Cybersecurity

The first hour of a ransomware attack: what to do, in order

What to do in the first hour after discovering a ransomware attack: isolate, don't pay, and who to call first

The ransom note is on every screen in the office, and someone's already asking if IT can sort it before lunch. It can't, not from a standing start, and what happens in the next ten minutes matters more than almost anything else that happens over the following month.

This is the order to do things in: what to touch, what to leave alone, who to ring, and why. None of it guarantees you get your files back, and it won't stop this happening again on its own. It does stop a bad morning turning into a much worse month.

How you know it's actually ransomware

Usually it's not subtle. File names carry a new extension nobody recognises. A text file or HTML page appears in every folder, sometimes on the desktop too, explaining that your files are encrypted and giving a countdown and a payment address. Shared drives that worked five minutes ago won't open. Sometimes the whole screen locks and shows the note full-size. Sometimes it's quieter, and you only notice because three people in a row report the same folder won't open.

If that's what's in front of you, stop reading generic troubleshooting steps and start here.

Isolate the machine, don't just switch it off

Pull the network cable. If it's on wifi, turn the wifi off on that specific device, not just close the lid. The point is to stop the encryption spreading to shared drives and other machines on the same network, and to stop the attacker sending further instructions to that device while it's still connected.

Don't power it off if you can avoid it. This is the part most people get backwards. Shutting down feels responsible, and it does stop whatever's running, but it also wipes the contents of memory, and that's often where the evidence of how the attacker got in actually lives. NCSC's own incident guidance treats this as a genuine trade-off, not a simple rule: disconnecting preserves that evidence and stops the attacker issuing further commands, but it may not halt activity already underway; shutting down is quicker but can make it far harder afterwards to confirm the attacker's actually gone. Without your own forensics team, disconnect first, and leave any decision about power to whoever you call next.

If more than one machine is affected, or you genuinely don't know how far it's spread, the same logic scales up: taking the whole office off the internet at the router or switch buys time to work out what you're dealing with. It's a blunt tool and it stops everyone working, but a few hours offline beats a few days rebuilding from scratch.

Don't pay, and don't reply to the note yet

Leave the ransom note alone beyond photographing it. Don't email the address in it, don't visit the payment site "just to see how much," and don't decide alone whether to pay.

UK law enforcement's position, repeated in NCSC's own ransomware guidance, is blunt: they do not encourage, endorse or condone paying a ransom. Paying doesn't guarantee you get your data back, and it doesn't undo the fact the machine was compromised in the first place. You're still infected, you've just also sent money to whoever did it. Attackers who've been paid once are more likely to come back. Some ransomware doesn't decrypt anything at all even after payment, sometimes called wiper malware dressed up as ransomware, and there's no way to tell the difference from the note alone.

If you carry cyber insurance, this is usually where the policy actually starts to matter. Most require the insurer to be told before any payment decision, sometimes before you even engage a specialist, and acting outside that can affect what's covered. Check the policy, or call the insurer's helpline, before anyone considers a reply.

Don't wipe or reinstall until you know how big this is

The instinct to nuke the infected machine and rebuild it from a clean image straight away is understandable, and done too early, it's a mistake. You don't yet know which machines are affected, whether the backups you're about to restore from are themselves compromised, or whether the attacker copied data out before encrypting it. Wipe first and you might lose the only record of any of that.

Work out, roughly, what you're looking at before you fix anything:

  • Which machines and shared drives show signs of encryption, and which don't yet.
  • When your last backup ran, whether it's reachable from the infected network, and whether it looks intact.
  • Whether any system holding customer, patient or staff personal data is among the affected machines.

That's a triage exercise, not a full investigation, and with the right help it shouldn't take more than an hour. It's also exactly the point where most small businesses need someone who's done this before, because guessing wrong here is expensive.

Who to call, in order

WhoWhen and why
Your IT provider or internal IT leadFirst call, before anyone else. They can confirm what's actually happened, start containment properly, and tell you what the next calls need to cover.
NCSCReport via report.ncsc.gov.uk if the incident affects data on employees or customers, your hardware or software, or personal data generally. NCSC isn't a regulator and won't pass details on without your consent, but reporting gets you access to their guidance and, sometimes, direct support.
Action Fraud (now Report Fraud, reportfraud.police.uk)Call 0300 123 2040. For a business currently under a live cyber attack, that line runs 24 hours a day, seven days a week, not just office hours.
ICOOnly if personal data is at risk, and only where the breach is likely to result in a real risk to those people's rights and freedoms. If it clears that bar, you have 72 hours from becoming aware of it to notify them. If you don't have every detail yet, report what you know within the window and follow up.
Your cyber insurer, if you have a policyCheck what it actually requires before you do anything else expensive. Some policies set their own notification deadlines, and acting first can affect what's covered.
StaffBrief them without the gory detail: what's affected, what to avoid doing (don't try to "help" by restarting anything), and who to bring questions to.

What to preserve, and what not to touch

Photograph the ransom note before anyone closes it, deletes it, or restarts the machine it's on. Note the exact time you first noticed something was wrong, and what the first sign actually was. That timeline matters later, to your insurer, to the ICO if you end up reporting to them, and to whoever investigates.

Don't reformat or wipe any affected drive. Don't run a fresh backup job over the top of an infected share; if the backup destination gets overwritten while the source is still compromised, you can lose your last clean copy along with everything else. And don't let well-meaning colleagues start "trying things" on the affected machines, however confident they are with computers generally. Every action taken before someone's assessed the scope is one more thing to untangle afterwards.

Keep a running written log from the moment you find it: what was discovered and when, who's been told, what's been switched off and by whom, what's still running. It sounds like admin for its own sake in the middle of a crisis. It's the single thing that makes the next few days faster instead of slower.

A realistic first hour

TimeWhat happens
0–5 minutesDisconnect the affected machine(s) from the network. Photograph the ransom note. Don't power anything off yet.
5–15 minutesCall your IT provider or internal IT lead. Tell everyone nearby to stop working on anything that looks affected and to leave it switched on.
15–30 minutesRough triage: which machines and shares are affected, whether backups look reachable and intact, whether personal data is involved. Start the written log.
30–60 minutesReport to NCSC and Action Fraud if it's clearly a live cyber attack. Call your insurer if you have a policy. Hold off on any decision about paying, wiping or rebuilding until this point.

Where we come in

This is exactly the kind of morning our monitoring and response work exists for. The Complete plan (£108/user/month) on the pricing page includes SIEM and log retention, managed detection and response, and 24/7 support cover including out-of-hours, so an infection like this is more likely to be caught and contained before it reaches every shared drive in the building rather than after. Professional (£77/user/month) includes managed backup with tested restores and EDR, which is what turns "how intact is our backup" from a guess made under pressure into a quick answer.

None of that is a promise nothing will ever get through. No monitoring stops every attack, and we won't tell you otherwise. What it changes is how fast someone notices, and how much of the building is affected by the time they do. You can see how we handle this on our own systems on the security page. If part of how this started was a convincing email that looked like it came from inside your own company, it's also worth reading our guide to stopping people spoofing your business email, since that's a common way in.

If you run a dental or GP practice, the reporting obligations here sit alongside your DSPT requirements rather than replacing them, covered in our NHS DSPT guide.

The short version

Disconnect, don't switch off. Don't pay or reply yet. Don't wipe anything until you know how far it's spread. Call your IT provider first, then NCSC and Action Fraud, and the ICO within 72 hours if personal data's at risk and the breach clears the harm threshold. Write down what happened and when, from the first minute.

If you don't have anyone to make that first call to, get in touch and we'll talk you through it. And if you'd rather this list never had to matter, that's what the health check and the managed plans on the pricing page are actually for.

Frequently asked questions

Should I turn the infected computer off completely?+

Not immediately, if you can help it. Disconnect it from the network first: pull the ethernet cable, or turn off wifi on that specific device. That stops the ransomware reaching shared drives or other machines while leaving the contents of its memory intact, which is often where the evidence of how the attacker got in actually sits. Powering off is quicker and does stop whatever's running, but NCSC's own guidance treats this as a genuine trade-off rather than a simple rule, because a full shutdown can make it much harder afterwards to work out what happened and confirm the attacker's gone. If you're not sure, disconnect and wait for advice before you touch the power button.

Should we just pay to get our files back quickly?+

UK law enforcement's position, repeated in NCSC's own ransomware guidance, is that they don't encourage, endorse or condone paying. There's no guarantee paying gets your data back, the machine's still compromised either way, and you've sent money to whoever did it. Businesses that pay once are more likely to be targeted again. If you have cyber insurance, check the policy before anyone even considers replying to the note. Most require the insurer to be told first, and paying without that can affect what's covered.

Do we legally have to report this to anyone?+

It depends what's affected. If personal data belonging to customers, patients or staff is at risk, and the breach is likely to result in a real risk to those people's rights and freedoms, UK GDPR requires you to notify the ICO within 72 hours of becoming aware of it. Reporting to NCSC (via report.ncsc.gov.uk) and Action Fraud isn't a legal requirement in the same way, and NCSC is explicit that reporting to them doesn't fulfil any separate regulatory obligation you might have. It's not a substitute for the ICO report if one's needed.

What counts as 'affecting personal data' for the ICO deadline?+

Anything that stores details about identifiable people: customer records, staff HR files, patient records, even a spreadsheet of names and email addresses. If a system holding any of that shows signs of encryption, or you can't rule out the attacker having copied it before locking it, treat the 72-hour clock as running from the moment you realised. Not every breach has to be reported, only ones likely to cause real harm, but that judgement is easy to get wrong under pressure. Involve whoever handles your data protection compliance, or your IT provider, early rather than deciding alone.

Should we take the whole office offline, or just the infected machine?+

Start with whichever machines are actually showing signs of infection. If it's spread to more than one device, or you genuinely don't know how far it's got, disconnecting the router or switch for the whole site is a reasonable next step. It's disruptive and stops everyone working, but a few hours without internet costs less than the ransomware reaching every shared drive in the building. This is exactly the kind of call that's easier with someone experienced on the phone rather than guessing alone.

What if we don't have backups, or don't know if they're any good?+

Then your options narrow fast, and it's worth finding out before an attack rather than during one. Check when your last backup completed, and separately whether it's reachable from the same network the ransomware is on, because a backup sitting on a share the ransomware can also reach isn't much of a backup. If none of that's been tested recently, say so honestly to whoever you call in rather than assuming it'll be fine. It changes what's actually recoverable, and how.

Can Alpha IT help if this happens to us?+

Yes, whether we already look after your systems or not. Get in touch and we'll talk you through what to do first. We can't promise this never happens to a business we look after; nobody honestly can. What our Professional and Complete plans change is how fast it's noticed and how much of the network is affected by the time someone acts, through managed backup with tested restores and EDR, and on Complete, 24/7 monitoring and managed detection and response.

Call usFree consultation