Cybersecurity & privacy guides for everyoneMonday, October 5, 2026
Threats & Malware

Ransomware Recovery: What to Do in the First 24 Hours

By Digitals Innovation Editorial Team · Updated Sep 17, 2026 · 5 min read

If ransomware has hit, act fast but not frantically: isolate affected devices, preserve evidence, identify what was lost, and restore only from clean backups. The first hours decide whether this is an incident or a disaster. Use the plan below as a checklist.

Hour zero: contain the spread

Your first goal is to stop encryption from reaching more machines.

  • Disconnect affected computers from the network by unplugging the cable and turning off Wi-Fi. Do not shut them down if you can avoid it, as memory may hold useful evidence.
  • Disable shared drives and remote access paths if you suspect they are being used to spread.
  • Isolate backup systems immediately so they cannot be reached and encrypted.
  • Do not log in to affected machines with administrator accounts, because attackers may be capturing those credentials.
Tip: Use a phone or a separate known-clean device to communicate. Assume email and chat on the affected network may be watched.

Do not rush to reboot everything. It is tempting to restart machines to see whether the problem disappears. Rebooting can trigger additional encryption routines, destroy evidence and lose recoverable data in memory. Disconnect first, then decide with calm heads. If you are a small team without security staff, call a professional responder before taking any technical step beyond isolation.

Hours one to four: assess and preserve

Before you wipe anything, gather the facts you will need later.

  • Photograph the ransom note and record any filenames or extensions added to encrypted files.
  • List which systems, accounts and data sets are affected.
  • Note when the first signs appeared and what happened just before, such as an unusual email or a login at odd hours.
  • Keep logs from firewalls, servers and email systems. Copy them to a safe location.
  • Preserve a few encrypted files and the ransom note. They help identify the variant and may be useful if a decryptor is released.

Bring in help now. A professional incident response team, your cyber insurer if you have one, legal counsel and the relevant authorities can each add value. Many regions have official reporting channels for ransomware.

Hours four to twelve: find the cause and close it

Restoring into the same hole invites a second attack. Work out how the attacker got in and what they touched.

  • Review remote access logs, recently created accounts and unusual administrator activity.
  • Reset passwords for all privileged accounts and any account that logged in on affected machines. Do this from a clean device.
  • Revoke active sessions and tokens for email and cloud services.
  • Check for persistence such as new scheduled tasks, services or hidden remote access tools.
  • Patch the vulnerable system or close the exposed service that let them in.

If data was stolen, assume it may be published and prepare for the legal and communication consequences.

Hours twelve to twenty-four: restore safely

Rebuild in order of business importance, and only from sources you trust.

  1. Verify backups are clean by checking dates against the earliest known compromise.
  2. Rebuild affected machines from fresh installations rather than trying to clean them in place.
  3. Restore data into an isolated environment and scan it before reconnecting.
  4. Bring systems back in stages, starting with core services, and monitor closely.
  5. Turn on logging and alerts before you reconnect, so a return visit is noticed quickly.

Keep stakeholders informed with short, honest updates. Staff and customers respond better to a clear plan than to silence.

A simple restore priority list

Agree on the order before you start rebuilding. A sensible order begins with identity systems such as directory services, then core infrastructure like DNS and network services, then the applications that generate revenue or protect safety, and finally the less critical systems. Restoring in the wrong order can create dependencies that fail. Record each restored system, the time, the backup used and the checks performed, so you can show exactly what was done if asked later.

After the incident

Once things are stable, hold a review without blame. Record what worked, what failed and how long each step took. Update your backup strategy, add multi-factor authentication where it was missing, tighten administrator access and rehearse the plan again. Recovery is also the best time to fund improvements that were previously postponed.

Communicating with staff and customers

Tell people what they need to know, when they need to know it. Staff should hear quickly which systems are unavailable, which workarounds to use, and that they must not try to fix things themselves or connect personal devices. Customers need an honest, calm statement that an incident is being handled, what it may affect and where to find updates. Avoid speculating about the attacker or the cause before the facts are confirmed, and keep a record of every statement released so messages stay consistent.

Throughout the process, resist pressure to move faster than your evidence allows. A rushed restore that reintroduces the attacker costs far more time than a careful one. Keep a written log, take breaks, and hand over tasks between shifts so decisions stay clear.

Frequently asked questions

Should I turn off an infected computer?

Disconnecting it from the network is the priority. Powering it off can stop encryption but may erase volatile evidence. If you cannot get expert advice quickly, isolating first and powering down second is a reasonable approach.

Can I trust my backups after an attack?

Only after checking them. Attackers often sit inside a network for a while before encrypting, so a recent backup might contain their tools. Restore into an isolated space and scan first.

Do I have to report a ransomware attack?

It depends on where you operate and what data was affected. Many jurisdictions require notification when personal data is involved. Ask legal counsel early so deadlines are not missed.

Key takeaways

  • Isolate quickly, but do not destroy evidence.
  • Find and close the entry point before restoring anything.
  • Restore from verified clean backups in stages.
  • Review the incident afterward and improve your defenses.
DI
Digitals Innovation Editorial Team
We turn security jargon into steps you can follow. Guides are researched, reviewed and updated as threats and tools change.

Related guides