Commteck
Guide

What to do in the first hour of a ransomware attack

5 min read · last reviewed 2026-10-06

Ransomware is a business interruption that arrives as a pop-up. The first hour decides how much of it you keep: most of the damage is done by the attack spreading to the next machine, and by well-meaning attempts to fix things that destroy the evidence you would need later.

Stop the spread before you investigate

If a screen or a file share is encrypted and you have not seen anything like it before, treat it as ransomware and cut the paths between machines. Unplug the network cable from the affected computer and turn the Wi-Fi off — the machine keeps running, but it stops being able to encrypt the workstation next to it. If several machines are affected, the honest answer is to power down the whole network (the router and the switches) and use phones and paper until someone qualified is on the line.

Do not reboot, and do not pay

A reboot can destroy the memory-only evidence that shows how the attacker got in, so leave affected machines powered on and disconnected. Do not delete anything, and do not run a cleaner or a decryptor you found online.

Paying is not a recovery plan: payment funds the next attack, it may be a crime depending on who you are dealing with, and a reported share of payers never receive working keys. The organisations that recover well are the ones with a usable backup — which is why the guide worth reading before this happens is the one on backup.

Call the people who have to be called

In order, and all in the first hour: your IT provider or your own technical lead; your insurer's cyber line (most policies have a 24-hour number and a breach coach); your practice-management or EHR vendor, because their hosted side may be untouched; and your leadership. If patient information may be involved, your counsel and your privacy officer need to know the same day — regulated notification clocks start when you become aware, not when the investigation ends.

Recover from a copy you have tested, then close the way in

Restore the most important system first and check the data before you move on — the goal is a working front desk, not a perfect estate. Rebuild rather than trust a machine that was encrypted: modern attacks leave persistence behind, and a machine that was cleaned is still a machine the attacker has been on.

Then fix the way in: the cause is usually a credential — a phished password with no second factor, or remote access that was open to the internet. MFA on email and remote access, patching, and backup that is offline or immutable are what make the second attempt boring instead of fatal.

This is general guidance for practices in Utah — it is not legal, medical, compliance or tax advice, and it is not a substitute for advice on your own systems and obligations. Reviewed 2026-10-06; tell us if something in it has changed.