Ransomware has hit: what to do in the first 24 hours
The first hour determines how bad the next month is. What to do, in order.
Almost every business we assess has something they call a backup. The question is never whether one exists — it is whether it would survive the event you are backing up against.
It is decades old and it survives because each element addresses a different way of losing data: hardware failure, site loss, and deliberate destruction.
Modern ransomware does not just encrypt the machine it lands on. It looks for backup storage first, because the operators know that a business with working backups will not pay.
Anything mounted and writable from an infected machine is not a backup — it is additional data awaiting encryption. That includes a NAS with a persistent share, a USB drive left plugged in, and cloud storage with a synchronisation client.
The copy that saves you is one the attacker cannot reach: a rotated disk physically disconnected, tape, or object storage with immutability enabled so that even an administrator credential cannot delete it within the retention window.
This matters more than people expect. Ransomware often sits dormant for weeks before triggering. If your retention is seven days and the intrusion happened three weeks ago, every copy you hold may contain the payload.
A reasonable pattern for a small business: daily copies for two weeks, weekly for two months, monthly for a year. The storage cost is modest and the depth is what gives you options.
An untested backup is a belief, not a capability. Two things need testing, and they are different.
Restore test — can you actually get a file back? Do this monthly. It takes ten minutes.
Recovery test — can you bring a whole server back, and how long does it take? Do this annually, on isolated hardware. The purpose is partly to prove it works and partly to find out the real number, because the real number is usually longer than anyone assumed.
That number matters commercially. If restoring your main server takes eleven hours and the business can tolerate four, you have a gap to close — and you would rather learn that during a test than during an incident.
For a typical small office with a server or two:
None of this is expensive relative to what it protects. The hard part is not the technology — it is that someone has to own it and keep checking.
Ask us about cyber security services, or request a free assessment directly.
The first hour determines how bad the next month is. What to do, in order.
If you offer Wi-Fi to guests in Türkiye, this obligation applies to you.
The data is usually still there. The real loss happens during recovery attempts.