Ransomware Recovery Checklist for Small Teams: The First 48 Hours
The expensive mistake teams make during ransomware is restoring while the attacker is still inside. They reimage two machines, join them back to the network, and watch the encryption return through the front door. The first 48 hours are not a restore project — they are a containment project with a restore at the end. Here is the checklist that keeps the order right.
The first 48 hours — in order
- Isolate before you touch anything — unplug, don't power off. Pull the network cable / turn off Wi-Fi on every machine that shows the ransom note or behaves oddly. Do not shut down: RAM holds evidence, and some strains kill the boot sector on a clean shutdown. One encrypted laptop left plugged into the office switch is how five machines became thirty.
- Protect the backup before the backup is next. Pause cloud sync (OneDrive, Dropbox, Google Drive) and disconnect network-attached backup shares. Ransomware walks mapped drives and sync folders by design — an untouched, offline copy is your entire recovery, and it is the attacker's next target while it's still reachable.
- Verify the backup offline before you trust it. Any backup taken after infection started is already encrypted — compare timestamps against the first symptom, then restore the newest clean copy to an isolated machine and actually open files from it. An air-gapped or offline copy passes. Everything still attached to the network gets the same suspicion as the patient.
- Preserve evidence before you wipe. If a machine is still on, photograph the ransom note (the ID string matters), note what changed — extensions, wallpaper, files renamed — and capture what you can before reimage. You need it to identify the strain, to report to police (ReportCyber in Australia, IC3 in the US), and for the insurer's claim. Wiping first makes all three harder.
- Decide the ransom question with counsel, not adrenaline. Paying funds the next attack, offers no decryption guarantee, and still leaves you with a data breach to disclose. Loop in legal and your insurer before deciding — many policies void coverage if you pay or even negotiate without notifying them first. Write the decision down either way; the written decision is what auditors and insurers ask for.
- Restore clean, not fast. Rebuild from known-good media, and rotate every credential before a machine rejoins the network: passwords, API keys, tokens, VPN accounts, service accounts — assume all of them are burned. And patch the way in (it is usually exposed RDP or a VPN without 2FA) before reconnecting, or you are re-infecting the rebuilt fleet on day one.
- Convert the pain into a drill. In the review, answer four things: what did we lose, what alerted (or didn't), what was manual, and how long was the offline copy lagging. Then schedule the quarterly restore test and the offline backup cadence. Teams that recover in days did the drill before the incident; the drill is the only part of this checklist you can practice in peacetime.
The 48-hour timeline, on one card
| Window | Do | Do not |
|---|---|---|
| Hour 0–1 | Unplug affected machines; pause syncs; disconnect backup shares | Power off, pay, or "just check one file" |
| Hour 1–4 | Verify offline backup on an isolated machine; capture evidence | Restore onto the production network |
| Hour 4–24 | Report (ReportCyber / IC3), call insurer and lawyer, hold public comms to facts | Negotiate unilaterally; trust "decryption guarantees" |
| Hour 24–48 | Rebuild clean; rotate every credential; patch the entry vector | Rejoin the network with the old password set |
| Day 3+ | Restore data, monitor like it's on fire, run the review and book the drill | Declare victory before the first clean week |
The three rules that make the checklist work
- The offline copy is the recovery. 3-2-1 backup means nothing if the "1" is on a share the attacker could reach. One offline or immutable copy, tested quarterly, beats five backups that ransomware can encrypt.
- Every credential is burned. The cheapest assumption after any ransomware event is that every password, key, and token the network ever held is on someone else's machine. Rotation is an hour of work; re-infection is a second incident report.
- Report even if you pay. Law enforcement tracks the strains and sometimes holds working decryptors; insurers and regulators read the report as evidence you handled it like an adult. Silence only protects the attacker.
---
The Ops Starter Kit Vol. 2 ($27) is the advanced incident-management pack — the DR plan, evidence log, comms templates, and the tabletop scenarios this checklist drills into — launch week: 30% off any paid kit with code HIVE-LAUNCH30 at checkout (ends Sep 11, 23:30 ACST).