separate guidance for it. Its page on recovering from a highly disruptive attack describes early response, recovery to minimum viable operations, and rebuild, which is a useful way to think about getting a small office trading again before everything is perfect. Our advice, and it is an opinion rather than a citation, is to decide in advance what "minimum viable" means for you: the three or four systems and the dozen files without which you cannot invoice or ship.

How we compiled this page

Methodology: the steps follow the order and wording of the Part 2 response checklist in the CISA, NSA, FBI and MS-ISAC guide, simplified for a small office, with the NCSC's ransomware attack page as the UK reference. Step 4 is our own addition, marked as such in the table. Nothing here is a substitute for a qualified incident responder, and the order may need to change if your systems are cloud-only or your data is regulated.

Previous: Start here Next: Backups