Ransomware Recovery: What to Do in the First 24 Hours
There is a specific moment every ransomware victim describes the same way: an employee notices files won’t open, then a second person reports the same thing, and within minutes it’s clear this isn’t one workstation’s problem. Per CISA’s #StopRansomware guidance https://www.cisa.gov/stopransomware, what an organization does in the next few hours matters enormously. It has more influence on the eventual cost and downtime of a ransomware incident than almost any decision made before the attack. This guide is a practical, hour-by-hour framework for that first day. It’s written for the decision-maker who is dealing with this for the first time, under pressure, without the luxury of researching best practice in the moment.

Hour Zero: Contain Before You Investigate
The instinct to understand what happened before acting is natural, but containment has to come first. Every minute a ransomware strain keeps spreading across the network means more systems encrypted and more recovery work later.
**Immediate actions, in order:**
1. **Disconnect affected systems from the network** — pull the network cable or disable Wi-Fi on visibly affected machines. Do not power them off yet; a powered-off machine can lose forensic evidence in memory that’s valuable for understanding the attack later. Some encryption processes can also be interrupted mid-execution by isolating rather than shutting down.
2. **Isolate network segments**, not just individual machines, if the spread is already touching multiple systems — this may mean disabling switch ports or segmenting VLANs rather than trying to chase down every infected endpoint individually.
3. **Disable shared network drives and file shares** organization-wide, temporarily, to stop ransomware from reaching backup-adjacent storage or other departments’ data before you’ve confirmed the blast radius.
4. **Do not pay, and do not negotiate**, at this stage — that decision needs full information and, ideally, legal and law enforcement input, not a panicked response in hour one.

Hour One to Three: Assemble the Response and Notify
**Activate your incident response plan** — if one exists, this is the moment it earns its keep. If one doesn’t exist, this incident is the reason to build one immediately afterward.
**Who to call, and in what order:**
1. **Your managed security provider or internal security lead** — for technical triage and containment support.
2. **Your cyber insurance provider**, if you carry a policy. Many policies require notification within a specific window, and most insurers maintain panels of approved incident-response and forensics firms whose costs are covered — versus firms you engage independently.
3. **Legal counsel** — particularly relevant given Saudi PDPL notification obligations if personal data may have been affected, and to guide communication so nothing said internally or externally inadvertently creates liability before the facts are established.
4. **Law enforcement** — reporting a ransomware incident is both a legal consideration in many jurisdictions and can sometimes provide access to decryption tools or intelligence on the specific ransomware family involved.
**Do not delete anything.** Encrypted files, ransom notes, and any suspicious emails or files that may be the initial infection vector are all evidence — both for understanding the attack and for any insurance or law enforcement process that follows.

Hour Three to Twelve: Assess the Actual Damage
With the immediate spread contained, the priority shifts to understanding scope:
– **Which systems are encrypted, and which are merely disconnected as a precaution?** These are different categories and get triaged differently.
– **What ransomware family is this?** Identifying the specific strain (often visible in the ransom note or file extension pattern) matters. Some older or poorly-implemented ransomware families have known decryption tools published by security researchers — worth checking before assuming payment or full restore is the only path.
– **Are backups intact?** This is the single most important question in the entire incident, and the answer depends entirely on decisions made long before the attack. Backups that were reachable from the compromised network (a “backup” that’s really just another network share) are frequently encrypted along with everything else. Attackers specifically target backup infrastructure because they know it’s the organization’s escape route.
– **Is there evidence of data exfiltration, not just encryption?** Many modern ransomware operations steal data before encrypting it, then threaten to publish it as additional leverage — a materially different incident, with different notification and legal obligations, than encryption alone.

Hour Twelve to Twenty-Four: Begin Recovery Planning
This is where an organization’s backup strategy — decided months or years earlier — determines whether recovery takes hours or weeks.
**The 3-2-1 backup principle** (three copies of data, on two different media types, with one copy stored offline or otherwise isolated/immutable) exists specifically for this scenario. An isolated or immutable backup copy — one ransomware cannot reach or modify even with full network access — is the difference between “we restore from last night’s backup by end of day” and “we’re negotiating with criminals because every copy of our data was reachable from the same compromised network.”
**Recovery sequencing priorities**, once clean backups are confirmed:
1. Core business systems required for revenue-generating operations first
2. Email and communication systems, so the organization can coordinate its own response and communicate externally
3. Supporting and non-critical systems last
**Before restoring anything**, confirm the environment is actually clean. Restoring into a network where the attacker’s initial access point hasn’t been identified and closed is a well-documented way for organizations to be re-encrypted within days of “recovering.”

The Question That Determines Everything: Do You Have Clean Backups?
Every recommendation above assumes an isolated, tested, recent backup exists. If it doesn’t, the organization’s options collapse to three uncomfortable ones. Rebuild from scratch (often weeks of lost productivity and data), pay the ransom (with no guarantee of receiving a working decryption key, and its own legal and ethical considerations), or accept permanent data loss. This is why backup architecture is not an IT line item — it’s the single control that determines whether a ransomware attack is a bad day or an existential event for the business.
A properly configured backup strategy uses immutable, air-gapped, or otherwise isolated backup targets. Platforms like Acronis Cyber Protect Cloud are built specifically around this model, combining backup with built-in ransomware detection that can halt an active encryption process and auto-restore affected files. That turns “do we have clean backups” from a source of dread into a confirmed yes, checked routinely rather than discovered under pressure.
After the First 24 Hours
Once immediate containment and initial recovery planning are underway, the work shifts to root-cause identification: how did the attacker get in — phishing, an exposed remote-access service, a compromised credential? Then comes closing that specific gap before full restoration, and a post-incident review that feeds back into the organization’s security posture. Ransomware recovery doesn’t end when systems come back online; it ends when the entry point that allowed the attack is actually closed.
The Real Lesson
Nearly every element of a fast, low-damage ransomware recovery was decided before the attack happened: whether backups were truly isolated, whether an incident response plan existed and had been rehearsed, whether monitoring would catch the spread in minutes rather than hours. The first 24 hours after ransomware hits are where preparation gets tested, not where it gets built.

—
*SirajTech deploys Acronis Cyber Protect Cloud with immutable backup and built-in ransomware detection, and provides incident response support for Saudi businesses facing an active ransomware event. If you are dealing with an active incident right now, contact our emergency response line immediately rather than continuing to read.* Contact