Ransomware Recovery: What Actually Happens in the First 24 Hours

Most businesses only think about ransomware recovery in the abstract, until the morning someone can’t open a file… then can’t open any files, and a ransom note appears on screen instead. At that point, the questions come thick and fast. Do we pay it? Do we turn everything off? Who do we even call first?

Here’s a realistic look at what actually happens in the first 24 hours of a ransomware incident, and why some of the instinctive reactions can do more harm than good.

First Hour

The first hour of Ransomware Recovery: contain, don’t panic

The instinct when something looks badly wrong is to start switching things off. That instinct is understandable, but it’s not quite right. Powering machines off abruptly can destroy the evidence needed to understand how the attackers got in and what they touched, which matters both for recovery and for any later insurance or legal process.

The correct first move is containment, not destruction: disconnecting affected devices from the network (network cable out, Wi-Fi off) to stop the ransomware spreading further, while leaving the machines themselves running wherever possible. This is also the point where your IT support or incident response provider needs to be brought in immediately, ideally within minutes, not hours. If you have a cyber insurance policy, this is also the moment to call your insurer, since many policies require you to use their approved incident response partners for costs to be covered.

1 6 Hours

Hours one to six: working out what actually happened

Once the immediate spread is contained, the focus shifts to assessment. This is less dramatic than it sounds on TV, it’s methodical, careful work to answer a few key questions: which systems and data are affected, how did the attacker get in, and, critically, has any data actually been stolen (exfiltrated) rather than just encrypted.

That last question matters enormously, because it changes your legal obligations. If personal data has been accessed or stolen, UK GDPR requires you to notify the ICO without undue delay, and, where feasible, within 72 hours of becoming aware of the breach, if it’s likely to pose a risk to people’s rights and freedoms. Getting a clear picture in these early hours is what makes that 72 hour clock manageable rather than a scramble.

This is also usually when a decision gets made about reporting the incident to Action Fraud and the NCSC (the National Cyber Security Centre), both of which are recommended steps, and can also connect you with additional support.

6 12 hours

Hours six to twelve: the ransom question

Somewhere in this window, the business conversation almost always turns to the ransom note itself. The NCSC’s consistent advice is not to pay: there’s no guarantee paying gets your data back or stops it being leaked anyway, it directly funds further criminal activity, and paying can mark you out as a business willing to pay in future.

In practice, the decision is rarely made by one person in the moment. It usually involves your incident response provider, your insurer (if you have cyber cover), and sometimes legal advice, weighing up the reality of your backups, the sensitivity of the data involved, and the operational cost of downtime. The single biggest factor in how straightforward this conversation is almost always comes down to one thing decided long before the attack: whether you have clean, tested, offline backups to recover from.

Ransomware Recovery Hours 12-24

Hours twelve to twenty-four: starting recovery

With containment done and the picture reasonably clear, attention turns to recovery. This is where the earlier work pays off, or doesn’t. Recovering from backups isn’t as simple as restoring the most recent copy; those backups need to be checked to confirm they’re clean and weren’t compromised alongside everything else, otherwise you risk reinfecting a freshly rebuilt system.

Systems are typically brought back one at a time, in order of business priority, rather than all at once, with checks at each stage. It’s also common for this window to include the first steps of internal and external communication, letting staff know what’s happened and what to expect, and preparing any necessary communication to customers or partners if their data or service has been affected.

Twenty four hours in, most businesses are not “back to normal.” They’re stable, contained, and on a clear path to recovery, which, in the middle of a ransomware incident, is genuinely the goal.

Divider

The best first 24 hours is the one you never have

Everything above becomes far more manageable, faster, and less costly when it isn’t being figured out for the first time during a live incident. Businesses that recover quickest from ransomware are almost always the ones that already had an incident response plan, tested backups kept genuinely offline or immutable, and a clear idea of who to call in the first five minutes.

That’s exactly what our Cybersecurity Consultancy and Backup & Recovery services are built to put in place before you ever need them. If you’re not confident your business could answer “what do we do in the first hour” today, that’s the conversation worth having now, not during an attack.

More Posts

Contact us to plan your next stage of IT growth

Perfect Solutions For Your Organisation

Whether you’re enhancing security, gaining deeper insight from your data, or embracing AI, we’ll guide your next move with clarity & confidence.

Read other articles

Latest News & Articles

Cyber Insurance: More than a Checkbox Exercise

Do you buy cyber insurance the same way you buy any other insurance? Fill in a form, tick…

Ransomware Recovery: What Actually Happens in the First 24 Hours

Most businesses only think about ransomware recovery in the abstract, until the morning someone can’t open a file……

5 signs your business has outgrown its current IT support

Outgrowing your IT support is usually a sign business is going well. More staff, more sites, more systems,…

Resources