Your Ransomware Response Plan: The First Hour Matters Most

Nobody makes good decisions at 6am with the systems down. That is why the plan has to exist before the attack, not during it.
Server rack in a dark room, the infrastructure a ransomware response plan is built to protect

It usually starts on a normal morning. Someone cannot open a file. Then a second person calls. Then a folder full of documents has a strange new extension, and there is a text file explaining where to send the payment.

What happens in the next hour shapes everything that follows: whether you are back on Thursday or in three weeks, and whether the incident stays contained or spreads across every server you own. A ransomware response plan exists so that nobody has to invent those decisions while their hands shake.

Server rack in a dark room, the infrastructure a ransomware response plan is built to protect

Your ransomware response plan: the first hour, step by step

Isolate, do not shut down

Disconnect affected machines from the network. Pull the cable, disable the wireless. Encryption spreads across shares and connected drives, so cutting the path buys you everything.

Resist the urge to power devices off. Shutting down destroys evidence in memory that specialists use to identify the strain, and sometimes to recover keys. Isolate, leave running, wait for someone who knows what they are looking at.

Protect your backups first

Modern attackers target backups before they encrypt anything, because backups are the reason you can refuse to pay. Check immediately whether your backup system is reachable from the infected network, and disconnect it if it is. Backup recovery is your entire negotiating position, so protect it before you do anything else.

Get the right people in one room

Your IT partner, a director who can make decisions, and whoever handles communication. Three people, one channel, one set of decisions. Use phones or a separate messaging app, because your email may be compromised or unavailable.

Notify early

Call your cyber insurance provider before you commission any work. Most policies require it, and many will only cover incident response carried out by their approved specialists. Calling afterwards can invalidate your claim.

If personal data is involved, data protection rules give you a short window to notify the regulator. In the EU that clock runs to 72 hours. If you fall under NIS2, the first notification window is shorter still.

Do not answer the ransom note yet

Whether to pay is a decision for later, made with legal advice and full knowledge of what you can restore. It is never a first-hour decision, and law enforcement in most countries discourages payment because it funds the next attack.

What decides how well this goes

By the time the ransomware attack starts, your options are already set by choices made months earlier. A ransomware response plan is mostly preparation, and it comes down to four things.

Backups you have actually tested. The 3-2-1 approach with at least one copy offline or immutable. Untested backups fail at the worst possible moment, and a restore that takes eleven days is not really a recovery.

A contact list on paper. Your IT partner, insurer, legal counsel, key customers. Stored somewhere that does not require logging into the systems that are down.

Segmentation and least privilege. Ransomware travels on permissions. If every user can reach every share, one click reaches everything. Domain admin accounts used for daily work are how a single laptop becomes a company-wide outage.

A decision tree written in advance. Who declares an incident. Who can authorise shutting down production. Who talks to staff and customers. Agree it when everyone is calm.

The days after

Recovery is slower than people expect. You rebuild rather than clean, because a system that had an attacker in it is not trustworthy afterwards. You restore in order of business priority, verify as you go, and change every credential.

Expect the business side to take as much energy as the technical side. Staff need to know what to tell customers. Customers need honest updates rather than silence. Suppliers may need alternative ways to reach you. A ransomware response plan that only covers servers leaves the hardest conversations to whoever happens to answer the phone.

Then you find out how they got in, because otherwise you are rebuilding a system with the same door open. In most cases it turns out to be a phishing email, a remote access service exposed to the internet, or an unpatched device that nobody owned.

Do not build your ransomware response plan alone

Here is what we see most: companies with a plan in a document nobody has opened for two years, written for an environment that has since changed completely. It reads well and helps nobody.

A plan is only real when someone maintains it, tests the restores and keeps the contact details current. That is not a task to squeeze between customer meetings, and it is precisely the kind of work we take on at EvolvingDesk.

We build the ransomware response plan around your actual systems, put immutable backups in place, test restores on a schedule and rehearse the incident procedure with your team. If something does happen, you make one call and we are already inside the situation, not reading about your environment for the first time.

Your job is to run the business. Ours is to make sure a bad Tuesday morning stays a bad Tuesday morning instead of becoming a bad quarter.

Want your incident response reviewed? Plan a call and we will start with the only question that matters: when did you last successfully restore something?

Read more

Useful references: the CISA ransomware guide and the NCSC guidance on mitigating ransomware.

Did this article spark some ideas?

Find out what we can do for you, schedule a call today.

About EvolvingDesk: Making IT Effortless

We turn complex IT into simple, effective solutions for your business. Whether it’s cloud services, custom applications, or network management, EvolvingDesk combines the latest technology with personal service, so your business stays secure, connected, and ready for growth. IT made simple, just the way it should be.

What do we do?

At EvolvingDesk, we provide practical IT solutions that fit the way your business works. From tailored software and reliable business WiFi to smart surveillance and hands-on support, we make sure your technology runs smoothly, so you can stay focused on your goals.

Contact-Microsoft

Development

Hosting & Cloud

Surveillance Systems

Network & WiFi

IT-Support

VoIP & Phone

E-Mail & Workspace

Point of Sale