All insights

What should you do in the first hour of a ransomware attack?

2 min readBy Brendon Whiting, Founder · 23 July 2026

In the first hour of a ransomware attack: disconnect affected machines from the network but do not power them off, stop using every connected system, ring your IT provider's emergency line, and write down what you saw and when. Do not pay, negotiate or delete anything before help arrives. The first hour decides how the next month goes.

Each step has a reason. Disconnecting, pull the network cable, kill the Wi-Fi, stops the encryption spreading to shared drives and other machines; powering off feels safer but destroys evidence in memory that responders may need, so isolate rather than shut down. Stop using connected systems, including email, because whoever deployed the ransomware may have been reading the mailbox for weeks; coordinate by phone instead. And the notes matter more than they feel like they do: when it was noticed, which machines, the exact wording of the ransom note, what anyone clicked. Responders rebuild the timeline from exactly this.

Then the calls, in order. Your IT provider or security operator first, ours runs 24/7, because containment is measured in minutes: isolating machines, disabling compromised accounts, establishing what the backups look like. Then, with advice rather than in panic: your insurer, since policies require early notice; ReportCyber for the ACSC; and, if personal information is involved, the Privacy Act's data breach assessment. What you should not do in hour one is open negotiations, pay anything, or let a well-meaning staff member start deleting and reinstalling, every one of those closes doors you may badly want open.

The honest truth is that the first hour is mostly decided before it starts. Whether this is a rough week or an existential event turns on one earlier fact: offline backups that someone has actually test-restored. That is what strips ransomware of its power over you, and it is why recovery is a real outcome, not a slogan; Karidis Corporation came out of a malware incident rebuilt to one hundred per cent Essential Eight coverage. If you are reading this calmly, spend the hour you have: ask when your backups were last test-restored, and put an emergency number where reception can find it. Ours is 1800 456 567.

Do the one thing that defuses ransomware.

Ask when your backups were last test-restored. If nobody can answer, that is the gap worth closing this week, and we will help you close it.

Frequently asked questions

Not as a reflex, and not alone. Payment guarantees nothing, decryption often fails or is partial, it marks the business as a payer, and payments can carry legal and sanctions complications. It is a decision to make with incident responders, your insurer and legal advice, never from adrenaline. Tested offline backups remove most of the attacker's bargaining power before the question arises.

Report it to the ACSC through ReportCyber, and check your obligations beyond that: if personal information was likely accessed and serious harm is possible, the Privacy Act's Notifiable Data Breaches scheme requires assessment and may require notifying the OAIC and affected people. Insurers also require prompt notice, and late notice is a common reason claims get complicated.

Unglamorously: a phished or reused password, an unpatched system exposed to the internet, or a malicious attachment someone was busy enough to open. That is the useful news, because multi-factor authentication, prompt patching and application control blunt all three routes, which is why the Essential Eight is the prevention plan and not just compliance.

Questions? Let's talk.

Call 1800 456 567 or fill out the form.

  • 30-minute discovery — no jargon, no pressure
  • Plain-English Essential Eight Cyber Security Scorecard
  • A clear plan tailored to your business

Prefer to talk?

Call 1800 456 567

Powered by Calendly — your data is handled securely.

Our office · Level 2, 25 Grenfell Street, Adelaide

By submitting, you agree to our terms and privacy policy. No spam — ever.