Ransomware Recovery Checklist: What to Do in the First 24 Hours
Ransomware doesn't announce itself. You walk in on Monday morning and half your files are encrypted. The ransom note is on every desktop.
What you do in the first 24 hours determines whether you recover or pay.
Hour 0-1: Contain
- [ ] Isolate affected machines. Disconnect from network immediately. Don't power off - you may lose volatile memory needed for forensics.
- [ ] Identify the ransomware strain. Check the ransom note, file extensions, and any ransomware identification tools (e.g., No More Ransom).
- [ ] Assess scope. How many machines are affected? Which systems? Which data?
- [ ] Do NOT pay the ransom. Paying doesn't guarantee recovery and marks you as a willing target for future attacks.
- [ ] Contact your incident response team. If you don't have one, contact a managed security service provider immediately.
Hour 1-4: Assess
- [ ] Check your backups. Are they intact? Are they offline? When was the last successful backup?
- [ ] Identify the entry point. How did the ransomware get in? Phishing email? RDP? Vulnerable software? This determines your recovery path.
- [ ] Document everything. Timeline of events, affected systems, actions taken. You'll need this for insurance and law enforcement.
- [ ] Notify stakeholders. Employees, customers (if their data is affected), law enforcement, cyber insurance provider.
- [ ] Preserve evidence. Don't wipe affected machines yet. You may need them for forensics.
Hour 4-12: Recover
- [ ] Verify backup integrity. Test a restore on a clean machine before committing to full recovery.
- [ ] Rebuild from clean images. Don't try to clean infected machines. Wipe and rebuild from known-good images.
- [ ] Patch the entry point. Whatever let the ransomware in - close it before reconnecting any systems.
- [ ] Change all passwords. All of them. Service accounts, admin accounts, user accounts. The attacker may have credentials.
- [ ] Restore from backups. Start with critical systems first. Verify each restore before moving to the next.
Hour 12-24: Restore
- [ ] Reconnect systems in stages. Don't bring everything back at once. Test each system before connecting the next.
- [ ] Monitor for re-infection. The attacker may have left persistence mechanisms. Watch for unusual activity.
- [ ] Update all software. OS, applications, firmware. Close every vulnerability the attacker could have used.
- [ ] Implement additional controls. Multi-factor authentication, network segmentation, endpoint detection and response.
- [ ] Communicate with stakeholders. Update employees, customers, and partners on recovery status.
After Recovery: Prevent
- [ ] Conduct a post-mortem. What happened? How did it get in? What could have prevented it?
- [ ] Implement security recommendations. Don't just recover - improve. Close the gaps that let the attacker in.
- [ ] Train employees. If phishing was the entry point, security awareness training is your best defense.
- [ ] Test backups regularly. A backup you can't restore from is not a backup.
- [ ] Review your incident response plan. Update it with what you learned from this incident.
The Hard Truth
Most small businesses that get hit by ransomware don't recover. Not because the ransomware is unbreakable, but because they don't have:
- Tested backups
- An incident response plan
- Someone who knows what to do
Don't wait for the ransom note to wish you had these things.
Free resource: The First 30 Minutes - free incident quick-start checklist.
Full incident response kit: Ops Starter Kit - templates, checklists, and runbooks.
Use code LAUNCH50 for 50% off anything in the store.
Top comments (0)