Knowledge · Guides & Articles · Guide

Ransomware: What to Do in the First Hour

A calm, step-by-step playbook for the first sixty minutes after a ransomware attack — how to contain it, who to call, and the costly mistakes to avoid.

Cybersecurity 4 min read Updated 2026-07-15

Ransomware: What to Do in the First Hour

You sit down, and instead of your files you see a ransom note demanding payment in cryptocurrency. Your stomach drops. What you do in the next sixty minutes matters more than almost anything else — it determines how far the infection spreads, whether you keep any clean data, and whether you preserve the evidence investigators and insurers will need. This is not legal advice, and every situation is different, but here is a sound general playbook.

Minute 0 to 5: Do not panic, and do not pay yet

Take a breath. Panic leads to the two worst mistakes: paying immediately, or wiping the machine to “make it go away.” Do neither yet. Paying does not guarantee you get your files back, may violate sanctions rules, and marks you as a target for the next attack. Wiping destroys the evidence you may legally need. Leave the ransom note on screen and take a photo of it with your phone.

Minute 5 to 15: Contain it — pull it off the network

Ransomware spreads across networks, shared drives, and cloud sync folders. Your single most important action is to stop the spread:

Minute 15 to 30: Assess the scope

Now figure out how bad it is, without touching the infected machine more than necessary.

Minute 30 to 45: Notify the right people

You do not have to handle this alone, and in many cases you are legally required to involve others.

Minute 45 to 60: Preserve evidence and plan recovery

Mistakes that make it worse

After it is over: prevent the next one

The only real defense is preparation. Keep offline, tested backups following the 3-2-1 rule (three copies, two media types, one off-site and disconnected). Turn on multi-factor authentication everywhere. Patch your systems. Train your team to spot phishing, which is how most ransomware gets in. A recovery plan you have actually tested is worth more than any ransom you could pay.

Reminder: This is general guidance, not legal advice. For your legal obligations, consult an attorney or the Indiana Attorney General’s office, and report the crime to the FBI at ic3.gov.

⚠ Safety note: This guide is general information, not legal advice. Ransomware may involve reporting obligations under Indiana and federal law. Contact law enforcement (FBI IC3 at ic3.gov), and for guidance on your legal duties consult an attorney or the Indiana Attorney General’s office. When in doubt, call a professional before acting.

← Back to the Knowledge hub