Ransomware Recovery Plan: The First 24 Hours at a Contractor

A step-by-step walkthrough of the first day after a ransomware attack, from isolating systems to calling insurance, and what to decide ahead of time.

3 min readBy Ironfield Cyber Team

Ransomware rarely arrives at a convenient moment. It tends to surface early in the morning or over a weekend, when someone discovers that files will not open and a ransom note sits on the screen. What the company does in the next 24 hours shapes how long recovery takes and how much damage results.

This walkthrough is a general guide. Every incident differs, and you should involve your IT provider, insurance carrier, and legal counsel as early as possible. The best time to read it is now, before you need it.

Hour 0 to 1: Contain

Isolate, do not power off

Disconnect affected computers from the network by unplugging network cables or disabling wireless. In most cases it is better not to shut down machines, because memory may hold evidence useful to investigators. If you cannot tell which systems are affected, it is reasonable to disconnect broadly, including servers, and to cut off internet access at the firewall if necessary.

Protect the backups

Immediately confirm the backups are intact and disconnect them from the network if they are not already isolated. Attackers frequently target backup systems.

Use a different channel

Do not use potentially compromised systems to coordinate. Switch to phone calls and personal or out-of-band messaging, since your email may be monitored by the attacker.

Hour 1 to 4: Assemble and notify

  1. Activate your incident team. Owner or executive lead, IT provider, finance lead, operations lead, and someone to handle communications.
  2. Call your cyber insurance carrier. Many policies require prompt notice and have a preferred panel of responders. Using an approved vendor may affect coverage.
  3. Contact legal counsel. They can advise on privilege, notification duties, and communications.
  4. Engage incident response specialists if your provider recommends it or your policy provides it.
  5. Start a log. Record every action, who did it, and the time. This will matter for insurance, legal review, and the investigation.

Law enforcement

Consider reporting to the FBI, for instance through the IC3 or a local field office, and to CISA. Reporting helps investigators and may support your recovery.

Hour 4 to 12: Assess

Scope the damage

Work out which systems were affected, whether data was copied out as well as encrypted, and how the attacker got in. The entry point matters: if you restore without closing it, you may be attacked again.

Decide what operations can continue

Can crews keep working? Can you pay people? Identify the most time-sensitive functions, such as payroll, equipment dispatch, and pay applications, and plan manual workarounds. Paper timesheets and phone-based dispatch are unglamorous but effective.

Secure credentials

Assume that passwords on affected systems are compromised. Plan to reset them, starting with administrator accounts and email, once the environment is safe.

Hour 12 to 24: Begin recovery

Rebuild in the right order

Restore identity and core network services first, then the systems that support payroll, accounting, and project operations. Restore to clean systems and scan restored data before reconnecting it.

Communicate

Tell employees what to do and what not to do: do not turn on affected machines, do not talk to the media, and report suspicious messages. Prepare a brief statement for customers, owners, and subcontractors, reviewed by counsel.

The ransom question

Paying is a complex decision with legal, ethical, and practical dimensions. Payment does not guarantee data recovery or that stolen data will not be used. Legal restrictions may apply in some cases. Make this decision with counsel, your insurer, and specialists, not under panic.

Decide before the crisis

  • Who has authority to disconnect systems?
  • Where is the printed contact list and incident plan?
  • Which backups are offline, and who can access them?
  • What are the restoration priorities?
  • How will the team communicate if email is down?

Practice

A tabletop exercise, where the team talks through a ransomware scenario, exposes gaps cheaply. Run one at least annually and update the plan afterward.

Ironfield Cyber can help

Ironfield Cyber helps contractors and energy companies prepare incident response plans, test backups, and run tabletop exercises. If you would like a plan on paper before you need it, we are glad to build one with you.