A Ransomware Recovery Walkthrough: The First 72 Hours

A hypothetical timeline of the first three days after a ransomware attack on a contractor, showing the decisions, steps and mistakes that shape the recovery.

3 min readBy Ironfield Cyber Team

No two ransomware incidents unfold the same way, but the first few days follow a familiar pattern. This article walks through a hypothetical example to show what decisions come up and how preparation changes the outcome. The company, people and timeline are invented for illustration.

Consider a hypothetical 80-person mechanical contractor. On a Saturday morning, the owner receives a call from a superintendent who cannot open drawings on the shared server. Files have strange extensions and a text document demands payment.

Hour 0 to 2: Contain

The first priority is to stop the spread, not to figure out the cause.

  • Isolate affected systems. Disconnect infected computers and servers from the network by unplugging cables or disabling Wi-Fi. Do not shut them down if you can avoid it, as memory can hold valuable evidence. If isolation is unclear, ask an incident response professional.
  • Do not wipe anything yet. Resist the urge to reformat machines immediately.
  • Call for help. Contact your IT provider and, if you have one, your cyber insurance carrier's incident hotline. Many policies require early notice and specify approved responders.
  • Preserve backups. Confirm whether backup systems are intact and disconnect them from the network if they are not yet affected.
  • Start a log. Someone should write down every action and its time.

Hour 2 to 12: Assess

With containment underway, the team needs facts.

  1. Which systems are affected: file server, accounting, email, laptops?
  2. Is data only encrypted, or is there evidence that data was copied? Many attackers steal data before encrypting.
  3. How did the attacker get in? Common routes include stolen credentials, exposed remote access, and phishing.
  4. Are the attackers still in the network? If so, recovery on a compromised network may simply repeat the problem.
  5. What do the backups contain and how recent are they?

Bring in forensic expertise if the situation is complex. Reset credentials only according to a plan, because the attacker may be watching.

Hour 12 to 24: Decide and communicate

Leadership faces several decisions.

Legal and insurance

Engage legal counsel experienced in incident response. Notification obligations may apply if personal information was exposed, and the specifics vary by state and contract. Customers with security clauses may require prompt notice, including utility or defense clients.

Law enforcement

Consider reporting to the FBI and CISA. They accept reports and may provide helpful guidance.

The payment question

Paying a ransom is a business and legal decision with no guarantee. Payment does not ensure that data will be restored or that stolen data will not be released, and legal issues, such as sanctions, may apply. Strong, tested backups usually take this question off the table.

Internal communication

Tell employees what happened in plain terms, what to do and not do, and how to work in the meantime. Use phones, texts or personal email if company email is down. Assume the attacker may be reading company email.

Hour 24 to 72: Recover

  • Rebuild from clean sources. Restore from known-good backups to clean systems, not on top of infected ones.
  • Prioritize. Start with identity services, then payroll and accounting, then project files, then everything else.
  • Fix the entry point. Close the hole the attackers used, enable multi-factor authentication, and rotate all passwords and secrets.
  • Monitor closely. Watch for signs of renewed access.
  • Verify before reconnecting. Scan restored data and confirm systems are clean.

Where preparation made the difference

In this hypothetical, three things sped recovery: an offsite immutable backup, a printed incident contact list that did not depend on email, and a previously tested restore of the accounting server. A company without them might spend weeks rebuilding.

Mistakes to avoid

  • Rebooting and wiping before preserving evidence.
  • Using a compromised email system to coordinate recovery.
  • Restoring backups before the attacker has been removed.
  • Letting the office handle everything without a clear decision maker.

Preparing now

Write a one-page response plan listing contacts, decision makers, insurance details and backup locations, and print it. Rehearse it once a year with a short tabletop exercise.

Ironfield Cyber provides incident response support and helps clients prepare plans and tested recovery before an attack. If you would like to run a tabletop exercise for your leadership team, we can facilitate one.