Blog Incident Response

What to do in the first 2 hours after a ransomware attack: A step-by-step guide

A ransomware attack is a crisis situation where minutes matter. A poor response, restarting systems, paying the ransom without thought or destroying evidence, can significantly worsen the situation. Here is the exact procedure to guide you through the first critical hours.

22 December 2025 · 12 minutes reading · Incident Response

You arrive at work in the morning and your colleagues' computers display a message demanding a ransom. Or the IT administrator detects unusual activity on the servers in the middle of the night. Either way, you discover that your organisation is facing a ransomware attack. What now?

The first 120 minutes after discovering an attack are critical. They determine the scale of the incident, whether forensic evidence can be preserved for the investigation, and how quickly recovery will proceed. This guide provides specific steps: not general advice, but a precise procedure that can be implemented immediately.

Minutes 0–15: Immediate response (what NOT to do and what TO do)

The first instinct of many people is to restart the computer, hoping the problem will disappear. This is a fatal mistake. Restarting causes loss of data in volatile memory, which may contain decryption keys, information about the attacker, or traces of their presence in the system.

What NOT to do immediately

What to do immediately

  1. Document everythingwhat you see, photograph the screens with your mobile phone. Record the time of discovery.
  2. Activate the crisis team - contact the IT director, security manager and management. Keep contacts ready outside the affected systems (printed or on a mobile phone).
  3. Stop using affected internal communication systems: switch to an alternative channel (personal phones, Signal).

Minutes 15-45: Network isolation and scope identification

Isolation is the most important technical step in the first hours. The aim is to stop the spread of ransomware to other systems and prevent data exfiltration (the attacker may still be downloading data even if encryption is already underway or has finished).

Procedure for isolating the network

  1. Disconnect the affected network segments from the rest of the infrastructure at the switch or firewall level: not by physically unplugging cables from each PC, but by centrally changing VLAN or ACL rules.
  2. Block outgoing traffic on the internet-facing firewall for affected segments. You will stop any ongoing data exfiltration and malware communication with the C2 server.
  3. Insulate backup systems - disconnect backup servers from the production network to prevent the backups from being encrypted. This is priority number one for recovery.
  4. Document the network topology during an attack: screenshots from firewalls, SIEM and NAC systems.

Identification of the scope of the attack

In parallel with insulation, identify which systems are affected:

Minutes 45-90: Contacting the IR team and forensic preservation of evidence

If you do not have your own Incident Response team, it is time to call in external specialists. SecureOn.cz provides 24/7 IR services with a guaranteed response time. Save the number in advance, searching for contact details during an incident wastes valuable time.

Forensic preservation of evidence

Proper preservation of evidence is crucial for two things: the investigation of the attack and any potential criminal report. Carry out these steps before any restoration:

Minutes 90–120: Notification of obligations under NIS2 and communication

If your organisation falls under the NIS2 Directive (and from 2025 this applies to thousands of Czech companies), you are legally required to report serious cyber incidents to NÚKIB. The deadlines are strict:

Submit notifications via the NUKIB.cz portal. Delays or failure to notify may result in sanctions of up to 10 million EUR or 2% of global turnover.

Internal and external communication

Communication during an incident cannot be improvised. Prepare concise, factual reports for different groups:

Deposits and restoration: how to proceed correctly

Recovery from backups is the preferred approach, paying a ransom is a last resort to be considered only after consulting with incident response specialists and legal counsel, if no backups exist or they are also encrypted.

How to verify deposits before restoration

  1. Verify that backups are clean: check the backup system logs for the last successful backup without errors.
  2. Isolate backup media from the network before restoration: an attacker may still be present.
  3. Renew up to of a clean environment (fresh installation OS), never on existing compromised systems.
  4. Before connecting restored systems to production, perform a security scan.

The ideal backup strategy for ransomware resilience is the 3-2-1-1-0 rule: 3 copies of data, on 2 different media types, 1 off-site, 1 offline (air-gapped), and 0 errors during backup verification.

Preparing for a ransomware attack is significantly more effective and cheaper than dealing with the aftermath of an actual attack. SecureOn.cz offers custom Incident Response playbooks for your organisation, regular simulation exercises and a 24/7 IR hotline. Contact us before you need it.

Conclusion: Plan, not panic

A ransomware attack tests an organisation's preparedness at the worst possible time. Companies that manage ransomware incidents with minimal losses share one common factor: they had a pre-prepared Incident Response plan, regularly tested backups, and contacts for IR specialists stored outside digital systems.

If your plan says only "call IT", it is not a plan. It is a wish. Start building real preparedness today.

Do you need advice on cybersecurity?

Our experts are ready to assess your situation. The first consultation is free of charge.

Get a free consultation