Ransomware hits and the clock starts. What you do in the first 24 hours decides whether you’re back online in days or explaining data loss to clients for months. Here’s what a real ransomware recovery plan looks like in practice, hour by hour, from the engineers who run them.
Hour 0–1: Contain, don’t clean
The instinct is to start deleting things. Don’t. The first move is isolation: pull infected machines off the network, disable Wi-Fi, and segment anything that talks to shared storage. Endpoint protection like SentinelOne can automatically quarantine affected devices, which buys you time.
Do not power machines off. Memory holds forensic evidence and, in some cases, encryption keys. Disconnect, don’t shut down.
Hour 1–4: Scope the blast radius
Now you find out what you’re dealing with. Which systems are encrypted? Which accounts were compromised? Is the attacker still inside? This is where 24/7 monitoring earns its keep; if your MSP saw the first alerts, containment likely started before you knew there was a problem.
Reset credentials for any account that touched an infected system. Assume admin accounts are burned until proven otherwise. Enforce MFA everywhere if it wasn’t already.
Hour 4–8: Verify your backups before you touch them
This is the hour that separates companies with a ransomware recovery plan from companies with a backup subscription. Attackers target backups first. Before restoring anything, verify that backup copies are clean, complete, and predate the infection. Restoring from a compromised backup just reinfects the environment.
If backups were encrypted or deleted, this is when leadership, legal, and cyber insurance get on a call. Paying a ransom is a legal and financial decision, not an IT one.
Hour 8–16: Rebuild from known-good
Wipe and reimage infected endpoints. Restore servers from verified backups into a clean, isolated environment first, then reconnect in stages. Patch the entry point before anything goes back online; restoring systems with the same open door invites round two.
Hour 16–24: Communicate and document
Clients, staff, and possibly regulators need to hear from you. What’s known, what’s suspected, what’s next. Document everything: timeline, affected systems, actions taken. You’ll need it for insurance, compliance, and improving the plan itself.
Plan it before you need it
A ransomware recovery plan only works if it exists before hour zero. Tested backups, defined roles, isolation procedures, and an MSP who picks up the phone. SADOS backs its clients with 24/7 monitoring, SentinelOne endpoint protection, and U.S.-based engineers on every ticket, 4-hour response SLA included. Not sure your backups would survive an attack? Start there. See how SADOS handles cybersecurity.