What should you do in the first hour of a ransomware attack?
In the first hour of a ransomware attack: disconnect affected machines from the network but do not power them off, stop using every connected system, ring your IT provider's emergency line, and write down what you saw and when. Do not pay, negotiate or delete anything before help arrives. The first hour decides how the next month goes.
Each step has a reason. Disconnecting, pull the network cable, kill the Wi-Fi, stops the encryption spreading to shared drives and other machines; powering off feels safer but destroys evidence in memory that responders may need, so isolate rather than shut down. Stop using connected systems, including email, because whoever deployed the ransomware may have been reading the mailbox for weeks; coordinate by phone instead. And the notes matter more than they feel like they do: when it was noticed, which machines, the exact wording of the ransom note, what anyone clicked. Responders rebuild the timeline from exactly this.
Then the calls, in order. Your IT provider or security operator first, ours runs 24/7, because containment is measured in minutes: isolating machines, disabling compromised accounts, establishing what the backups look like. Then, with advice rather than in panic: your insurer, since policies require early notice; ReportCyber for the ACSC; and, if personal information is involved, the Privacy Act's data breach assessment. What you should not do in hour one is open negotiations, pay anything, or let a well-meaning staff member start deleting and reinstalling, every one of those closes doors you may badly want open.
The honest truth is that the first hour is mostly decided before it starts. Whether this is a rough week or an existential event turns on one earlier fact: offline backups that someone has actually test-restored. That is what strips ransomware of its power over you, and it is why recovery is a real outcome, not a slogan; Karidis Corporation came out of a malware incident rebuilt to one hundred per cent Essential Eight coverage. If you are reading this calmly, spend the hour you have: ask when your backups were last test-restored, and put an emergency number where reception can find it. Ours is 1800 456 567.
Do the one thing that defuses ransomware.
Ask when your backups were last test-restored. If nobody can answer, that is the gap worth closing this week, and we will help you close it.
Frequently asked questions
Questions? Let's talk.
Call 1800 456 567 or fill out the form.
- 30-minute discovery — no jargon, no pressure
- Plain-English Essential Eight Cyber Security Scorecard
- A clear plan tailored to your business