The anatomy of a ransomware incident: How to contain threats within the first hour

The anatomy of a ransomware incident: How to contain threats within the first hour

A ransomware attack can spread through your network with alarming speed and can lock away vital data and disrupt key systems before anyone can react. This speed means that the first hour after you discover an incident is critical. Your decisions during this period can determine how far the ransomware spreads, how much of your systems are affected, and how much time and money you spend recovering your business.

Anatomy of a ransomware attack

Ransomware attacks vary in methodology depending on how and why they are created, but they all typically follow several stages. 

An attacker first gains access, often through phishing, stolen credentials, an unpatched vulnerability, or a compromised remote-access service. Once inside, if they continue undetected, they can escalate their privileges to gain access to more data.

Next, attackers commonly move laterally through the network, searching for valuable systems and data. Older ransomware attacks only locked files, but newer varieties also allow criminals to exfiltrate sensitive information before encrypting files. Once they’ve spread the ransomware across as many systems as possible, they demand payment.

Sometimes the criminals keep their word after a ransom has been paid, but often they simply vanish after receiving the ransom, leaving your files locked and systems offline.

Why the first hour after a ransomware incident is the most important

The longer ransomware operates unchecked, the greater the damage to your business. The attackers will race to compromise additional accounts, disable security controls, encrypt more files, or access connected systems, so you have to beat them to the punch.

After a ransomware attack is active for 60 minutes, it may be too late to contain it and save your data.

How to contain a ransomware threat within the first hour

The following ransomware response checklist gives you a practical starting point. Your exact response plan should be created with input from your IT or cybersecurity provider to tailor it to your needs.

Step 1: Activate your response plan

As soon as you have credible evidence of ransomware, treat it as a serious security incident. Immediately notify the appropriate decision-makers and contact your IT team or managed services provider (MSP).

DO NOT allow employees to independently troubleshoot infected computers. Uncoordinated actions can destroy evidence or inadvertently help ransomware spread.

Step 2: Isolate affected devices

Disconnect suspected infected computers from your network to prevent ransomware from communicating with other systems. If necessary, disconnect network cables or disable Wi-Fi.

You likely do not have to shut down every computer in your organization. Your IT provider should determine which systems need to be isolated and which should remain available for investigation or business continuity.

Step 3: Disable compromised accounts and access

If you suspect stolen credentials, disable affected user accounts and terminate active sessions. Your IT provider should prioritize reviewing privileged accounts because attackers frequently target administrative credentials.

Step 4: Scan and activate your backups

Immediately verify that data backup systems are isolated and protected from the compromised environment. Do not assume they are safe; ransomware operators prioritize eliminating recovery options so that you have no choice but to pay a ransom.

Avoid connecting backup repositories to infected systems until your IT team determines that doing so is safe.

Step 5: Preserve evidence and documentation

Proper evidence collection and documentation will help with the recovery process and may be needed to satisfy compliance requirements and avoid fines. 

Preserve:

  • Activity logs
  • Malware samples
  • Lists of which systems appear affected
  • A record of what actions have already been taken

DO NOT delete suspicious files or wipe infected devices unless your incident response team instructs you to do so.

Step 6: Inform relevant stakeholders and authorities

Depending on how many systems were affected, what data was compromised, and if customers/third parties were affected, you may need to inform several outside organizations of the attack. 

These may include, if applicable: 

  • Your cyber insurance carrier
  • Legal counsel
  • Data security regulators
  • Law enforcement
  • Data recovery specialists

If you have cyber insurance, follow its requirements carefully. Your policy may specify which vendors or response procedures you must use.

To minimize the risk of ransomware and the damage it can cause, partner with an experienced cybersecurity services provider like XBASE. For a customized ransomware response plan tailored to your organization, contact XBASE for a consultation today.