Ransomware: What the First 24 Hours Should Look Like
Rohit Malhotra
Director, Security Practice, RippleCode
We've led incident response for organizations that recovered in days and others that took months. The variance is rarely about the malware — it's about the first 24 hours. Here's the timeline that works.
Hour 0–1: Contain without destroying evidence
Isolate affected segments — don't power off machines (you lose memory forensics). Disable compromised accounts, block known C2 traffic and snapshot cloud resources. Activate your incident response retainer immediately; every hour of delay compounds.
Hour 1–4: Establish command
- Name an incident commander with decision authority
- Move communications off potentially compromised systems
- Notify legal counsel and cyber insurance — before making promises to anyone
- Begin an incident log; it will matter for insurance and regulators
Hour 4–12: Scope and assess
Identify patient zero and the attack path. Determine what data was accessed or exfiltrated — modern ransomware is double extortion, and the data-breach dimension often exceeds the encryption dimension. Verify backup integrity offline before trusting recovery plans.
Hour 12–24: Decide and communicate
With scope known, leadership decides on recovery strategy and stakeholder communication. Regulators have notification clocks (72 hours under GDPR and India's DPDP Act). Honest, early communication consistently outperforms silence.
The uncomfortable truth
Every one of these steps is 10× easier if rehearsed. Tabletop exercises cost a day per quarter and are the single highest-ROI security investment we know.