Skip to content
Cybersecurity7 min readMay 25, 2026

Ransomware: What the First 24 Hours Should Look Like

RM

Rohit Malhotra

Director, Security Practice, RippleCode

We've led incident response for organizations that recovered in days and others that took months. The variance is rarely about the malware — it's about the first 24 hours. Here's the timeline that works.

Hour 0–1: Contain without destroying evidence

Isolate affected segments — don't power off machines (you lose memory forensics). Disable compromised accounts, block known C2 traffic and snapshot cloud resources. Activate your incident response retainer immediately; every hour of delay compounds.

Hour 1–4: Establish command

  • Name an incident commander with decision authority
  • Move communications off potentially compromised systems
  • Notify legal counsel and cyber insurance — before making promises to anyone
  • Begin an incident log; it will matter for insurance and regulators

Hour 4–12: Scope and assess

Identify patient zero and the attack path. Determine what data was accessed or exfiltrated — modern ransomware is double extortion, and the data-breach dimension often exceeds the encryption dimension. Verify backup integrity offline before trusting recovery plans.

Hour 12–24: Decide and communicate

With scope known, leadership decides on recovery strategy and stakeholder communication. Regulators have notification clocks (72 hours under GDPR and India's DPDP Act). Honest, early communication consistently outperforms silence.

The uncomfortable truth

Every one of these steps is 10× easier if rehearsed. Tabletop exercises cost a day per quarter and are the single highest-ROI security investment we know.

More on Cybersecurity

Want this expertise on your project?

The engineers who write these articles are the ones who staff your engagement.