Ransomware has hit: what to do in the first 24 hours
The first hour determines how bad the next month is. What to do, in order.
When a drive fails the instinct is always the same: try again. Power cycle it, swap the cable, plug it into another machine, download a recovery tool. Each of those steps can destroy recoverable data permanently.
A deleted file does not leave the disk immediately. The file system marks that area as free, but the data stays there until something is written over it.
The problem: the operating system keeps writing to the disk even when you do nothing. Temporary files, logs, updates. The longer the device stays powered on, the higher the chance of overwriting.
With mechanical failure it is worse. Running a drive that is making noise can physically scratch the platter surface. Past that point nothing can be done.
RAID: when one disk drops the array keeps running. Panicking, inserting a spare and starting a rebuild is the common mistake. If a second disk is weak it will fail during the rebuild and the array is gone. Assess before acting.
Virtual machines: before trying to repair a machine that will not start, take a copy of the disk file. Interfering with a snapshot chain can break it permanently.
Ransomware: disconnect from the network first. If encryption is still running, it is running while you read this.
When recovery is finished the real question is: why did this not come back from a backup?
Data recovery is expensive and its outcome uncertain. Backup is cheap and certain. Reviewing the backup design so it does not happen twice costs far less than the recovery invoice.
Ask us about data recovery service, or request a free assessment directly.
The first hour determines how bad the next month is. What to do, in order.
Most businesses have backups. Far fewer have a backup that survives ransomware — and that is a different thing.
If you offer Wi-Fi to guests in Türkiye, this obligation applies to you.