Thinking about camera coverage? Get a free site survey

Ransomware recovery: What the first 24 hours look like

Picture of Nick Stafford
Nick Stafford

Chief Revenue Officer

5 min read
Share this article:
Facebook
X
LinkedIn
Email
Print
ransomware-the-first-24-hours
Ransomware recovery: What the first 24 hours look like

Ransomware hits and the clock starts. What you do in the first 24 hours decides whether you’re back online in days or explaining data loss to clients for months. Here’s what a real ransomware recovery plan looks like in practice, hour by hour, from the engineers who run them.

Hour 0–1: Contain, don’t clean

The instinct is to start deleting things. Don’t. The first move is isolation: pull infected machines off the network, disable Wi-Fi, and segment anything that talks to shared storage. Endpoint protection like SentinelOne can automatically quarantine affected devices, which buys you time.

Do not power machines off. Memory holds forensic evidence and, in some cases, encryption keys. Disconnect, don’t shut down.

Hour 1–4: Scope the blast radius

Now you find out what you’re dealing with. Which systems are encrypted? Which accounts were compromised? Is the attacker still inside? This is where 24/7 monitoring earns its keep; if your MSP saw the first alerts, containment likely started before you knew there was a problem.

Reset credentials for any account that touched an infected system. Assume admin accounts are burned until proven otherwise. Enforce MFA everywhere if it wasn’t already.

Hour 4–8: Verify your backups before you touch them

This is the hour that separates companies with a ransomware recovery plan from companies with a backup subscription. Attackers target backups first. Before restoring anything, verify that backup copies are clean, complete, and predate the infection. Restoring from a compromised backup just reinfects the environment.

If backups were encrypted or deleted, this is when leadership, legal, and cyber insurance get on a call. Paying a ransom is a legal and financial decision, not an IT one.

Hour 8–16: Rebuild from known-good

Wipe and reimage infected endpoints. Restore servers from verified backups into a clean, isolated environment first, then reconnect in stages. Patch the entry point before anything goes back online; restoring systems with the same open door invites round two.

Hour 16–24: Communicate and document

Clients, staff, and possibly regulators need to hear from you. What’s known, what’s suspected, what’s next. Document everything: timeline, affected systems, actions taken. You’ll need it for insurance, compliance, and improving the plan itself.

Plan it before you need it

A ransomware recovery plan only works if it exists before hour zero. Tested backups, defined roles, isolation procedures, and an MSP who picks up the phone. SADOS backs its clients with 24/7 monitoring, SentinelOne endpoint protection, and U.S.-based engineers on every ticket, 4-hour response SLA included. Not sure your backups would survive an attack? Start there. See how SADOS handles cybersecurity.

Table of Contents

0