Halian Systems | Empowering Business

Security | 6 min read

Ransomware Recovery: What to Do in the First 24 Hours

The average ransomware incident now costs businesses well into seven figures once downtime, recovery, and reputational damage are counted. Most of that cost is determined by what happens in the first 24 hours – not by the ransom itself.

Disconnect, don't power off

Isolate affected machines from the network immediately. Powering them off can destroy forensic evidence and encryption keys held in memory that a recovery specialist might otherwise use.

Assume the backup is the plan, not the ransom

Paying does not guarantee a working decryption key, and it funds the next attack. A tested, isolated backup is the actual recovery plan – which is why untested backups are not a plan at all.

Call your incident response contact before you touch anything else

Whether that’s an internal team, a managed provider, or a dedicated IR firm, get them on the call before attempting fixes yourself. Well-intentioned troubleshooting is one of the most common ways evidence gets destroyed.

The businesses that recover fastest are the ones who already knew who to call before the incident happened.

Document everything as you go

Timestamps, systems affected, ransom notes, and communications all matter later – for insurance, for law enforcement, and for the post-incident review that prevents a repeat.

Notification obligations don't wait for you to feel ready

Depending on your industry and what data was affected, you may have a legal clock running on breach notifications. Loop in legal counsel early, not after recovery is complete.

The bottom line

Recovery speed is decided by preparation, not improvisation. If you don’t have a written incident response plan yet, that’s the actual first step – before the 24 hours ever start.

Scroll to Top