Skip to main content

Ransomware Hit Your Files: What to Do in the First Hour

Media Ransomware Hit Your Files What to Do in the First Hourat 12_01_17 AM

You open a document and Windows says it cannot read the file. Other files suddenly have unfamiliar extensions, folders contain ransom notes, and shared drives begin filling with renamed or encrypted data.

You may see messages such as:

  • “Your files have been encrypted.”
  • “Contact us to recover your data.”
  • “Do not rename or modify encrypted files.”
  • “Pay within 72 hours or your data will be published.”

This is no longer an ordinary computer fault.

Ransomware can encrypt local files, connected storage and accessible network shares. Modern attacks may also involve stolen information, disabled backups, compromised administrator accounts and threats to publish sensitive data. 

What happens in the first hour can determine whether the incident remains limited to one computer or spreads through the organisation.

The immediate priorities are:

  1. Stop the spread.
  2. Protect unaffected systems and backups.
  3. Contact the right people.
  4. Preserve evidence.
  5. Establish the scope before attempting recovery.

Do not begin randomly deleting files, reinstalling Windows or connecting backup drives. Containment must come before cleanup.

First: Confirm the Warning Signs

Ransomware may reveal itself through:

  • Files that no longer open
  • New extensions added to filenames
  • Ransom notes in multiple folders
  • Desktop wallpaper replaced with payment instructions
  • Sudden loss of access to shared drives
  • Large numbers of files changing simultaneously
  • Antivirus or backup services unexpectedly stopping
  • Unfamiliar administrator accounts
  • High disk and network activity
  • Other employees reporting the same symptoms
  • A threat to publish stolen company information

Do not assume that encryption is limited to the computer where you first noticed it. The infected machine may be one victim among several, or it may be the device spreading the attack to shared systems.

Minute 0–5: Isolate the Affected Device

The first objective is to prevent the computer from communicating with other systems.

Disconnect:

  • The Ethernet cable
  • Wi-Fi
  • Mobile tethering
  • VPN connections
  • Docking-station network connections
  • Direct links to other computers

Do not browse the network looking for other machines from the affected PC.

CISA recommends immediately identifying and isolating impacted systems. Microsoft’s ransomware-response guidance similarly advises isolating compromised devices from the network to restrict further spread. 

Disconnect external storage

Remove external devices that ransomware could continue encrypting, including:

  • USB drives
  • External SSDs and hard drives
  • Memory cards
  • Locally attached backup drives

Do not reconnect those devices to another production computer until an experienced technician has assessed them.

Should you turn the computer off?

For a business incident, the preferred action is normally:

Isolate the device from the network but leave it powered on.

Keeping it running may preserve volatile evidence such as active processes, network connections, encryption activity and malware held in memory. Microsoft explicitly advises isolating affected devices without shutting them down during ransomware investigation. 

However, power the device off when:

  • You cannot disconnect it from the network.
  • Files are continuing to be encrypted.
  • The computer is actively damaging attached storage.
  • No qualified responder is immediately available.
  • The attacker remains connected and network isolation is impossible.

CISA states that powering down may be necessary when an affected system cannot otherwise be disconnected, although this loses some evidence held in memory. 

Do not keep a machine online solely to preserve evidence while it continues destroying business data.

Minute 5–10: Alert Your IT and Security Team

Do not try to handle a company ransomware incident alone.

Contact:

  • Your internal IT team
  • Your managed IT provider
  • Your cyber-security provider
  • Senior management
  • The organisation’s data-protection lead
  • Your cyber-insurance incident line, where applicable

Use a trusted phone or unaffected device. Do not rely solely on company email or Teams if those accounts or systems may also be compromised.

Provide:

  • The affected computer’s name
  • The user who was signed in
  • The first time the problem was noticed
  • The ransom-note filename
  • Any new file extension
  • Whether shared drives are affected
  • Whether other users have reported problems
  • Whether the computer has been isolated
  • Whether backup systems appear accessible

A coordinated incident response is essential because technical, operational, legal, insurance and communications decisions may all need to begin simultaneously. The NCSC recommends planning clear decision-making, escalation and specialist support for disruptive cyber incidents. 

Minute 10–15: Warn Other Users Without Spreading Panic

Notify employees through a trusted channel.

A clear internal alert might say:

“We are investigating a suspected ransomware incident. Do not open unexpected attachments, connect external drives or access affected shared folders. Leave computers switched on unless IT instructs otherwise. Report unusual filenames, ransom notes or login prompts immediately.”

Tell users not to:

  • Restart affected computers
  • Delete ransom notes
  • Connect backup drives
  • Try online decryptors
  • Forward suspicious files to colleagues
  • Pay the ransom
  • Contact the attacker
  • Continue working in affected network folders

Users should report symptoms, but they should not perform their own technical investigation.

The message should be factual and controlled. The NCSC recommends managing communications deliberately during cyber incidents to reduce confusion, conflicting instructions and avoidable reputational damage. 

Minute 15–25: Establish the Initial Scope

Your IT team should begin determining what is affected.

Check from trusted management systems—not by browsing from the encrypted machine.

Questions include:

  • Is only one endpoint affected?
  • Are multiple employees reporting encrypted files?
  • Are file servers accessible?
  • Are Microsoft 365, SharePoint or OneDrive affected?
  • Are backups still running?
  • Are virtual machines being encrypted?
  • Are domain controllers or identity systems affected?
  • Is suspicious encryption activity still occurring?
  • Are remote-access or administrator accounts active?
  • Has data been copied out of the organisation?

Isolate other affected systems

When another computer shows the same signs, isolate it immediately.

Where Microsoft Defender for Endpoint or another EDR platform is deployed, security teams may be able to remotely isolate devices while maintaining limited communication with the security service. Device isolation is specifically intended to help prevent attacker control, data theft and lateral movement. 

Consider broader network containment

A serious incident may require temporarily restricting:

  • VPN access
  • Remote Desktop
  • Internet-facing services
  • Administrative accounts
  • File-sharing protocols
  • Connections between network segments
  • Compromised cloud identities

These decisions should be made by someone who understands the network. Switching off the wrong infrastructure can disrupt evidence collection, recovery tools, telephones, access-control systems or critical operations.

Protect the Backups Immediately

Backups are among the attacker’s most valuable targets.

Do not assume they are safe because the backup software still opens.

Ransomware operators may:

  • Delete backup snapshots
  • Encrypt backup repositories
  • Compromise backup administrator accounts
  • Disable backup services
  • Modify retention policies
  • Wait until infected files have replicated into backups

Restrict access to backup systems and prevent affected machines from reaching them.

Do not start restoring files during the first hour unless a qualified responder has confirmed that:

  • The attacker no longer has access.
  • The ransomware is contained.
  • The backup is clean.
  • The recovery environment is trusted.

The NCSC advises connecting backups only to known-clean devices and scanning backup data before restoration because ransomware may have been present before the incident was discovered. 

A clean backup restored into an infected network may simply be encrypted again.

Minute 25–35: Preserve Evidence

Do not remove the evidence that may explain how the attack started or what the criminal accessed.

Preserve:

  • The ransom note
  • Screenshots
  • New file extensions
  • Suspicious emails
  • Attachments
  • Website addresses
  • Telephone numbers
  • Cryptocurrency wallet addresses
  • Attacker email addresses
  • Chat portal information
  • Security alerts
  • Firewall and VPN logs
  • Endpoint-protection alerts
  • Cloud sign-in logs
  • Backup logs
  • User reports
  • The initial timeline

Record the exact time of every containment action.

For example:

23:14 — User reported files would not open

23:17 — Ransom note confirmed

23:19 — Ethernet disconnected

23:21 — IT provider contacted

23:28 — Second device isolated

23:34 — VPN access suspended

Do not edit the ransom note or rename encrypted files.

Do not run a succession of unapproved cleanup tools. Scans, deletions and restarts can alter timestamps, remove malware samples and destroy evidence needed to establish the initial access route.

CISA response guidance includes preserving system images, memory captures and relevant logs where possible so investigators can understand the attack and support legal or insurance requirements. 

Minute 35–45: Secure Identities and Administrator Access

Ransomware is often the final visible stage of a longer intrusion.

The attacker may already possess:

  • Administrator credentials
  • VPN credentials
  • Microsoft 365 sessions
  • Backup administrator access
  • Service-account passwords
  • Remote-management access
  • Cloud application tokens

The security team may need to:

  • Disable confirmed compromised accounts
  • Reset privileged credentials
  • Revoke active cloud sessions
  • Remove unfamiliar MFA methods
  • Disable suspicious application registrations
  • Rotate service-account secrets
  • Review administrator-group membership
  • Block attacker-controlled IP addresses

Do not require every employee to change passwords immediately from potentially infected computers.

Credential changes should be coordinated from trusted systems. Otherwise, the replacement passwords may be captured by malware or the attacker may be warned before containment is ready.

Minute 45–60: Begin Formal Incident Management

By the end of the first hour, the organisation should have an incident lead and an initial plan.

The plan should cover:

  • Technical containment
  • Operational continuity
  • Backup protection
  • Evidence preservation
  • Identity security
  • Legal and regulatory assessment
  • Insurance notification
  • Police and government reporting
  • Staff communication
  • Customer and supplier communication
  • Recovery priorities

The team should establish a safe channel for incident communications. Do not discuss sensitive recovery details through accounts the attacker may still be monitoring.

Report a Live Ransomware Attack

UK businesses, charities and other organisations experiencing a live cyberattack can call Report Fraud on 0300 123 2040 immediately. The dedicated live-incident service operates 24 hours a day, seven days a week. 

Incidents can also be reported to the NCSC through its cyber-incident reporting service. The NCSC may become directly involved in incidents of national significance and can help coordinate engagement with other parts of government. 

In Scotland, fraud and cybercrime should be reported to Police Scotland by calling 101, unless there is an immediate emergency. 

Reporting can provide:

  • Law-enforcement intelligence
  • Advice on the next steps
  • Links to related attacks
  • Evidence supporting disruption of the criminal group
  • Additional regulatory context

Do not wait for a complete forensic report before reporting an attack that is actively affecting the organisation.

Start the Data-Breach Assessment

Ransomware can create a personal data breach even when the main visible symptom is unavailable files.

UK GDPR considers the confidentiality, integrity and availability of personal data. Encryption may therefore constitute a personal data breach because authorised users can no longer access the information—even if there is not yet evidence that it was stolen. 

Begin recording:

  • What personal information is affected
  • How many people may be involved
  • Whether information was stolen
  • Whether the data was encrypted before the attack
  • Whether clean backups exist
  • How long systems may be unavailable
  • Possible harm to employees, customers or others

Where a breach is likely to create a risk to individuals, it must be reported to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. The clock begins when the organisation becomes aware of the breach, not when the attacker initially entered the network. 

Start the incident log even when you have not yet decided whether the reporting threshold has been met.

Do Not Pay During the First Hour

Do not telephone the attacker or begin cryptocurrency arrangements while the incident is still being contained.

Paying does not guarantee that:

  • A working decryption key will be provided.
  • Every file will be restored.
  • Stolen information will be deleted.
  • The attacker has left the network.
  • The organisation will not be attacked again.

The UK government strongly advises against paying ransoms, and the NCSC does not encourage, endorse or condone payment. 

Payment can also involve legal and sanctions risks. Making funds available to a sanctioned person or entity can expose those involved to civil or criminal penalties. UK organisations considering any payment need specialist legal, law-enforcement, insurance and financial-sanctions advice first. 

A ransom payment does not replace breach reporting, forensic investigation, rebuilding affected systems or correcting the original security failure. The ICO does not regard payment as reducing regulatory obligations or automatically mitigating the risk. 

Do Not Trust a Free Decryptor Without Verification

Some ransomware families have legitimate decryptors because:

  • Their encryption was flawed.
  • Law enforcement obtained the keys.
  • Security researchers recovered the infrastructure.
  • The criminal group released keys.

However, fake decryptors can contain further malware.

Do not upload sensitive business files, ransom notes or encrypted samples to an unknown website.

A qualified responder should identify:

  • The ransomware family
  • The file extension
  • The ransom-note characteristics
  • Available legitimate decryption options
  • Whether testing can be performed safely on copies

Never test a decryptor on the only copy of important encrypted data.

Do Not Rebuild the First Machine Too Quickly

Reinstalling Windows immediately may make one computer appear usable, but it can destroy evidence and do nothing about:

  • Stolen credentials
  • Other compromised systems
  • Malicious cloud sessions
  • Vulnerable remote-access services
  • Backdoors
  • Data theft
  • Compromised backups

The incident must be contained before recovery begins.

For business incidents, the affected machine may need:

  • Memory capture
  • Disk imaging
  • Malware collection
  • Log collection
  • Timeline analysis
  • Examination by the cyber-insurance or incident-response provider

Once evidence is preserved, the safest recovery is often to wipe and rebuild compromised systems from a trusted source rather than attempting to clean them in place.

What Home Users Should Do

When ransomware affects one personal computer:

  1. Disconnect Wi-Fi and Ethernet.
  2. Remove attached storage.
  3. Do not pay or contact the attacker.
  4. Photograph the ransom note.
  5. Use another trusted device to change important passwords.
  6. Report financial theft immediately to the bank.
  7. Report the crime through Report Fraud.
  8. Arrange professional malware and data-recovery assessment.
  9. Preserve the original encrypted drive where the files are important.
  10. Restore only from a known-clean backup after the computer has been securely rebuilt.

Do not experiment with the only copy of family photographs, financial records or business documents.

Where the computer contains particularly valuable or irreplaceable data, consider removing it from service rather than repeatedly restarting, scanning and modifying it.

What Businesses Should Not Do

Do not reconnect the infected computer

A device may resume encryption or reconnect to the attacker.

Do not connect the backup drive to “check it”

You may expose the final clean backup to the ransomware.

Do not delete encrypted files

They may be recoverable later through a legitimate decryptor or restoration process.

Do not rename encrypted files

Changing the extension does not decrypt them and can complicate automated recovery.

Do not contact the attacker casually

Communication may reveal internal information, weaken negotiations, alert the criminals to containment activity or create legal complications.

Do not hide the incident

Delays can increase financial, operational, contractual and regulatory damage.

Do not wipe every device immediately

The organisation may lose evidence required to find the point of entry and confirm that the attacker has been removed.

Do not assume encryption is the whole incident

Modern ransomware frequently includes data theft and extortion as well as encryption. 

A First-Hour Ransomware Checklist

When ransomware is discovered:

  1. Stop using the affected device.
  2. Disconnect Ethernet, Wi-Fi, VPN and docking network links.
  3. Remove attached storage.
  4. Leave the device powered on when it can be safely isolated.
  5. Power it off only when continued damage cannot otherwise be stopped.
  6. Contact IT and the cyber-security provider.
  7. Inform senior management and the data-protection lead.
  8. Contact the cyber-insurance incident line.
  9. Warn users through a trusted channel.
  10. Isolate every other affected device.
  11. Protect backup platforms and administrator accounts.
  12. Check whether file servers and cloud systems are affected.
  13. Preserve ransom notes, screenshots and logs.
  14. Start a precise timeline.
  15. Revoke confirmed compromised accounts and sessions.
  16. Establish a safe incident communication channel.
  17. Contact Report Fraud for a live organisational attack.
  18. Consider reporting to the NCSC.
  19. Start the UK GDPR breach assessment.
  20. Do not restore, pay or wipe systems until specialist advice is available.

How Hamilton Group Can Help

Ransomware is one of the most time-sensitive incidents a business can face.

Hamilton Group’s experienced IT and cyber-security team can help contain the attack, protect unaffected systems and begin a controlled recovery.

Immediate Containment

We can help:

  • Isolate infected devices
  • Restrict malicious network activity
  • Protect servers and cloud systems
  • Suspend compromised accounts
  • Preserve backups
  • Stop further lateral movement

Incident Investigation

Hamilton Group can review:

  • Endpoint-security alerts
  • Windows and server logs
  • Microsoft 365 sign-ins
  • Remote-access systems
  • Firewall and VPN activity
  • Administrator accounts
  • Ransom notes and encrypted-file patterns
  • Possible data theft

Backup and Recovery Assessment

We can establish:

  • Which backups remain clean
  • Whether backup accounts were compromised
  • The safest restore point
  • Which systems must be rebuilt
  • The correct recovery order
  • How to prevent restored systems being encrypted again

Microsoft 365 and Identity Security

Our team can:

  • Revoke suspicious sessions
  • Reset privileged accounts
  • Review MFA changes
  • Inspect mailbox rules
  • Investigate SharePoint and OneDrive activity
  • Remove unauthorised application access
  • Strengthen Conditional Access

Regulatory and Incident Support

We can help your organisation document:

  • When the incident was discovered
  • Which systems and data were affected
  • What containment actions were taken
  • Whether personal information may be at risk
  • Which specialist, insurer and regulatory contacts are required

Hamilton Group aims to make first contact on IT support requests within 15 minutes, helping businesses act before ransomware spreads further through their systems.

Contain First, Recover Second

The first hour is not the time to negotiate, restore files or experiment with cleanup tools.

It is the time to:

Isolate the affected systems, protect the backups, secure the accounts, preserve the evidence and bring in experienced help.

A controlled response may mean the difference between rebuilding one laptop and recovering an entire organisation.

For urgent help following ransomware or another live cyber incident, call Hamilton Group on 0330 043 0069, book a meeting with one of our experts or visit hgmssp.com.