Support Center | ☎︎ Call us: (845) 440-5000 | info@vjnetworks.com
Back to Blog

The First 24 Hours of a Ransomware Incident: What a Real Response Looks Like

Cybersecurity
Last updated: July 23, 2026

The first 24 hours of a ransomware incident follow a specific sequence: isolate affected systems immediately, preserve evidence before touching anything further, notify the right stakeholders in the right order, and resist the urge to reboot, wipe, or pay before consulting anyone. Skip a step and recovery gets slower, not faster.

Most business owners have never lived through this. Fair enough. I’d rather you learn the sequence here than improvise it live. This isn’t a walkthrough of some specific incident. It’s the federal government’s own published playbook, the one CISA, the FBI, NSA, and MS-ISAC jointly maintain, translated into what it actually means for a business with 20 or 30 people and no dedicated security team.

Hour One: Isolate, Don’t Panic

Disconnection first. Investigation second. CISA’s own guidance is direct about this: determine which systems are impacted and isolate them immediately, prioritizing whatever’s essential to daily operations first. If several systems or subnets look affected, taking the network offline at the switch level beats trying to unplug machines one at a time.

One detail most owners never expect. Isolate quietly. CISA specifically recommends coordinating the shutdown using phone calls instead of chat tools or email, since attackers sometimes still have eyes on internal communications at this stage and a visible scramble can trigger them to spread wider or detonate faster before you finish containing it.

IT technician isolating a server from the network during a ransomware incident response

What Not to Do, Even Though It Feels Productive

Three instincts to fight, all inside the first few hours. Rebooting affected machines feels like troubleshooting. It isn’t. It actually destroys evidence sitting in volatile memory that a forensic team needs later. Only power a device down if you genuinely can’t disconnect it any other way.

Restoring from backup immediately feels like recovery. Sometimes it’s premature. Ransomware is frequently the visible symptom of an earlier, quieter compromise, precursor malware that got in weeks before the encryption ran. Restore before anyone’s checked for that, and you can rebuild the exact same hole right back into a clean-looking network.

And paying, before anyone’s consulted, feels like the fast way out. It rarely is. Federal law enforcement sometimes knows about decryption tools for specific ransomware variants that security researchers have already cracked. That conversation has to happen before money moves, not after.

Who Actually Needs a Call

Not everyone needs to hear from you in the first hour. A specific short list does. Order matters less than speed here.

WhoWhy They’re On the List
Your IT provider or internal teamRuns containment and starts the technical response immediately
Your cyber insurance carrierOften has a required notification window and a panel of approved forensic vendors
Federal law enforcement (CISA, local FBI field office, or FBI IC3)Can offer decryptor intelligence and formally logs the incident
Legal counselGuides regulatory notification decisions before you make them yourself

Every one of these contacts should already be sitting in a written plan before any of this happens. Not looked up mid-incident. That single piece of prep work is the difference between an organized first hour and a chaotic one.

Team discussing who needs to be notified during a ransomware incident response

Preserving Evidence While You’re Also Trying to Recover

These two goals pull against each other constantly. Most owners don’t realize it until they’re living it. Recovery wants speed. Evidence preservation wants nothing touched. CISA’s guidance calls for a system image and memory capture of a sample of affected devices, plus preservation of anything highly volatile, system memory, security logs, firewall buffers, before it’s lost for good.

This is where a written plan actually earns its keep. Without one, most businesses default to “get it back online.” Evidence gets lost. That matters later for the insurance claim, for law enforcement, and for actually confirming the same hole gets closed instead of reopened next quarter.

Technician labeling and preserving storage evidence following a ransomware incident

New York’s Clock Is Already Running

This part catches businesses off guard here in the Tri-State area. New York tightened its breach notification law in December 2024. Thirty days. That’s the new cap. Affected residents have to be notified within that window, not on some open-ended “reasonable” timeline. If you’re a DFS-regulated financial entity specifically, that window is even shorter, 72 hours for certain cybersecurity events.

Both clocks start the moment you discover the incident. Not the moment you finish investigating it. That’s exactly why the notification list above has to be ready in advance. Figuring out who your regulatory contacts even are while day 25 ticks by is a bad way to spend day 25.

The First 24 Hours, Condensed

  • Isolate affected systems immediately, coordinating quietly by phone rather than email or chat.
  • Don’t reboot or wipe anything unless disconnection genuinely isn’t possible.
  • Capture a system image and preserve volatile evidence before it’s gone.
  • Call your IT provider, your cyber insurance carrier, and legal counsel, in whatever order gets them all on the phone fastest.
  • Check for precursor malware before restoring anything from backup.
  • Consult law enforcement about decryptors before any conversation about paying.
Business owner on a call during the early hours of an incident response

Questions I Get Before This Ever Happens

Should we just pay the ransom to make this go away faster?
Not without consulting law enforcement first. Decryption tools already exist for some ransomware variants, and paying doesn’t guarantee working decryption or that stolen data stays private either way.
Do we have to call the FBI, or can we handle this internally?
Nobody can force you to, but CISA specifically recommends it. Federal law enforcement can offer decryptor intelligence you won’t find anywhere else, and formally reporting it matters for insurance and legal purposes down the line.
How fast does our cyber insurance company actually need to hear from us?
Check your policy specifically, since windows vary by carrier, but treat it as urgent, not routine. Some policies tie coverage to how quickly you notified them and whether you used their approved forensic vendors.
What if we don’t have an incident response plan written down anywhere?
Then the first hour of an actual incident becomes the worst possible time to build one. A short plan naming who to call and in what order is worth more than a long one nobody’s read.
Once systems are isolated, how long before we’re actually back up?
Scope decides that, and so does whether backups are clean and actually tested. That groundwork matters months before any of this starts, not during it.

None of this requires a security team you don’t have. It requires a plan written down before the day you need it, and VJNetworks has helped small businesses across the Tri-State area build exactly that for over 20 years, through cybersecurity work that includes a real, tested incident response plan, not a template nobody reads. A free assessment checks whether your business actually has one, alongside VJNetworks’ managed IT services. For the prevention side of this same conversation, why “too small to target” doesn’t apply anymore covers what stops an incident before it starts.

Further reading: CISA’s “I’ve Been Hit by Ransomware” page covers the complete federal response checklist in full.

Build the Plan Before You Need It

A free assessment checks whether your business has a real, ready incident response plan, not just backups and hope. No obligation, no sales pitch.

Get Your Free IT Assessment →

Or call (845) 440-5000