Home  /  Blog  /  Security

Ransomware has hit: what to do in the first 24 hours

The first hour determines how bad the next month is. What to do, in order.

This article assumes it has already happened. If you are reading it as preparation, the short version is: an offline backup copy is the thing that decides your outcome, and everything below is easier if you have one.

First: contain, do not investigate

The instinct is to work out what happened. Resist it for twenty minutes and stop the spread first.

  • Disconnect affected machines from the network. Pull the cable or disable the switch port. Do not rely on the machine's own software.
  • Isolate the servers. If file servers are still reachable from infected workstations, encryption is still progressing while you read this.
  • Disconnect backup storage. If a backup drive or NAS is mounted and writable, it is being encrypted too. This is the single most consequential action in the first hour.
  • Do not power off encrypted machines yet. Memory may hold information useful for identifying the variant. Disconnect from the network instead.

Second: establish scope

Before deciding anything, find out how far it reached.

  • Which machines are encrypted, and which are merely unreachable?
  • Are the servers affected, or only workstations?
  • Which file shares, and how far back does the damage go?
  • Is cloud storage affected? Synchronisation clients cheerfully replicate encrypted files upward.
  • Which accounts were used? A compromised domain administrator account changes the entire response.

Write this down as you go. You will need it repeatedly and memory will not serve.

Third: verify the backups before trusting them

Do not assume they are clean. Check three things:

  • Is the backup itself encrypted? Anything that was mounted and writable when the attack ran is suspect.
  • How old is the last known-good copy? This defines your data loss, and it is usually the number that hurts most.
  • Does a test restore actually work? Restore something small to an isolated machine first. Discovering the backups were failing silently for four months, at this exact moment, is a well-documented experience.

Notification obligations

In Türkiye, a personal data breach must be reported to the Personal Data Protection Authority (KVKK) without undue delay — the Board's guidance sets 72 hours as the expectation. If EU residents' data is involved, GDPR obligations apply in parallel.

Ransomware is generally treated as a personal data breach where personal data was accessible, which in most business environments it was. Involve legal advice early; this is not a decision to make from a technical assessment alone.

Also consider your cyber insurance policy, if you hold one. Many require notification within a fixed window and some restrict who may perform the remediation.

On paying

We do not advise on the payment decision — it is a legal and commercial matter, not a technical one, and it may carry sanctions implications depending on the group involved.

What we will say factually: payment buys a decryption tool that frequently works imperfectly, does not remove the attacker's access, and does not undo data that was exfiltrated before encryption. Restoring from a clean backup is a better outcome wherever it is available.

Rebuilding

Two rules govern recovery.

Do not restore into the same compromised environment. If you do not know how they got in, restoring simply resets the clock. Establish the entry point first — commonly exposed remote desktop, a phished credential, or an unpatched edge device.

Rebuild rather than clean. Machines that were encrypted should be reinstalled from known-good media, not disinfected. Reset every credential, including service accounts, and enable multi-factor authentication on anything reachable from outside before reconnecting.

Afterwards

The uncomfortable part is that the conditions that allowed it were almost certainly visible beforehand: a flat network, remote desktop exposed to the internet, no offline backup copy, an endpoint agent that had stopped reporting months ago.

If you are recovering from an incident, we can help with containment, scope assessment and the rebuild. If you are not, a security review now costs a great deal less than this article's subject matter.

Need help with this?

Ask us about cyber security services, or request a free assessment directly.

Cyber security services
Blog

More articles

Security

Backup for small businesses: the 3-2-1 rule

Most businesses have backups. Far fewer have a backup that survives ransomware — and that is a different thing.

Security

Guest Wi-Fi log retention in Türkiye: who must comply?

If you offer Wi-Fi to guests in Türkiye, this obligation applies to you.

Security

The first hour after data loss: what to do and what not to

The data is usually still there. The real loss happens during recovery attempts.