Cybersecurity

Ransomware Recovery: What to Do in the First 24 Hours

In brief

The first 24 hours of a ransomware attack decide the cost. Isolate infected devices immediately without powering them off, photograph the ransom note to preserve evidence, do not pay, and call your incident response team while you report to the FBI and CISA. Then restore from clean, offline backups. Fast, ordered action is why 53% of victims now recover within a week.

A ransomware attack is a race against the clock, and the first 24 hours set the price you pay in downtime, data, and money. The response follows a fixed order: contain the spread, preserve the evidence, resist the ransom, call for expert help, report to law enforcement, and rebuild from backups. Businesses that move through those steps calmly and quickly recover in days. Businesses that panic, reboot machines, or rush to pay often turn a contained incident into a shutdown. This guide walks the first day in the exact order you should act, with the verified data behind each decision.

The stakes are highest for small and mid-sized businesses. Ransomware appeared in 88% of breaches at small and mid-sized organizations in the Verizon 2025 DBIR, compared with 39% at large enterprises, according to Infosecurity Magazine's coverage of the report. A smaller company usually has fewer people to run the response and less cash to absorb the downtime, which makes a disciplined plan even more valuable. The good news is that the plan is knowable in advance, and the outcomes for prepared organizations keep improving.

53% of ransomware victims fully recovered within a week in 2025, up from 35% the year before, while only 18% took more than a month, down from 34%. The businesses that recover fastest are the ones that contain the attack in the first hours. Sophos State of Ransomware 2025

Hour zero: isolate the infected systems first

Your first move is to stop the spread by isolating every affected device from the network. Ransomware is built to travel, scanning for shared drives, mapped folders, and other machines to encrypt, so each minute a compromised device stays connected widens the blast radius. Disconnect the network cable, disable Wi-Fi and Bluetooth, and if several systems or subnets are already hit, isolate the network at the switch level to cut everything off at once. Speed matters more than precision here. It is better to disconnect a machine you are unsure about than to leave one infected device talking to the rest of your network.

One caution overrides the instinct to hit the power button. Do not shut affected devices down unless isolating them any other way is impossible. Powering a machine off wipes the volatile memory that holds the ransomware's fingerprints, the encryption process, and clues investigators use to identify the strain and sometimes to decrypt it. The goal is to break the network connection while keeping the evidence intact. Pull the cable, kill the wireless, and leave the device running.

Preserve the evidence before you touch anything

Before you start cleaning up, capture what the attack left behind, because that evidence drives both recovery and any insurance claim. The single most important artifact is the ransom note. Photograph it with a phone or separate camera so you keep the exact wording, the payment instructions, the attacker's contact details, and any identifiers that help match the incident to a known ransomware group. That photograph often speeds recovery, because identifying the strain can point to a free decryptor, and it is standard evidence for a police report or a cyber insurance filing.

The federal CISA #StopRansomware Guide goes further and recommends taking a full system image and a memory capture from a sample of affected devices before any eradication begins. It also advises coordinating the response quietly and using out-of-band communication, such as phone calls rather than the compromised email system, so the attackers do not see that you have discovered them and accelerate the encryption. Treat the scene like a crime scene, because legally and technically, it is one.

Do not pay the ransom

Paying the ransom is neither required nor a reliable way to get your data back. The FBI advises against paying because it funds the criminal operation, marks you as a willing target for the next campaign, and offers no guarantee the attackers will hand over working decryption keys. Many victims who pay still lose data, and some are extorted a second time. The stronger position is to treat the ransom as a last resort you have engineered your way out of, not a line item in the recovery budget.

64% of ransomware victims declined to pay in 2025, up from roughly half two years earlier, and the median ransom payment fell to $115,000 from $150,000. Refusing to pay is now the norm, and it works when you have backups to restore from. Verizon 2025 DBIR

Refusing to pay only holds up when you can recover another way, which is exactly why the backup step later in this list matters so much. If you have tested, offline backups, the ransom loses its leverage entirely. Free decryptor tools published through the No More Ransom project can also unlock data encrypted by certain strains at no cost, which is another reason to identify the ransomware early rather than reaching for a checkbook. Keep the decision in the hands of your incident response team and, if you carry it, your cyber insurer, who negotiate these situations for a living.

Call your incident response team and get expert help

Within the first hour, escalate to the people equipped to run the response. That means your internal IT and security leads, your managed IT or security provider, and your cyber insurance carrier if you hold a policy, because insurers often require early notification and provide an approved incident response firm. A specialist team knows how to identify the ransomware variant, confirm the full scope of the compromise, and guide eradication without destroying evidence or missing a hidden foothold the attackers left behind.

This is also the moment to activate your incident response plan and assemble the people who need to make decisions, including leadership, legal counsel, and whoever handles communications. Assign clear roles so the technical work, the reporting, and the customer communication happen in parallel rather than waiting on one overloaded person. A small business without an in-house security team should have this contact list arranged in advance, because looking up who to call while your systems are encrypted costs hours you do not have.

Report the attack to the FBI and CISA

Report the attack to law enforcement as part of the first-day response, not as an afterthought weeks later. File with the FBI's Internet Crime Complaint Center at IC3.gov and notify CISA, which coordinates the national ransomware response and can sometimes provide guidance or decryption resources. Reporting feeds the intelligence that helps disrupt the groups behind these attacks, and it may be legally required depending on your industry and state breach-notification rules.

$16.6B in reported cybercrime losses across the United States in 2024, a 33% increase over the prior year, logged across 859,532 complaints to the FBI's Internet Crime Complaint Center. Those totals only reflect the incidents victims reported. FBI IC3 Internet Crime Report, 2024

Reporting carries a practical upside beyond civic duty. Law enforcement occasionally holds decryption keys seized from ransomware operations, and a filed report is what connects your case to that help. It also creates the paper trail your insurer and, potentially, regulators will expect. The businesses that stay silent gain nothing and lose access to the one set of resources built specifically to help ransomware victims recover.

Restore from clean, offline backups

Recovery comes from your backups, which is why tested, offline copies of your data are the most important control you own. Once the environment is contained and the infected systems are wiped and rebuilt, you restore from a backup taken before the attack. The critical detail is that the backup must be isolated from the network, because modern ransomware deliberately hunts for and encrypts connected backups first. An immutable or air-gapped copy is what survives to bring you back.

54% of organizations restored their data from backups in 2025, the lowest share in six years, even though backups remain the fastest and cheapest way to recover without paying a ransom. Sophos State of Ransomware 2025

Restore in priority order, bringing back the systems that keep the business running first, and verify each restored system is clean before you reconnect it. Do not rush everything online at once, because a single missed foothold can re-encrypt a freshly restored environment. This is the step where preparation pays off most clearly. A business that tests its restores regularly knows the backups actually work, while a business that has never tried often discovers, at the worst moment, that its backups are incomplete, corrupted, or were encrypted along with everything else.

Why the first 24 hours decide the final bill

Every hour of the first day compounds into the eventual cost, in downtime, forensics, lost customers, and recovery labor. The organizations that contain and restore quickly spend far less than those that let the attack sprawl or spend days deciding whether to pay.

$1.53M was the average ransomware recovery cost in 2025, excluding any ransom paid, down from $2.73 million in 2024. The figure covers downtime, investigation, and rebuilding, and it grows with every hour the response is delayed. Sophos State of Ransomware 2025

The broader breach data reinforces the point that speed lowers cost. IBM found the mean time to identify and contain a breach fell to 241 days in 2025, the lowest in nine years, and that breaches contained faster cost meaningfully less than those that dragged on. The global average cost of a data breach was $4.44 million that year, according to IBM's Cost of a Data Breach Report. You cannot control which day an attacker strikes, but the response you run in the first 24 hours is squarely in your hands, and it is the single biggest lever on how the story ends.

Prepare now so the first 24 hours go smoothly

The best time to write your ransomware response plan is long before you need it. A prepared business has isolated, tested backups, a written incident response plan, a current contact list for its IT provider and insurer, and staff who know not to reboot or pay on instinct. That preparation is the difference between a bad week and a business-ending event, and it is far cheaper than either.

Building and maintaining that readiness is more than most small teams can sustain alone, which is where a managed provider earns its place. Tuminto sets up immutable backups, monitors for the early signs of ransomware, and keeps a tested response plan ready as part of coordinated cybersecurity services, so if the day ever comes, the first 24 hours run by a plan instead of by panic. The aim is simple: contain fast, recover from backups, and never have to weigh whether to pay.

Assume the attackers stole your data, not just locked it

Modern ransomware usually steals your data before it locks it, so treat every attack as a data breach from the first hour. Most groups now run double extortion, copying sensitive files out of the network and threatening to publish them on a public leak site even if you restore from backups and never pay. Some escalate to triple extortion, adding denial-of-service attacks or direct threats to your customers and staff. Because of that shift, one of your first-day tasks is to check whether data left the network. Review outbound traffic, firewall logs, and any data loss prevention alerts for large or unusual transfers, and look for staging folders or compression tools the attacker used to package files. If data was taken, the incident carries legal disclosure duties. State breach-notification laws, and rules like HIPAA for regulated data, can require you to notify affected people and regulators within a set window, and publicly traded companies must disclose material incidents to the SEC within four business days. Bring in breach counsel early so those clocks are tracked from hour one, following the exfiltration checks in the CISA #StopRansomware Guide.

Find how the attackers got in, and name the strain

Before you rebuild, find the door the attackers used, because restoring without closing it invites them straight back in. Ransomware operators rarely appear out of nowhere. They usually get in through an unpatched vulnerability, a phishing email, or a stolen password, then linger in the network for days or weeks, moving laterally and escalating privileges before they trigger encryption. That dwell time is why the ransom note is the last step, not the first. Have your incident response team trace the entry point and any backdoors or new admin accounts the attacker left for re-entry, and confirm the full blast radius before a single system comes back online. At the same time, name the strain. The ransom note, the file extensions on encrypted files, and the attacker's contact details identify the variant, and running them through ID Ransomware or the No More Ransom project confirms the match. Some strains have known flaws, so a free decryptor may already exist and spare you a rebuild. Identifying the variant early shapes the whole recovery.

29% of enterprise ransomware attacks in 2025 started with an exploited vulnerability, the single most common technical entry point, while phishing and compromised credentials each accounted for 21%. Closing that entry point is what stops a repeat attack. Sophos State of Ransomware in Enterprise 2025

Notify your cyber insurer before you hire your own responders

If you carry cyber insurance, call the carrier before you engage any outside responders, because most policies require early notice and will not reimburse costs from a firm you hired on your own. Insurers keep vetted panels of incident response firms, forensic investigators, and breach counsel, and the carrier connects you to that approved team the moment you report. Save the insurer's 24-hour breach hotline number now, so the notification call takes minutes rather than slowing the response. Route the forensic work through breach counsel rather than hiring investigators directly. In many cases that keeps the resulting report under attorney-client privilege, which matters if litigation or a regulatory review follows, and counsel also tracks the notification deadlines the incident triggers. One more legal point shapes any payment discussion. Paying certain sanctioned ransomware groups can itself break the law, so the decision belongs with your insurer, counsel, and response team, never with a panicked individual reaching for a wire transfer. The order you make these calls protects both your coverage and your legal position.

Confirm the backup itself is clean before you trust it

A backup is only a recovery if it is clean, so validate the copy itself before you restore from it. Modern ransomware groups spend days or weeks inside a network before they encrypt anything, and during that window they hunt for backups to corrupt or delete so paying becomes your only option. A backup that looks intact may already hold the attacker's tooling or postdate the initial break-in. Before you restore, have your team confirm the copy predates the earliest attacker activity you found and scan it for signs of compromise. Restore into an isolated clean-room environment rather than straight onto the production network, so a hidden foothold cannot re-encrypt everything the moment it reconnects. Bring systems back in dependency order, starting with identity and network services, then databases, then the applications that rely on them. This validation step is why immutable, air-gapped backups matter so much. A copy the attacker cannot reach or alter is the one you can actually trust when the day comes.

Related reading

FAQ

What should you do first in a ransomware attack?

The first action is to isolate the infected devices by disconnecting the network cable and turning off Wi-Fi, so the ransomware cannot spread to other machines or shared drives. Do not power the devices off, because volatile memory holds evidence investigators need. Then photograph the ransom note, alert your incident response team, and begin reporting. Speed in this first step is what limits the damage.

Should I pay the ransom?

No, paying is not required and does not guarantee recovery. The FBI advises against paying because it funds further crime and offers no assurance you will get working decryption keys. Most victims now agree: 64% of ransomware victims declined to pay in the Verizon 2025 DBIR, and the median ransom fell to $115,000. If you hold tested offline backups, you can restore without paying.

How long does it take to recover from ransomware?

Recovery time is improving. In the Sophos State of Ransomware 2025 report, 53% of victim organizations fully recovered within a week, up from 35% the year before, and only 18% took more than a month. The businesses that recover fastest are the ones that isolate quickly in the first hours and restore from clean, tested backups rather than negotiating.

Should I turn off my computer during a ransomware attack?

Disconnect it from the network, but do not shut it down unless you cannot isolate it any other way. CISA warns that powering a device off erases ransomware artifacts and evidence held in memory, which investigators and cyber insurers rely on. Pull the network cable and disable Wi-Fi to stop the spread while keeping the machine on.

Do I have to report a ransomware attack?

You should report every ransomware attack to the FBI through IC3.gov and to CISA, and many industries and states legally require breach notification. The FBI's Internet Crime Complaint Center logged $16.6 billion in reported cybercrime losses in 2024, and its data depends on victims coming forward. Reporting also opens access to law enforcement resources and, in some cases, free decryption keys.

Can you recover data after ransomware without paying?

Yes, if you have tested, offline backups. Restoring from backup is the standard recovery path, and 54% of organizations used backups to get their data back in 2025 according to Sophos. Free decryptor tools from the No More Ransom project can also recover data locked by certain ransomware strains. Paying should be a last resort, not the plan.

Do ransomware attackers steal data before encrypting it?

Often, yes. Most ransomware groups now run double extortion, copying sensitive data out of the network before they encrypt it and threatening to publish it on a leak site even if you restore from backups. That turns the attack into a data breach with legal disclosure duties, so check your outbound traffic and firewall logs for signs of exfiltration in the first 24 hours and engage breach counsel to track any notification deadlines.

How do ransomware attackers get into a business network?

Ransomware usually enters through an exploited vulnerability, a phishing email, or a stolen password. In the Sophos State of Ransomware in Enterprise 2025 report, an exploited vulnerability was the most common technical entry point at 29% of attacks, with phishing and compromised credentials each at 21%. Attackers then dwell in the network for days or weeks before encrypting, so finding and closing that entry point is essential before you restore.

Who should I call first after a ransomware attack?

Call your incident response team and your cyber insurance carrier within the first hour, and if you hold a policy, notify the insurer before you engage any outside vendor. Many policies will not reimburse response costs if you hire a firm before reporting, and the insurer connects you to an approved team of responders, forensic investigators, and breach counsel. Save your insurer's 24-hour breach hotline number before you ever need it.

How do I know which ransomware strain hit my business?

You identify the strain from the ransom note, the file extensions added to encrypted files, and the attacker's contact details, then confirm the match through ID Ransomware or the No More Ransom project. Naming the variant matters because some strains have known flaws with a free public decryptor, which can let you recover without paying or rebuilding. Identify the strain early, because it shapes the rest of the recovery.

Recover in days, not weeks

Build your ransomware response plan

We will review your backups, monitoring, and response readiness, then show you exactly where a ransomware attack would hurt most, with no obligation.

Book a Consultation