The First 30 Minutes of a Ransomware Incident
A minute-by-minute checklist for small IT teams · Hive80 Lab · Sep 2026
When ransomware hits a 20-person company, the difference between a bad night and a company-ending event is what happens in the first 30 minutes. Most small teams lose those minutes to confusion, not to attackers. Here is the field-tested sequence.
Minute 0–5: Confirm and contain
- Do not power off encrypted machines if you can avoid it — you may destroy volatile evidence, and with some strains the only chance to avoid re-paying.
- Isolate: pull the network cable / disable Wi-Fi on suspected hosts. Unplug, don't shut down.
- Preserve: photograph the ransom note and the ransomware ID (ID Ransomware, No More Ransom) before anything else.
Minute 5–15: Escalate on your terms
- Activate the call tree. Who decides when the owner is asleep? Decide this now, not at 2 a.m.
- Start the timeline log: every action, timestamped. Insurers and forensics will ask for it.
- Freeze backups: disconnect backup targets so the encryption job doesn't finish its work.
Minute 15–30: Decide with a clear head
- Identify the strain from the note. Some have free decryptors.
- Engage insurer/legal if the policy requires it before contacting anyone.
- Never negotiate from a compromised machine.
Print the checklist tonight. You will not have time to search for it during an incident.
← All Hive80 Lab resources