Loading

How to respond to a ransomware attack: The first 72 hours

How to Respond to a Ransomware Attack Hero Image

When ransomware hits, the first 72 hours shape everything that follows. The early decisions your team makes determine how far the damage spreads, how much data you recover, and how quickly your business comes back online. A fast, methodical response keeps the incident contained and puts you on the shortest path to recovery.

Ransomware incident response moves through clear phases. Each one builds on the work before it, carrying your team from the first signs of an attack through containment, investigation, and a confident return to normal operations. 

How to know when you’re dealing with an active ransomware incident

By the time a ransom note appears on screen, the malware has usually spent hours or days moving laterally through your network, escalating privileges, disabling defenses, and encrypting data. Understanding that timeline changes how you respond. Instead of reacting to a single event, you're interrupting a process already in motion, and how much of your environment survives depends on how quickly you cut it off.

This is why the principle behind effective ransomware incident response is interruption over investigation in the opening minutes. You diagnose the full picture later. 

Signs you're under attack

The clearest signs of an active ransomware attack are files that suddenly carry unfamiliar extensions or refuse to open, ransom notes dropped into folders or displayed on screens, and users locked out of systems they normally access.

Earlier in the sequence, subtler indicators give the attack away. Watch for signs like:

  • Spikes in CPU and disk activity as encryption runs
  • Outbound traffic to unfamiliar IP addresses
  • New admin accounts nobody created
  • Security tools going offline without explanation

One of these alone might be ordinary noise, but several together should be your cue to act.

Who to contact immediately

A confirmed ransomware attack triggers six notifications, and each party unlocks a different part of your response:

  • Incident response team: Leads the technical containment and owns the early recovery decisions.
  • Executive leadership: Authorizes business-level decisions, like taking systems offline or pausing operations.
  • Legal counsel: Clarifies your disclosure obligations and protects privileged communications from the start.
  • Cyber insurance carrier: Activates your policy and connects you to vetted specialists, and most policies require notice within a set window to keep coverage intact.
  • FBI: Takes the criminal report, contributes attribution, and can point you toward any decryptors security researchers have released for your variant.
  • CISA: Offers technical assistance, including forensic support and current threat intelligence on the variant you're facing.

Reaching these parties early keeps your response coordinated and protects the legal and financial options you'll rely on over the days ahead.


Hours 0–4: Contain the damage

The first four hours belong to containment. The goal during this time is to stop the ransomware from reaching more systems.

Disconnect compromised systems from the network, but leave them powered on. Unplug the Ethernet cable, disable the wireless adapter, or isolate the machine at the switch level so it can no longer communicate with the rest of your environment or reach the internet. Shutting a system down wipes the volatile data living in memory, and that memory often holds encryption keys, running processes, and other artifacts your investigators need. Keep the machine alive and quarantined, and you preserve the evidence while cutting off the attacker's path.

Capture a system image and a memory snapshot of affected machines before you touch anything else. Collect firewall logs, security event logs, ransom notes, and samples of the malware or suspicious files you find. Much of this evidence is volatile or short-lived, so grab it early before it ages out or gets overwritten.

Rushing into cleanup or rebuilding destroys the trail your investigators and legal team depend on, and that trail is essential for insurance claims, law enforcement, and any litigation that follows. A disciplined incident response ransomware workflow treats evidence preservation as a first-class step.

Bring your full response team online with clear roles already assigned. A strong team pulls together:

  •  IT and security staff to run technical containment
  • An incident commander to direct the effort and hold decision authority
  • Legal counsel to guide disclosure and privilege  
  • A communications lead to manage internal and external messaging. 

Pre-assigned roles are what keep the response calm under pressure. When everyone knows who owns which call before the incident starts, you skip the confusion over who has authority and move straight into coordinated action.

Hours 4–24: Investigate the scope

With the spread contained, the next window shifts to investigation. Before you restore anything, you need a clear picture of what happened and how far it reached.

Start by pinning down which strain you're dealing with. The ransom note, the file extensions appended to encrypted files, and the contact methods the attacker leaves behind all point toward a specific variant. Run those details through threat intelligence databases like ID Ransomware or the No More Ransom project to confirm the match. 

Some variants have known encryption flaws, so a free decryption tool may already exist and could spare you a rebuild.

Map every system, application, and data store the attack touched, working through your environment methodically. Trace the attacker's movements to identify systems they reached but haven't yet encrypted, since those may still harbor persistence. This full accounting is what makes safe recovery possible, giving you a verified map of what to rebuild and in what order.

Check whether the attacker stole data before encrypting it. Review outbound network traffic for large or unusual transfers, inspect logs from your firewall and data loss prevention tools, and look for staging directories or compression utilities the attacker may have used to package data for theft. 

Exfiltration changes your response. When data leaves your network, you're facing double extortion, where attackers threaten to leak stolen information even after you recover your systems from backups. That brings legal disclosure obligations, regulatory considerations, and reputational stakes into play, so confirming it early lets you plan the right response from the start.

Hours 24–72: Begin recovery

Recovery starts once you understand the full scope and the environment is stable. With the threat contained and the blast radius mapped, you can rebuild on solid ground.

Verify that your backups are clean before you restore a single file. Scan each one for signs of compromise, confirm that it predates the earliest attacker activity you identified, and check that the files haven't been encrypted or tampered with. 

Restoring from an infected copy puts you right back where you started and reinfects the systems you just cleaned. Reliable data backup and recovery services keep your backups immutable and let you test them regularly, so you have verified-clean copies to restore from.

Rank every system by two factors: how much downtime costs and how many other systems depend on it. The high scorers come back first.

Dependencies set the sequence, because a system can't run until the things it relies on are already up. Restore in this order:

  1. Authentication and networking, since nothing else works without them.
  2. Databases, which your applications need to function.
  3. Applications, once the databases they read from are live.

Map this chain before you start, so you recover everything the first time without backtracking.

During recovery, your internal and external audiences need different things from you.

Leadership and employees need to know where things stand. Give them regular status updates on what's back online, what's still down, and when you expect restoration.

Customers, partners, and regulators may need formal notice. Breach notification laws often require this once you confirm that attackers stole data. Route these messages through legal counsel and your communications lead so every disclosure stays accurate and consistent.

Whatever the audience, honesty and timing carry the most weight. Straight, well-paced updates protect the trust your business depends on while you work to bring operations back. 

After the first 72 hours

Getting systems back online is a milestone, not the end of the work.

Run a full review while the details are fresh. Trace how the attacker got in and why your defenses missed them. Document the attack timeline, the decisions your team made under pressure, and where your response broke down. This record drives every improvement you make to your incident response techniques for ransomware attacks.

Turn each finding into a specific change. An unpatched entry point calls for a tighter patching cadence. Easy lateral movement calls for network segmentation and stricter access controls. Test your ransomware data recovery process against the gaps the incident exposed, confirming you can restore quickly and cleanly.


How Cohesity's Cyber Event Response Team supports ransomware recovery

When ransomware hits, you don't have to face it alone. Cohesity’s Cyber Event Response Team (CERT) gives you direct access to incident response specialists 24/7, at no extra cost to Cohesity customers.

We work alongside your team and your chosen IR partner, giving them deeper insight into your data so the whole effort moves faster. We support you across the full recovery, from investigating the attack to validating clean backups and restoring through a clean room that keeps reinfection out. We also help before anything goes wrong, running resilience assessments that sharpen your ransomware incident response ahead of a real event.

Loading