← SecureAZ Blog

Incident Response · 7 min read · Published 20 April 2026 · Reviewed 17 August 2026

Ransomware: What to Do in the First 24 Hours

The first 24 hours after a ransomware attack determine how much damage you take. Here's the response sequence, what not to do, and who to call in NZ and Australia.

Ransomware hits fast. Within minutes of execution, files are being encrypted across your network. By the time someone notices something's wrong, significant damage may already be done.

What you do in the first 24 hours largely determines how bad the outcome is. Businesses that respond quickly and systematically recover faster, pay less (or nothing), and limit the scope of data exposure. Businesses that panic, make ad hoc decisions, or wait too long end up in much worse shape.

This is the response sequence that matters.

The first 30 minutes

Isolate immediately. The moment you suspect ransomware, disconnect affected machines from the network. Unplug ethernet cables. Disable Wi-Fi. If you can identify the infected endpoint, isolate it. If you can't identify it, consider taking down network segments until you can.

The goal is to stop lateral movement — ransomware spreads aggressively across shares, mapped drives, and connected systems. Every minute an infected machine stays on the network is more encrypted files.

Do not turn off infected machines. Counterintuitive, but important: powering down can destroy forensic evidence and, in some cases, make recovery harder. Leave them isolated but running unless told otherwise by your incident response team.

Do not pay yet. Payment is a last resort, not a first response. You don't yet know whether backups are viable, whether decryption tools exist (some ransomware variants have been cracked), or whether paying will actually result in recovery.

The first two hours

Activate your incident response plan. If you have one, follow it. If you don't, now is when you'll wish you did — but you can still work through this systematically.

Call your IT provider or incident response team. This is not a time for internal troubleshooting. Ransomware response requires specific skills: identifying the variant, assessing backup integrity, determining the blast radius, and advising on recovery options. If you don't have an IR retainer, call one.

Report to CERT NZ. This is important and often skipped. CERT NZ provides free incident assistance to NZ businesses and can advise on the specific ransomware variant. In Australia, report to the ACSC. Reporting also helps the agencies track attack patterns and issue warnings to other businesses.

Assess your backups. This is critical. Are your backups intact and unencrypted? When were they last tested? Are they stored offline or isolated from your main network? If your backups were connected to the network at time of infection, assume they may also be compromised until confirmed otherwise.

Document everything. Photograph ransom notes. Screenshot error messages. Record the timeline of what happened and when. This matters for insurance claims, legal obligations, and recovery.

The first 24 hours

Determine the variant. Your IR team will identify the ransomware. This matters because:

  • Some variants have decryption tools available (check nomoreransom.org)
  • The variant tells you the likely attack vector and whether you have a data exfiltration problem (double extortion ransomware steals data before encrypting it)

Assess the blast radius. What was encrypted? What can you restore from backups? What systems are down and what's the business impact of each?

Notify affected parties. If customer, employee, or partner data has been accessed or exfiltrated, you likely have notification obligations under the Privacy Act 2020. This is a legal requirement, not optional. Contact the Privacy Commissioner if you're unsure of your obligations.

Contact your cyber insurer. If you have cyber insurance, notify them immediately. Most policies have specific requirements around notification timelines and pre-authorisation of response spend. Failing to notify in time can affect your claim.

What not to do

  • Don't publicly announce the incident until you understand the scope — premature statements create legal and reputational risk
  • Don't negotiate with attackers directly without IR advice — there are established protocols and payment of ransom does not guarantee recovery
  • Don't restore from backups immediately without confirming the infection vector is closed — restoring to an active infection just re-encrypts your files
  • Don't reuse credentials that were active on affected systems until all passwords have been rotated

Practical checklist

First 30 minutes:

  • [ ] Isolate affected machines from the network
  • [ ] Alert IT/IR team
  • [ ] Do not power off infected machines
  • [ ] Photograph ransom notes and error messages

First 2 hours:

  • [ ] Report to CERT NZ / ACSC
  • [ ] Activate incident response plan
  • [ ] Check backup integrity
  • [ ] Start incident log

First 24 hours:

  • [ ] Identify ransomware variant — check nomoreransom.org
  • [ ] Determine blast radius
  • [ ] Notify cyber insurer
  • [ ] Assess Privacy Act notification obligations
  • [ ] Begin recovery planning with IR team

Before it happens

The best ransomware response is the one you never have to use. The ACSC Essential Eight — cyber.gov.au/essential-eight — gives you a prioritised set of controls that directly reduce ransomware risk: application control, patching, restricted admin privileges, and offline backups.

SecureAZ training covers ransomware recognition, incident response procedures, and phishing awareness (the most common ransomware delivery vector). Running regular simulations means your team knows what to do when it's real, not just when it's hypothetical. Ransomware is often delivered via phishing — Business Email Compromise covers the targeted attacks that frequently precede a network intrusion. Start a free account to see the incident response training modules.