Practical guide · HeroIT

Ransomware: use the first hour to contain impact

The first objective is not to reinstall everything quickly. Contain further spread, establish scope and preserve the information required for investigation and safe recovery.

01

0–15 minutes: contain impact

Isolate affected devices and network segments according to incident scope.

  • Disconnect network connectivity from affected systems
  • Protect unaffected backups and administrative access
  • Assign one incident coordinator

02

15–30 minutes: establish scope

Avoid destroying evidence through rushed changes.

  • List affected accounts, endpoints, servers and services
  • Preserve relevant logs and available evidence
  • Record a timeline and actions taken

03

30–60 minutes: activate recovery

Recovery starts from a trusted baseline.

  • Engage management and required legal, insurance or external contacts
  • Verify backup availability and separation
  • Plan prioritised recovery of clean systems and monitoring during return to service

FAQ

Frequently asked questions

Should we immediately reinstall an infected computer?

Not automatically. First contain the incident and preserve required information; rushed reinstallation can destroy useful evidence.

Should we shut down the whole network?

Isolation scope depends on the incident. Broad compromise may require broader isolation, but the decision should be controlled.

When should we restore backups?

When scope is understood, the recovery source is considered trustworthy and returning the system will not simply reopen the incident.

Dealing with an incident now?

Prioritise containment, coordination and a safe recovery path rather than a cosmetic fix.

20-min discovery call