You arrive at work in the morning and your colleagues' computers display a message demanding a ransom. Or the IT administrator detects unusual activity on the servers in the middle of the night. Either way, you discover that your organisation is facing a ransomware attack. What now?
The first 120 minutes after discovering an attack are critical. They determine the scale of the incident, whether forensic evidence can be preserved for the investigation, and how quickly recovery will proceed. This guide provides specific steps: not general advice, but a precise procedure that can be implemented immediately.
Minutes 0–15: Immediate response (what NOT to do and what TO do)
The first instinct of many people is to restart the computer, hoping the problem will disappear. This is a fatal mistake. Restarting causes loss of data in volatile memory, which may contain decryption keys, information about the attacker, or traces of their presence in the system.
What NOT to do immediately
- Do not restart no affected system: retain status in memory.
- Do not start an antivirus scan on affected systems. It may overwrite or delete evidence.
- Do not communicate with the attacker without consulting an IR specialist: every communication is a tactical matter.
- Do not erase No files or logs: even the buyback report serves as proof.
- Do not pay a ransom without a thorough analysis of the situation, payment does not guarantee data recovery, funds criminal structures and may contravene anti-corruption regulations.
What to do immediately
- Document everythingwhat you see, photograph the screens with your mobile phone. Record the time of discovery.
- Activate the crisis team - contact the IT director, security manager and management. Keep contacts ready outside the affected systems (printed or on a mobile phone).
- Stop using affected internal communication systems: switch to an alternative channel (personal phones, Signal).
Minutes 15-45: Network isolation and scope identification
Isolation is the most important technical step in the first hours. The aim is to stop the spread of ransomware to other systems and prevent data exfiltration (the attacker may still be downloading data even if encryption is already underway or has finished).
Procedure for isolating the network
- Disconnect the affected network segments from the rest of the infrastructure at the switch or firewall level: not by physically unplugging cables from each PC, but by centrally changing VLAN or ACL rules.
- Block outgoing traffic on the internet-facing firewall for affected segments. You will stop any ongoing data exfiltration and malware communication with the C2 server.
- Insulate backup systems - disconnect backup servers from the production network to prevent the backups from being encrypted. This is priority number one for recovery.
- Document the network topology during an attack: screenshots from firewalls, SIEM and NAC systems.
Identification of the scope of the attack
In parallel with insulation, identify which systems are affected:
- Which servers and workstations show signs of encryption (high I/O, renamed files, ransom notes)?
- When did the attacker enter the network? (Ransomware is typically deployed after a 2-4 week reconnaissance period.) Review SIEM logs for the last 30-90 days.
- What type of ransomware is it? Check the extensions of the encrypted files and the ransom note: the database on ID Ransomware (ransomware.id) will help identify the variant.
- Has data exfiltration occurred? Check the outbound traffic logs, large data transfers prior to encryption are a typical pattern of double extortion attacks.
Minutes 45-90: Contacting the IR team and forensic preservation of evidence
If you do not have your own Incident Response team, it is time to call in external specialists. SecureOn.cz provides 24/7 IR services with a guaranteed response time. Save the number in advance, searching for contact details during an incident wastes valuable time.
Forensic preservation of evidence
Proper preservation of evidence is crucial for two things: the investigation of the attack and any potential criminal report. Carry out these steps before any restoration:
- Memory dumpobtain a dump of the operational memory of affected systems using tools such as WinPmem (Windows) or LiME (Linux), decryption keys or malware artifacts may reside only in RAM.
- Disk image. Create a bit-for-bit copy of the hard drives from the affected systems (dd, FTK Imager). Always work with the copy, never with the original.
- Export logs. Windows Event Logs, firewall logs, proxy server logs, VPN logs, and Active Directory, everything that can reveal an attacker's activity.
- Keep the buyback reports and all communication with the attacker as evidence.
- Note down the hashes (SHA256) hash of key files for later integrity verification.
Minutes 90–120: Notification of obligations under NIS2 and communication
If your organisation falls under the NIS2 Directive (and from 2025 this applies to thousands of Czech companies), you are legally required to report serious cyber incidents to NÚKIB. The deadlines are strict:
- Within 24 hours: preliminary notification (early warning): basic information about the incident is sufficient.
- Within 72 hours: initial formal report with available information on scope and impact.
- Within 1 monthfinal report upon completion of the investigation.
Submit notifications via the NUKIB.cz portal. Delays or failure to notify may result in sanctions of up to 10 million EUR or 2% of global turnover.
Internal and external communication
Communication during an incident cannot be improvised. Prepare concise, factual reports for different groups:
- Employeeswhat is happening, what to do (do not use affected systems), who to contact. Eliminate panic and misinformation.
- Management and Board of Directorsimpact on operations, estimated costs, recovery timeline.
- Customers and partnersif there is a possibility that their data has been leaked, notify them promptly: the legal obligation under GDPR is to report it to the Office for Personal Data Protection within 72 hours.
- Media. Communicate through the legal department or a PR specialist, not the technical team. Do not give the attacker unnecessary publicity.
Deposits and restoration: how to proceed correctly
Recovery from backups is the preferred approach, paying a ransom is a last resort to be considered only after consulting with incident response specialists and legal counsel, if no backups exist or they are also encrypted.
How to verify deposits before restoration
- Verify that backups are clean: check the backup system logs for the last successful backup without errors.
- Isolate backup media from the network before restoration: an attacker may still be present.
- Renew up to of a clean environment (fresh installation OS), never on existing compromised systems.
- Before connecting restored systems to production, perform a security scan.
The ideal backup strategy for ransomware resilience is the 3-2-1-1-0 rule: 3 copies of data, on 2 different media types, 1 off-site, 1 offline (air-gapped), and 0 errors during backup verification.
Preparing for a ransomware attack is significantly more effective and cheaper than dealing with the aftermath of an actual attack. SecureOn.cz offers custom Incident Response playbooks for your organisation, regular simulation exercises and a 24/7 IR hotline. Contact us before you need it.
Conclusion: Plan, not panic
A ransomware attack tests an organisation's preparedness at the worst possible time. Companies that manage ransomware incidents with minimal losses share one common factor: they had a pre-prepared Incident Response plan, regularly tested backups, and contacts for IR specialists stored outside digital systems.
If your plan says only "call IT", it is not a plan. It is a wish. Start building real preparedness today.