Get in touch
Ransomware

Ransomware: what to do in the first 60 minutes

Published:

Short answer: isolate the affected devices from the network, do not pay and do not reply to the attackers before talking to someone who knows, keep evidence, and call for help. The goal of the first 60 minutes is not to solve the problem, but to keep it from growing and to avoid losing the evidence you will need.

The time splits below are our own practical suggestion to give you an order. The steps themselves are based on CISA's #StopRansomware guide.

How you recognise ransomware

  • Files that will not open or have an unknown extension.
  • A message (ransom note) on screen or in a text file inside folders.
  • Alerts from antivirus or EDR, or computers that suddenly lock up and slow down.
  • Users losing access to shared folders or applications.

The first 60 minutes

Suggested order of actions
WhenWhat you doWhy
Minutes 0 to 10Identify which devices are affected and disconnect them from the network and Wi-Fi.It stops the spread.
Minutes 10 to 20Appoint one person in charge. Coordinate by phone or another channel outside the network.The attackers may be reading email and chats.
Minutes 20 to 35Protect backups and accounts: disconnect the backup, change administrator passwords from a clean device, disable suspicious accounts.Attackers often look for and destroy backups.
Minutes 35 to 50Keep evidence: photograph the message, note times and devices, do not delete logs.They will be needed for the investigation, the insurer and the authorities.
Minutes 50 to 60Call for help: your security or IT provider, legal counsel, the insurer.The next decisions have legal and financial consequences.

If a step is not possible, move on to the next. The order matters less than leaving no affected device connected.

What NOT to do

  • Do not power devices off if you can disconnect them. CISA advises shutting them down only when you cannot disconnect them, because powering off loses evidence held in memory.
  • Do not delete, format or reinstall anything before evidence is collected.
  • Do not use the affected email or Teams to coordinate.
  • Do not reconnect a device "to see whether it is fixed".
  • Do not pay and do not contact the attackers without advice.

Should I pay?

CISA and law enforcement do not recommend paying. Paying does not guarantee you will recover your data or that the attackers will leave your systems, and it can carry legal consequences. Before any thought of it, check whether a free decryption tool exists for the variant that hit you, at the No More Ransom project run by Europol and its partners. The decision is not only technical: discuss it with a lawyer and with your insurer.

Whom to notify and when

Obligations and deadlines
WhoWhenNote
Competent authority (NIS2)Early warning within 24 hours, notification within 72 hours, final report within one monthIf your organisation falls under NIS2. The deadlines run from the moment you become aware of the incident.
Hellenic Data Protection AuthorityWithout undue delay and, where feasible, within 72 hoursIf personal data was breached with a likely risk to individuals (GDPR, Article 33).
Cybercrime DivisionAs soon as possiblePhone 11188 or an online complaint through gov.gr.
InsurerAs the policy requiresMany policies require prompt notice and prior approval for actions.

For a legal opinion consult a lawyer. The information here is general.

Will your backups save you?

If they are intact, offline or immutable, and have been tested, restoring is usually the best route. Do not connect them to a network that has not been cleaned, or they will be encrypted too. The most common surprise is that the backup exists but has never been tested.

Before it happens

  1. Backups with a tested restore and one copy kept offline.
  2. Multi-factor authentication (MFA) on all accounts, especially administrative ones.
  3. Device protection with EDR, which detects encryption early.
  4. A written response plan: who decides, whom you call, with phone numbers that do not depend on the network.
  5. Staff training on phishing, a common way in.

To see what an hour without systems would cost you, try the downtime cost calculator. If you are under attack right now, see the "I am under attack" page.

Frequently asked questions

Should I switch off the encrypted computer?

First try to disconnect it from the network and Wi-Fi. CISA advises powering off only if you cannot disconnect it, because evidence in memory is lost.

If I pay, will I get my data back?

There is no guarantee. CISA notes that paying does not ensure decryption or that systems will not be compromised again. Check first for a free tool at No More Ransom and consult a lawyer and your insurer.

Whom do I notify first?

First those who can help you contain the incident: your IT or security provider. Notifications to the authorities have deadlines (24 and 72 hours under NIS2, 72 hours under GDPR where it applies), so start the clock from the first moment.

Can you help me with an incident?

Yes. Write to us at [email protected] or call +30 694 877 9999 and describe what you see. We do not state a response time on the page, so do not wait for our reply before disconnecting the devices.