The first 24 hours of a ransomware incident follow a specific sequence: isolate affected systems immediately, preserve evidence before touching anything further, notify the right stakeholders in the right order, and resist the urge to reboot, wipe, or pay before consulting anyone. Skip a step and recovery gets slower, not faster.
Most business owners have never lived through this. Fair enough. I’d rather you learn the sequence here than improvise it live. This isn’t a walkthrough of some specific incident. It’s the federal government’s own published playbook, the one CISA, the FBI, NSA, and MS-ISAC jointly maintain, translated into what it actually means for a business with 20 or 30 people and no dedicated security team.
Hour One: Isolate, Don’t Panic
Disconnection first. Investigation second. CISA’s own guidance is direct about this: determine which systems are impacted and isolate them immediately, prioritizing whatever’s essential to daily operations first. If several systems or subnets look affected, taking the network offline at the switch level beats trying to unplug machines one at a time.
One detail most owners never expect. Isolate quietly. CISA specifically recommends coordinating the shutdown using phone calls instead of chat tools or email, since attackers sometimes still have eyes on internal communications at this stage and a visible scramble can trigger them to spread wider or detonate faster before you finish containing it.

What Not to Do, Even Though It Feels Productive
Three instincts to fight, all inside the first few hours. Rebooting affected machines feels like troubleshooting. It isn’t. It actually destroys evidence sitting in volatile memory that a forensic team needs later. Only power a device down if you genuinely can’t disconnect it any other way.
Restoring from backup immediately feels like recovery. Sometimes it’s premature. Ransomware is frequently the visible symptom of an earlier, quieter compromise, precursor malware that got in weeks before the encryption ran. Restore before anyone’s checked for that, and you can rebuild the exact same hole right back into a clean-looking network.
And paying, before anyone’s consulted, feels like the fast way out. It rarely is. Federal law enforcement sometimes knows about decryption tools for specific ransomware variants that security researchers have already cracked. That conversation has to happen before money moves, not after.
Who Actually Needs a Call
Not everyone needs to hear from you in the first hour. A specific short list does. Order matters less than speed here.
| Who | Why They’re On the List |
|---|---|
| Your IT provider or internal team | Runs containment and starts the technical response immediately |
| Your cyber insurance carrier | Often has a required notification window and a panel of approved forensic vendors |
| Federal law enforcement (CISA, local FBI field office, or FBI IC3) | Can offer decryptor intelligence and formally logs the incident |
| Legal counsel | Guides regulatory notification decisions before you make them yourself |
Every one of these contacts should already be sitting in a written plan before any of this happens. Not looked up mid-incident. That single piece of prep work is the difference between an organized first hour and a chaotic one.

Preserving Evidence While You’re Also Trying to Recover
These two goals pull against each other constantly. Most owners don’t realize it until they’re living it. Recovery wants speed. Evidence preservation wants nothing touched. CISA’s guidance calls for a system image and memory capture of a sample of affected devices, plus preservation of anything highly volatile, system memory, security logs, firewall buffers, before it’s lost for good.
This is where a written plan actually earns its keep. Without one, most businesses default to “get it back online.” Evidence gets lost. That matters later for the insurance claim, for law enforcement, and for actually confirming the same hole gets closed instead of reopened next quarter.

New York’s Clock Is Already Running
This part catches businesses off guard here in the Tri-State area. New York tightened its breach notification law in December 2024. Thirty days. That’s the new cap. Affected residents have to be notified within that window, not on some open-ended “reasonable” timeline. If you’re a DFS-regulated financial entity specifically, that window is even shorter, 72 hours for certain cybersecurity events.
Both clocks start the moment you discover the incident. Not the moment you finish investigating it. That’s exactly why the notification list above has to be ready in advance. Figuring out who your regulatory contacts even are while day 25 ticks by is a bad way to spend day 25.
The First 24 Hours, Condensed
- Isolate affected systems immediately, coordinating quietly by phone rather than email or chat.
- Don’t reboot or wipe anything unless disconnection genuinely isn’t possible.
- Capture a system image and preserve volatile evidence before it’s gone.
- Call your IT provider, your cyber insurance carrier, and legal counsel, in whatever order gets them all on the phone fastest.
- Check for precursor malware before restoring anything from backup.
- Consult law enforcement about decryptors before any conversation about paying.

Questions I Get Before This Ever Happens
Should we just pay the ransom to make this go away faster?
Do we have to call the FBI, or can we handle this internally?
How fast does our cyber insurance company actually need to hear from us?
What if we don’t have an incident response plan written down anywhere?
Once systems are isolated, how long before we’re actually back up?
None of this requires a security team you don’t have. It requires a plan written down before the day you need it, and VJNetworks has helped small businesses across the Tri-State area build exactly that for over 20 years, through cybersecurity work that includes a real, tested incident response plan, not a template nobody reads. A free assessment checks whether your business actually has one, alongside VJNetworks’ managed IT services. For the prevention side of this same conversation, why “too small to target” doesn’t apply anymore covers what stops an incident before it starts.
Further reading: CISA’s “I’ve Been Hit by Ransomware” page covers the complete federal response checklist in full.
A free assessment checks whether your business has a real, ready incident response plan, not just backups and hope. No obligation, no sales pitch.
