Security

Ransomware: How It Spreads, and What to Do in the First Hour

Ransomware attacks rarely feel sudden from the attacker's side — by the time files start getting encrypted, they've often already been inside the network for days or weeks. But from your side, it feels sudden: one moment things are normal, the next, files are locked and a ransom note is on the screen. What happens in the first hour after that discovery matters enormously.

7 min read

Compliance as a Byproduct of Good Operations

How Ransomware Actually Spreads

  • Phishing emails remain the most common starting point — a malicious attachment or link that gives an attacker an initial foothold on one device.

  • Compromised credentials — often obtained through a previous phishing attempt or a data breach — let attackers log in through legitimate-looking channels like remote access tools.

  • Unpatched software vulnerabilities give attackers a way in without needing anyone to click anything at all.

  • Lateral movement. Once inside, attackers typically don't encrypt anything right away. They quietly move across the network, seeking higher-level access and identifying valuable systems and backups — sometimes for days or weeks — before triggering the actual encryption.

  • Backup targeting. Increasingly, ransomware attacks specifically try to find and disable backups before encrypting live systems, precisely because backups are the easiest way to recover without paying.

Understanding this timeline matters: the moment encryption is discovered is usually not the moment the attack started. That's part of why prevention (patching, monitoring, access controls) matters as much as response.

The First Hour: What to Do

1. Disconnect, don't shut down. Isolate affected devices from the network immediately — unplug the network cable, disable Wi-Fi — but avoid powering the device off. Shutting down can complicate forensic investigation and, in some cases, trigger further damage depending on the ransomware variant.

2. Notify your IT team or provider immediately. Don't wait to "confirm it's serious" — time matters more than certainty in the first hour. The faster isolation happens, the more likely it is to contain the spread to a smaller number of systems.

3. Preserve evidence. Take a photo of the ransom note with a phone rather than a screenshot from the infected device, and don't attempt to delete or interact with the ransom note or affected files. This information matters for investigation and, if applicable, law enforcement reporting.

4. Don't pay, and don't negotiate, on your own. Even if a ransom note includes a countdown or threat, decisions about ransom payment should never be made unilaterally or under pressure in the first hour — this is a legal, financial, and strategic decision that needs proper guidance, not a rushed one.

5. Identify what's actually been affected. Work with IT to determine which systems and files were touched, and just as importantly, which weren't — this shapes the entire recovery plan.

6. Begin recovery from clean backups, if available. This is the moment tested, verified backups pay for themselves. Recovery should happen from backups predating the infection, after affected systems have been fully cleaned — restoring onto a still-compromised system risks reinfection.

Why the First Hour Sets the Tone

Businesses that respond quickly and methodically in the first hour typically limit ransomware to a handful of systems. Businesses that hesitate, or aren't sure who to call, often see the infection spread further simply because more time passed before isolation happened. Having a plan — and knowing who to call — before an incident happens is what makes fast action possible in the moment.

What This Means for You

Part of what a managed IT relationship provides is exactly this: a clear, fast path to isolation and recovery when something happens, backed by monitoring that's often catching early warning signs before full encryption ever occurs. If you're not sure your team knows the first steps to take or who to call in a ransomware scenario, that's worth fixing before it's needed, not after.

Ask your service provider whether a formal incident response plan is in place for your organization, and if not, about setting one up. It's a short conversation now that could save a very long, very expensive day later.

Want this reviewed against your own environment?

Want this reviewed against your own environment?