Quick answer: When ransomware hits, the decisions made in the first 24 hours decide whether it stays a minor outage or becomes a weeks long crisis. Instead of panicking and shutting machines down, isolate the affected ones from the network (pull the cable, turn off Wi-Fi) but keep them powered, because data in memory can be valuable for analysis. Take your backups offline and read only immediately, or the encryption will reach them too. Do not pay the ransom: payment does not guarantee your data comes back and marks you as a repeat target. Document the incident, notify the national authority and, where required, the data protection authority, and engage an incident response team. In short, the first day is about three things: stopping the spread, preserving evidence, and notifying the right parties.

Ransomware usually hits an organization quietly, in the middle of the night or over a weekend. You arrive in the morning, files will not open, there is a payment note on the screen, and everyone is looking at you. The first moves decide the outcome. This article walks through what to do, step by step, in the first 24 hours, and which mistakes make things worse.

The first hours: stop the spread

The most dangerous trait of ransomware is that it does not stay on one machine; it spreads across network shares, backups and other servers. So the first job is to cut the affected systems off the network. Physically pull the network cable, turn off the wireless, and isolate the affected VLAN if you can.

A common mistake is shutting the machines down right away. But a running system may hold data about the encryption key or the attacker's traces in memory, and that helps in forensic analysis. Instead of cutting the power, isolate from the network. This distinction matters later in the digital evidence and chain of custody process.

Save your backups (while there is still time)

Modern ransomware campaigns hunt the backups first. The goal is to leave you helpless and force payment. If your network attached backups are still clean, take them offline at once and mark them read only. In cloud backups, turn on version history and delete protection.

The real lesson here is taught before the incident: backups that follow the 3-2-1 rule, with at least one copy fully offline (air gapped), are the strongest card you hold against ransomware. For organizations with no backup strategy, the first 24 hours are far more painful.

Why you should not pay

Payment always sits on the table as an option, especially when the business stops. But the truth is that a significant share of organizations that pay do not get all their data back, and many are hit again within months. Payment signals to the attacker that this organization pays, and in some countries paying groups on a sanctions list carries additional legal risk. Running recovery from backups and incident response is cheaper and safer in the long run.

Notification and legal obligations

Ransomware is often a data breach; before encrypting, the attacker steals the data and threatens to leak it (double extortion). If personal data was affected, you need to consider notifying the data protection authority within 72 hours; for details see the 72 hour breach notification guide. Also report the incident to the national cyber incident response center. Running the process within a cyber incident response playbook makes sure neither the technical nor the legal steps are skipped.

First 24 hours checklist

Time Action Purpose
First 1 hour Isolate affected systems from the network Stop the spread
First 1 hour Do not power off, keep power on Preserve memory evidence
1-3 hours Take backups offline and read only Secure the recovery path
2-6 hours Engage the incident response team Controlled recovery
6-24 hours National authority and data protection notification Legal compliance
6-24 hours Find and close the entry path Prevent recurrence

Find how they got in

Bringing the system back is not enough; if the attacker used the same door, they return a few weeks later. Ransomware usually gets in through three paths: a phishing attachment an employee opened, an internet exposed remote desktop (RDP) with a weak password, or an unpatched server flaw. Bringing the system back up without finding and closing the root cause invites a second incident. Leaked credentials are also a common starting point; review your leaked passwords and credential stuffing risk.

The KAOS and DSET approach

DSET works on both the response side of ransomware and on prevention before it happens. Our local AI engine KAOS scans the organization's external surface to detect classic ransomware entry paths such as internet exposed RDP, unpatched services and leaked credentials, and reports every finding with a working proof, without noise. When an incident happens, our forensics team preserves the evidence, finds the entry path and manages recovery. The goal is not to meet that payment note one morning.

Frequently asked questions

If I pay the ransom, will my data come back? There is no guarantee. A significant share of organizations that pay do not get all their data back, and the decryptor tool they receive is often slow or flawed. Payment also marks you as a paying organization and makes you a repeat target. The right path is to run recovery from clean backups and a controlled incident response.

Should I shut the computers down right away? No, do not shut them down; isolate them from the network. A running system may hold the encryption key or the attacker's traces in memory, and that is valuable in forensic analysis. Cutting the power destroys this evidence. Pulling the network cable or turning off the wireless is enough to stop the spread.

I am a small business, do I still have to notify? If personal data was affected, notification to the data protection authority is on the table regardless of business size. Reporting the incident to the national authority is also important, both legally and so the community can prepare for similar attacks. An incident response advisor helps you clarify which notifications are mandatory.

Sources

To prepare your organization against ransomware or manage recovery after an incident, contact DSET. We provide security and incident response consulting from our Ankara Hacettepe Teknokent laboratory.