The first 24 hours of a ransomware attack decide whether it’s an incident or an extinction event — and most of the critical moves are non-technical. Hour one: contain without destroying evidence, assume email is compromised, declare the incident. Hours 1–4: stand up an incident commander, engage legal counsel to direct the IR firm (privilege), notify cyber insurance, move to out-of-band comms. Hours 4–12: scope the compromise, assume domain admin loss, verify backup integrity before trusting any restore. Hours 12–24: regulatory clocks are running (GDPR 72h, SEC 4 business days), pay/no-pay is a business decision with sanctions and legal exposure — rehearsed teams make it calmly. The organisations that survive rehearse this before it happens.
At 2:19 a.m. on February 21, 2024, Change Healthcare — the company that processes roughly one in three American medical claims — lost its network to an ALPHV/BlackCat ransomware affiliate. Within hours, pharmacies nationwide couldn’t verify insurance. Prescriptions stalled for cancer patients. The company disconnected over 100 systems, and the outage ran for weeks, not hours. A ransom payment of roughly $22 million was later traced on-chain, and the affiliate reportedly got stiffed by its own ransomware-as-a-service operator in an exit scam — a reminder that even “resolving” an extortion can go sideways.
Change Healthcare had resources most organisations can only dream of. What separates survivors from casualties at their scale — and at yours — is rarely the security budget. It’s what the incident team does, in order, in the first 24 hours. This playbook walks those hours minute-by-minute, then covers the part most technical articles skip: the non-technical decisions — people, communications, legal posture, and logistics — that decide whether the company on the other side of day one is still a going concern. (For how attackers typically get the initial foothold that ends in ransomware, see One Key to Rule Them All.)
The Clock Starts Long Before the Encryption
The single most important mental model for the first 24 hours: the ransomware detonation is the end of an intrusion, not the beginning. Modern crews dwell inside networks for days or weeks before triggering encryption — staging payloads, mapping file shares, harvesting credentials, and above all exfiltrating data. Double extortion has been the default operating model for years: they encrypt what they can’t steal quietly, and they steal what gives them leverage after you restore.
Three consequences follow, and every good playbook is built on them:
- Assume Active Directory is gone. If encryption ran, assume domain admin is compromised until forensics proves otherwise. Every credential in the forest is hostile until rotated.
- Assume the data is already stolen. Plan statements, legal exposure, and notifications on that basis; being pleasantly surprised beats the reverse.
- Assume your communications are monitored. Email, chat, and conferencing run on the compromised network. Move critical coordination out-of-band from the first hour.
With that model loaded, here are the actual hours.
Hour Zero: The First Sixty Minutes
Encryption declares itself loudly: files renaming themselves, applications erroring en masse, AV alerts firing across dozens of hosts simultaneously, and — most reliably — a helpdesk spike from users whose documents have turned into garbage. The first hour is a sequence, and the order matters:
- T+0–5 min: Someone recognises this is ransomware, not a glitch, and declares an incident. The single biggest first-hour failure is ambiguity about whether this is “an issue” — declared incidents get resources.
- T+5–15 min: Isolate, don’t annihilate. Disconnect affected segments, kill VPNs and remote-access gateways, disable suspect accounts. Do not wipe, reimage, or “clean” anything yet — evidence of how they got in lives on those machines.
- T+15–30 min: Protect the crown jewels. Cut remaining links between compromised and clean segments. If backups are domain-joined or network-accessible, isolate them now — attackers hunt them deliberately in the final minutes before detonation.
- T+30–60 min: Establish out-of-band comms — personal phones, a pre-paid messaging channel, anything off the corporate identity plane. Start a timestamped decision log. Notify leadership through the crisis tree, not email blasts.
| Phase | Do | Don’t |
|---|---|---|
| Detection (T+0–5) | Declare incident; start decision log | Debate severity for an hour |
| Containment (T+5–15) | Segment, kill VPN/suspect accounts | Power-cycle or reimage everything |
| Backup defence (T+15–30) | Isolate backup infrastructure | Trust “it’s on another VLAN” |
| Command (T+30–60) | Out-of-band channel; call the tree | Coordinate over compromised email |
Hours 1–4: Stand Up the Machine
By roughly 9:00 a.m. of day one, the informal heroics must become a structure. This is the window where the technical incident becomes an organisational one:
1. Name the incident commande
One person owns decisions — not the CEO, not the CISO’s whole team, one accountable commander with a deputy. Everyone else works for them. Rotation exists (you cannot run a 24-hour operation on adrenaline), but authority never splits.
2. Put counsel in the chain of command — first
Engage outside counsel experienced in cyber incidents, and have counsel retain the incident-response firm. That structure makes investigative work product privileged, which matters enormously when plaintiffs’ lawyers arrive at month three. Brief litigation-hold expectations to everyone taking notes.
3. Notify cyber insurance — precisely
Most policies require prompt (sometimes near-immediate) notification and often dictate which IR firm, which negotiators, and which forensics vendors you may use. Calling your broker is a 10-minute task on a normal day; failing to do it in the window can jeopardise the entire claim. If you’re reading this before an incident, check the clause tonight.
4. Engage law enforcement early
National cyber authorities (CISA and the FBI in the US, the NCA in the UK, EU CERTs, local e-crime units) bring decryptors for retired strains, intelligence on active crews, and — occasionally — quiet wins like law-enforcement seizures that hand victims keys back. They do not bring obligations to tell your customers; treat them as allies, not threats.
5. Build the war room’s second life
Out-of-band group chats, a physical room if feasible, and a battle rhythm: 30-minute coordination loops early, stretching as the picture stabilises. Log every decision with a timestamp and the rationale — this log becomes the backbone of your regulatory disclosure, insurance claim, and post-incident report.
Hours 4–12: Scope, Preserve, and Interrogate Your Backups
The afternoon is a technical triage with three fronts. IR analysts start reconstructing the intrusion while the business answers the question that actually determines the cost of the event: when do we operate again?
- Forensics: Find the ingress point and the earliest attacker activity. Common openings: phished credentials with no MFA, an unpatched edge device, a valid but leaked key. Identify the strain(s) — extortion crews increasingly run multiple encryptors, sometimes a fast crude one and a slower “quality” one.
- Scoping: Which systems encrypted, which were touched but not encrypted (the distinction decides rebuild size), and — the hard one — what left the network. Egress logs, cloud storage access, and the crew’s own leak-site claims all feed this.
- Backup integrity — the whole game: Verify the last clean restore point before trusting it. Attackers deleting or encrypting reachable backups is standard tradecraft, and restoring from a backup they poisoned re-encrypts you live on camera. Immutable or offline copies that were verified by an actual test restore, on a schedule, are the difference between a bad week and Chapter 11 discussions.
One more midday task: check the leak sites. If your data is already posted — some crews post within hours to force urgency — that changes your legal and communications posture immediately, and your 72-hour regulatory clock is already running.
Hours 12–24: The Decisions With Long Shadows
By evening of day one, three irreversible-ish decisions loom. They deserve slow thinking executed quickly:
1. Pay or not pay
Both public positions are defensible; neither is cost-free. Two well-documented reference cases frame the trade:
| Case | Choice | Outcome |
|---|---|---|
| Change Healthcare (2024) | Reportedly paid ~$22M; affiliate allegedly re-extorted | Weeks of outage; massive downstream damage; payment traced publicly |
| British Library (2023) | Refused to pay Rhysida | Months of degraded service; leaked staff/reader data; ~£2.3M+ recovery cost, gradual clean rebuild |
Paying funds the ecosystem, invites repeat extortion (you’re now a “proven payer” on the crew’s CRM), may violate sanctions regimes (OFAC and equivalents), and — as the exit-scam detail above shows — doesn’t even reliably end the incident. Not paying means absorbing the encryption fully. If payment enters consideration at all, use professional negotiators through counsel, and verify the decryptor actually exists before any transfer.
2. Rebuild strategy: clean or parallel
Two paths: restore in-place after forensics clears the ingress vector, or build a new clean environment and migrate. When AD compromise is proven — it usually is — veterans overwhelmingly favour the second: reset credentials from a trusted baseline rather than trying to launder a poisoned forest.
3. Notify — on the clocks
- GDPR: notify the supervisory authority within 72 hours of becoming aware of a personal-data breach (awareness started today, hour zero).
- US SEC: public companies file the Item 1.05 Form 8-K within four business days of determining the incident is material.
- Sector regulators (HIPAA, FCA/PRA, state breach laws, NIS2 in the EU) each have their own clocks — counsel owns this checklist from hour four.
Say only what you know. “We are experiencing a cyber incident, we have engaged external experts, and systems are offline as a precaution” is a complete first statement. Speculation about scope creates the retroactive lies that end careers.
The Non-Technical Things That Decide the Outcome
Technical responders triage machines; incidents are survived by people and logistics. The items below are the field-tested “soft” list — the 10 things breached organisations say they wish they’d known:
1. Treat your people as casualties, not resources
Staff work the worst weeks of their professional lives while their own data is leaked. Rotate hard, sleep, and watch for the “second victim” effect in week two. HR belongs in the crisis team, not on the distribution list.
2. Communicate on a cadence — even with nothing new
Customers and staff forgive bad news; they don’t forgive silence. Fix a rhythm (e.g., an external update every 24 hours) and meet it religiously with honest, minimum-necessary statements.
3. One spokesperson, zero speculation
A single trained voice externally. Executives improvising on LinkedIn and technicians venting in niche forums are how post-breach lawsuits find their exhibits.
4. Write everything down — timestamps, decisions, privilege
The decision log from hour one becomes your regulatory narrative, your insurance evidence, and your lawsuit defence. Note facts, mark legal items for counsel, keep it contemporaneous.
5. Feed the machine
Literal logistics: food, beds, credential resets for the responders, account access that doesn’t depend on the compromised domain, and someone whose only job is unblocking those things. War rooms die of friction before they die of attacks.
6. Keep employees informed ahead of the leak site
If staff data was stolen, they’ll learn from the criminals’ blog otherwise. An internal head-start message beats a press inquiry into the break room by an hour.
7. Work the third parties early
Payroll processor? Factoring bank? Critical SaaS running on the same SSO? Day one is when you protectively reset and notify them — downstream collapses usually start with a partner nobody called.
8. Don’t negotiate directly
If the crew has a chat window on your screen, counsel-managed professionals talk to them. Amateurs negotiating against professional extortionists is how a $2M demand becomes a $20M demand.
9. Pre-book the post-incident review
Announce early that you’ll run a blameless post-incident review afterwards. It sounds cosmetic; it’s what keeps people reporting bad news fast during the crisis, which is the input your commander actually needs.
10. Protect the decision-makers’ health too
The CFO making a $10M judgment call on hour 30 without sleep isn’t heroic, it’s negligent risk management. Executive rotation and a designated “cold” second-opinion peer prevent the fatigued-decision tail.
Before You Get Punched: Preparation That Pays in Hour One
Boxing gyms don’t teach you to avoid being hit — they teach you to have already decided, before the punch lands, what your shoulders and chin do anyway. Incident response is the same discipline. Six preparations, all testable before you need them:
- Rehearse. Run a ransomware tabletop with real executives twice a year. The first time the CEO hears “do we pay?” should not be day zero.
- Pre-engage. IR retainer, breach counsel, and negotiators on paper, with response SLAs — retainers get scarce the day a big strain detonates.
- Verify restores, not backups. A backup you’ve never test-restored is a hypothesis. Schedule quarterly restore drills including the “new clean environment” path.
- Build the out-of-band channel now. A contact tree on personal phones, a messaging group that doesn’t touch corporate SSO, printed copies of the crisis plan — searchable “in the cloud” is not a plan when the cloud is the crime scene.
- Decide pay/no-pay in peacetime. A board-level position (with sanctions and legal guardrails) prevents the worst outcome: deciding under duress, in public, at hour 20.
- Audit your insurance before you need it. Coverage limits, panel vendors, notification windows, and exclusions (many quietly exclude nation-state-attributed incidents) — read it as if a plaintiff’s lawyer will read it later.
None of this prevents the punch. All of it decides whether you’re still standing at hour 24.
FAQ: First 24 Hours of a Ransomware Attack
Should we pay the ransom?
It’s a business decision with legal guardrails, not a security decision. Paying doesn’t guarantee restored data, marks you as a proven payer, may violate sanctions law, and funds the next attack — but some victims with no viable restore path do pay. If so: professional negotiators, counsel, and sanctions screening, always. Never direct contact by staff.
How fast does ransomware encrypt a network?
Modern strains with domain admin privileges can begin mass encryption within minutes and hit thousands of machines in the first hour — but the intrusion behind it usually began days to weeks earlier. Speed at detonation is why containment (segmentation, killing VPNs) outperforms attempts to “outrun” encryption host-by-host.
What if the backups are encrypted or deleted too?
That’s the scenario attackers engineer for deliberately. Options narrow to: immutable/offline copies you can verify, rebuilds from scratch, insurers’ decryption resources, and payment as last resort. It’s also exactly why pre-incident restore drills outweigh almost any other control investment.
Who must we notify, and how fast?
Depends on data and jurisdiction: GDPR supervisory authority within 72 hours of awareness; SEC 8-K within four business days of a materiality determination (US public companies); sector regulators (HIPAA, FCA, NIS2) on their own clocks; and contractual customer notification windows. Counsel maintains this checklist from hour four of any incident.
Should we talk to the attackers?
Only through professional negotiators managed by counsel — never directly. Crews profile the responders; untrained contact raises prices, leaks operational detail, and creates legal exposure. If a chat window appears, screenshot, preserve, and hand it to the professionals.
We’re small — no IR team, no retainer. Now what?
Declare the incident, isolate what you can without wiping evidence, contact your national cyber authority (CISA/FBI/NCA/equivalents — free, and they hold decryptors for retired strains), call your insurer, and get breach counsel same-day. Small organisations can survive this on improvisation plus those four moves; they rarely survive on improvisation alone.
Key Takeaways
- Detonation is the end of an intrusion, not the start. Assume domain compromise, assume data exfiltration, and assume your communications are watched — all three assumptions are usually correct.
- The first hour is a sequence: declare, isolate without destroying, protect the backups, go out-of-band. Order matters; reformatting evidence in minute ten is a self-inflicted wound.
- Structure beats heroics by hour four: one incident commander, counsel directing the IR firm for privilege, insurer notified precisely, law enforcement engaged as an ally.
- The pay/no-pay and notify decisions have long legal shadows. Make them slowly in peacetime, quickly in crisis — never improvised under sleep deprivation at hour 20.
- Most of what decides day one isn’t technical: people rotation, communication cadence, decision logs, logistics, and a single non-speculating spokesperson. Rehearse all of it before you need it.
References
- Change Healthcare / ALPHV-BlackCat 2024 incident reporting — national press and blockchain analyses of the reported ~$22M payment and affiliate exit-scam aftermath
- British Library — official cyber-attack impact assessment and restoration reports (Rhysida, 2023–2024)
- CISA #StopRansomware — ransomware response and preparedness guidance (Ransomware Response Checklist)
- NIST IR 8374 — Cybersecurity Framework Profile for Ransomware Risk Management
- GDPR Article 33 — 72-hour supervisory-authority notification requirement
- US SEC — Form 8-K Item 1.05 material cybersecurity incident disclosure rule (2023)
- Coveware / Chainalysis quarterly ransomware reports — payment, negotiation, and leak-site ecosystem data
- Internal: One Key to Rule Them All — how initial-access credentials typically land
