Guides · Crisis · 11 min read
The first 48 hours of a ransomware attack
What to do, in order, in the first two days of a ransomware attack at a company with no internal security team: containment, who to call, what to tell clients and staff, the legal clocks, and the decisions you must not take at 3 a.m.
Published 10 September 2026
Ransomware at a mid-sized company rarely looks like the films. Nobody announces themselves. On a Monday at 07:20 the shared drive is full of files with an extension nobody recognises, the ERP will not open, and a text file on the desktop explains the situation in confident English. The attackers were probably inside for days or weeks before that morning, and by the time you see the note the encryption is finished.
What follows is the shape of a first 48 hours that goes as well as it can. It assumes what is usually true below 500 employees: you have an external IT provider, no internal security team, an insurance policy nobody has read closely, and a director who is about to make a dozen decisions with incomplete information.
Hour 0 to 1 — stop the spread
- Disconnect affected machines from the network: pull the cable, disable Wi-Fi. Leave them powered on.
- Disconnect backups and any storage still attached — external drives, NAS, backup server. Encrypting the backups is the attacker's main objective after the primary systems, and they usually get there.
- Isolate rather than destroy: segment the network or unplug the switch uplink rather than shutting down servers.
- Change the passwords of privileged accounts from a clean device, and enforce MFA on email and remote access if it is not already on.
- Write down the time of every action from this moment on. A shared document or a notebook. This timeline is what you will hand to your insurer, your authority and possibly a court.
Hour 1 to 4 — assemble, and start the clocks
Someone has to declare, out loud, that this is a crisis and that they are running it. It is a named person, not a committee, and if that name is not decided in advance it will be decided badly.
- 01Call the IT provider and ask, explicitly, for containment and forensic preservation — not restoration. Restoring into a compromised network reinfects you, sometimes within the hour.
- 02Call the cyber insurer's hotline before engaging any incident-response firm. Most policies require notification within a short window and require you to use approved responders; paying a firm they have not approved can void the cover on the largest part of the bill.
- 03File the criminal complaint or report to your national cyber agency. In France that is a plainte plus ANSSI/cybermalveillance; in Belgium the CCB; elsewhere your national CSIRT. This is also usually an insurance precondition.
- 04Start the NIS2 clock if you are in scope: an early warning to the competent authority within 24 hours of becoming aware, then a fuller notification at 72 hours. If personal data may be involved, the GDPR clock is a separate 72 hours to the data protection authority.
- 05Set up an out-of-band channel for the crisis team — personal phones, a group chat off your corporate identity — on the assumption that internal email is either down or read by the attacker.
Hour 4 to 12 — scope, and speak first
Two things run in parallel and both are urgent. The technical team establishes what was reached: which systems, which data, whether data was exfiltrated before encryption (it usually was, and that is what the extortion is really about). Meanwhile you communicate — because on day two your clients will hear it from somebody, and it is materially better that they hear it from you.
Say four things and nothing more: what happened in one sentence, what it means for them concretely, what you are doing, and when you will next write. Do not speculate about cause, volume or blame. Do not promise a restoration date you cannot hold. The email that ages worst is the one that says "no data was affected" at hour six.
- Staff, first: what to do, what not to touch, who to call, and that nobody is in trouble for reporting something.
- Clients whose service is affected: the four sentences above, from a named person, with a next-update time.
- The bank, if payment or invoicing systems are touched, and specifically to guard against fraudulent payment instructions in your name — the second wave of an attack is often an invoice-fraud email to your customers.
- Suppliers who need to know their orders are delayed.
Hour 12 to 24 — the ransom question, answered calmly
You will be tempted to decide this at 2 a.m. Do not. The decision belongs to a small group in daylight — director, insurer, counsel, incident responder — and the facts you need are: do we have a restorable backup, has data been exfiltrated, and what is the realistic downtime cost per day.
Worth knowing before the conversation: paying does not reliably return your data, it does not remove the copies the attackers already hold, and in several jurisdictions a payment can breach sanctions rules if the group is listed. Public authorities in France, Belgium and at EU level uniformly advise against paying. Insurers increasingly restrict or exclude ransom payment altogether. What actually determines the answer is almost never the negotiation — it is whether a clean backup exists.
Hour 24 to 48 — rebuild, in the right order
- 01Rebuild clean, do not clean the dirty. New or reimaged machines, patched, into a fresh segment, with credentials rotated. Never reconnect a machine you have merely scanned.
- 02Restore in business order, not technical order: whatever lets you take orders and invoice comes first. Cash stops before systems do.
- 03Verify restored data against a known-good reference before letting people work in it. Silent corruption is common, and finding it in week three is worse than finding it on day two.
- 04Close the door before you open the shop: patch the entry point, remove the persistence the responders found, and force a full credential reset including service accounts.
- 05Send the second client update on the schedule you promised, even if the news is only "still working, next update Friday 17:00". Kept promises during a crisis are what survives it commercially.
- 06Keep the timeline current. At hour 48 you should be able to print every decision with its timestamp. That document is your insurance claim, your regulatory report and, if it comes to it, your defence.
The four things that decide how this goes, all of them decided in advance
- An offline or immutable backup, and a restore tested within the last six months.
- A one-page call list on paper: who declares, who calls the provider, the insurer, the authority, the clients.
- MFA on email, banking and remote access — the control that most often prevents the whole scenario.
- One rehearsal. Ninety minutes, once, with the actual people. It is the cheapest thing on this page and the one that most changes hour three.
None of the four is expensive. All four are the sort of thing that stays undone until somebody puts a number on the gap and looks at it every month.
Your reading
Fifteen questions. A score out of 100, and the three exposures costing you the most points.
The Diagnostic scores your crisis preparedness before the crisis, on backups, call lists and rehearsals. Reading this after the fact is expensive; reading it before is free.