HIVE80lab — Ops notes

Ransomware Recovery Checklist for Small Teams: The First 48 Hours

The expensive mistake teams make during ransomware is restoring while the attacker is still inside. They reimage two machines, join them back to the network, and watch the encryption return through the front door. The first 48 hours are not a restore project — they are a containment project with a restore at the end. Here is the checklist that keeps the order right.

The first 48 hours — in order

  1. Isolate before you touch anything — unplug, don't power off. Pull the network cable / turn off Wi-Fi on every machine that shows the ransom note or behaves oddly. Do not shut down: RAM holds evidence, and some strains kill the boot sector on a clean shutdown. One encrypted laptop left plugged into the office switch is how five machines became thirty.
  2. Protect the backup before the backup is next. Pause cloud sync (OneDrive, Dropbox, Google Drive) and disconnect network-attached backup shares. Ransomware walks mapped drives and sync folders by design — an untouched, offline copy is your entire recovery, and it is the attacker's next target while it's still reachable.
  3. Verify the backup offline before you trust it. Any backup taken after infection started is already encrypted — compare timestamps against the first symptom, then restore the newest clean copy to an isolated machine and actually open files from it. An air-gapped or offline copy passes. Everything still attached to the network gets the same suspicion as the patient.
  4. Preserve evidence before you wipe. If a machine is still on, photograph the ransom note (the ID string matters), note what changed — extensions, wallpaper, files renamed — and capture what you can before reimage. You need it to identify the strain, to report to police (ReportCyber in Australia, IC3 in the US), and for the insurer's claim. Wiping first makes all three harder.
  5. Decide the ransom question with counsel, not adrenaline. Paying funds the next attack, offers no decryption guarantee, and still leaves you with a data breach to disclose. Loop in legal and your insurer before deciding — many policies void coverage if you pay or even negotiate without notifying them first. Write the decision down either way; the written decision is what auditors and insurers ask for.
  6. Restore clean, not fast. Rebuild from known-good media, and rotate every credential before a machine rejoins the network: passwords, API keys, tokens, VPN accounts, service accounts — assume all of them are burned. And patch the way in (it is usually exposed RDP or a VPN without 2FA) before reconnecting, or you are re-infecting the rebuilt fleet on day one.
  7. Convert the pain into a drill. In the review, answer four things: what did we lose, what alerted (or didn't), what was manual, and how long was the offline copy lagging. Then schedule the quarterly restore test and the offline backup cadence. Teams that recover in days did the drill before the incident; the drill is the only part of this checklist you can practice in peacetime.

The 48-hour timeline, on one card

WindowDoDo not
Hour 0–1Unplug affected machines; pause syncs; disconnect backup sharesPower off, pay, or "just check one file"
Hour 1–4Verify offline backup on an isolated machine; capture evidenceRestore onto the production network
Hour 4–24Report (ReportCyber / IC3), call insurer and lawyer, hold public comms to factsNegotiate unilaterally; trust "decryption guarantees"
Hour 24–48Rebuild clean; rotate every credential; patch the entry vectorRejoin the network with the old password set
Day 3+Restore data, monitor like it's on fire, run the review and book the drillDeclare victory before the first clean week

The three rules that make the checklist work

---

The Ops Starter Kit Vol. 2 ($27) is the advanced incident-management pack — the DR plan, evidence log, comms templates, and the tabletop scenarios this checklist drills into — launch week: 30% off any paid kit with code HIVE-LAUNCH30 at checkout (ends Sep 11, 23:30 ACST).