The First 60 Minutes After a Ransomware Discovery

What matters in the first hour after you find encrypted files—and what to leave alone. A level-headed procedure for SMEs, before panic turns into mistakes.

The moment someone notices the first encrypted file shapes the damage more than all the weeks that follow. Not because everything could still be saved in that hour—but because it is when the most expensive mistakes get made. React unprepared and you wipe traces, lose evidence, or reinfect the freshly cleaned environment a second time by restarting in a rush.

This procedure does not replace an incident response plan—it describes what holds in the first hour, before the plan has been pulled off the shelf.

Isolate, Don’t Power Off

Affected systems belong off the network—but, where possible, not shut down hard. Powering off destroys volatile traces in memory that can be decisive for later analysis (which account, which malware, since when). Pull the network cable, disconnect Wi-Fi and VPN, seal off affected segments: this stops the spread without destroying the evidence.

Protect Backups Immediately

Modern ransomware deliberately hunts for backups and deletes or encrypts them along with everything else. The first active step therefore goes to the backups: if they are reachable, connections to them are severed; immutable, offline copies (Object-Lock) are now the most valuable asset in the building. Whatever has not yet been touched must no longer be reachable.

One Person Decides

In a real incident you need one named person to coordinate—not a dozen acting in parallel. That role decides on isolation, communication, and the order of recovery. If it is not fixed in advance, simply sorting out “who is actually allowed to do what here?” costs precious time.

Reporting Is Part of It

Depending on the impact, notification duties apply: for personal data, to the data protection authority (generally within 72 hours), and for regulated operators, additionally under NIS-2 (the EU cybersecurity directive) or sector-specific rules. Filing a criminal complaint with the police’s Central Cybercrime Contact Point (ZAC, Zentrale Ansprechstelle Cybercrime) preserves evidence and is often a prerequisite for insurance payouts. Setting these steps in motion in parallel, rather than handling them “after the cleanup,” prevents missed deadlines.

What to Leave Alone in the First Hour

  • Don’t pay under time pressure. The ransom question is a decision for later, with legal counsel and authorities—not for the first hour.
  • Don’t restore prematurely. A restore into a still-compromised environment encrypts the data a second time. Understand the cause first, then recover.
  • Don’t clean up the traces. Logs, affected systems, and storage media stay untouched until the analysis releases them.

Why This Belongs Prepared in Advance

All of this can only be carried out in the first hour if it was written down beforehand and rehearsed at least once: who decides, where the offline backups sit, which systems come back in which order, who gets informed and when. As an owner-run IT systems house in Solingen, we keep this incident readiness current for our clients—with immutable, geo-redundant backups and tested recoveries (hands-on Veeam practice), 24/7 monitoring through our NOC, and a rehearsed procedure—at a predictable flat monthly rate as part of our Business Continuity and Managed Services. The first hour is not a good time to start thinking about the procedure.

Let's talk about your situation.