Ransomware Response Plan: Who Does What in the First 24 Hours
A ransomware response plan names who leads, what you do in the first hour (isolate, preserve, call the right people), who decides on outside help and communications, and how you restore from clean backups. Write it before an attack, when you can think clearly, and keep a copy off your own network.
The outline below fits a small company. Each heading is a section of a short document. Fill in names and phone numbers now, because during an incident you won't have time to look them up.
Vendors Covered in this Article
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
Who does what during an attack?
Assign roles by person, with a named backup for each. For a small company, one person may hold two roles, but write it down:
- Incident lead: makes decisions, keeps the timeline and decides when to escalate.
- Technical lead: directs containment, investigation and recovery.
- Communications owner: handles messages to staff, customers, partners and the press, using approved wording.
- Legal and insurance contact: your attorney and your cyber insurer's claims line, since many policies require early notice and use of approved vendors.
- Scribe: records every action with a time, because the log matters for insurance, legal and lessons learned.
Add a contact card with mobile numbers for each role, your IT provider, your insurer, your outside counsel and a forensic firm if you have one. Print it and keep a copy somewhere that doesn't depend on your network, since email and chat may be down.
What happens in the first hour?
Speed matters, but so does not making things worse. A workable sequence:
- Recognize and declare. Call it an incident, name the incident lead and start the timeline.
- Isolate. Disconnect affected machines from the network and turn off wireless. Unplugging the network cable or using your endpoint tool's isolate function keeps evidence better than pulling power. Follow your responder's advice on shutdowns.
- Contain the account side. Disable or reset compromised accounts and rotate privileged credentials from a clean device, not from an affected machine.
- Protect the backups. Check that backup systems are not reachable from infected machines, and disconnect them if they are.
- Preserve evidence. Don't wipe or reimage machines yet. Photograph ransom notes and save sample encrypted files.
- Call for help. Notify your insurer, your attorney and an incident response firm, then IT and leadership.
Use out-of-band communication, such as personal phones or a separate chat workspace, in case attackers are reading company email.
Should you pay the ransom?
Decide the process ahead of time, not the answer. Payment is a legal, financial and ethical decision, and it never guarantees that data comes back or that the attackers don't return. It may also carry legal risk depending on who is behind the attack and where you operate, so involve your attorney and insurer before any contact with the attackers, and consider whether law enforcement should be notified.
Your plan should say who has authority to decide, who must be consulted first and that nobody negotiates alone. The best position to be in is one where clean, tested backups make the question much less urgent.
How do you communicate during and after?
Prepare short, factual templates for each audience and let counsel review them before use:
- Staff: what happened, what to do and not do, and how to report anything odd.
- Customers: what is affected, what you're doing and when you'll update them. Don't speculate about cause or scope.
- Regulators and contractual notifications: notification duties depend on your jurisdiction, the data involved and your contracts, so ask your attorney which apply and how fast.
- Insurer: follow the notice and vendor requirements in your policy.
Keep updates on a schedule, even when the update is that nothing has changed. Silence creates more speculation than a plain progress note.
How do you recover safely?
Recovery is where a second infection happens if you rush. Work through this order:
- Establish how the attackers got in, and close that path first: a stolen credential, an exposed remote access service or an unpatched system.
- Rebuild affected systems from known-good images rather than cleaning them in place.
- Restore data from backups you've verified are clean, testing in an isolated network before reconnecting.
- Reset all credentials, including service accounts and API keys, and enforce multi-factor authentication.
- Reconnect in stages while monitoring closely, with endpoint detection running on every restored device.
- Hold a review within two weeks and update this plan.
Detection tooling such as CrowdStrike or SentinelOne can help with isolation and visibility, and a disaster recovery plan defines how fast you need each system back. The general incident response plan covers non-ransomware events.
How do you prepare before it happens?
The preparation list is short and effective: keep at least one backup copy offline or immutable, test a full restore, enforce multi-factor authentication on email and remote access, patch internet-facing systems promptly, and deploy endpoint detection with someone watching it. Run a two-hour tabletop exercise once a year using a realistic scenario, and fix whatever it exposes. Your answers here will also help when customers send a security questionnaire.
What Good Looks Like
A short written plan names roles, a first-hour sequence and contacts, and is backed by offline backups you have restored in a test.
Building The Capability (5-Stage Skill Ladder)
How to Get Started
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
Frequently Asked Questions
What is the first thing to do when hit by ransomware?
Isolate affected machines from the network and declare an incident with a named lead. Then preserve evidence, protect your backups, and call your insurer, attorney and an incident response firm before making major decisions.
Should you pay a ransomware demand?
Don't decide alone or in a panic. Payment doesn't guarantee recovery and may carry legal risk. Involve your attorney, insurer and, where appropriate, law enforcement first, and rely on tested backups to reduce the pressure.
Should you turn off infected computers?
Isolating them from the network is the first step. Powering off can destroy volatile evidence and may not be necessary, so follow your incident response firm's guidance on shutdowns.
How often should we test a ransomware plan?
At least yearly, with a tabletop exercise, and after any major change in systems or staff. Also test a full backup restore regularly. The plan is only useful if people know their roles.
About the numbers
This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.
Related Guides
Disaster Recovery Plan: Setting RTO and RPO per Service
Build a disaster recovery plan by tiering services, setting RTO and RPO for each, choosing a recovery pattern and running a test you can trust.
Incident Response Plan for a Startup: A Fill-In Outline
An incident response plan outline for small engineering teams: roles, the first 15 minutes, communication steps, a security branch and a review process.
How to Answer Security Questionnaires Faster With an Answer Library
Build a reusable security questionnaire response library: answer format, evidence links, owners and review rules so sales reviews close in days, not weeks.
Moving to the Cloud: A Migration Plan for a Small Business
A phased plan for a small business cloud migration: inventory, choose a strategy per system, build a landing zone, pilot, cut over and retire the old.
Writing an Incident Response Runbook People Actually Follow at 3 A.M.
A worksheet approach to writing incident runbooks that hold up under real pressure, when the person on call is tired, stressed, and reading fast.
Do You Need EDR? A Small Business Decision Guide
Endpoint detection and response goes beyond antivirus. See when a small business needs it, what to compare in demos, and how to roll it out.