The ransom note appears at 2 a.m. By 8 a.m., half your endpoints are encrypted. By noon, your CEO is asking whether to pay. By 6 p.m., you have made ten decisions — and five of them were probably wrong.
This is the timeline that separates companies that recover in 48 hours from companies that lose a month. At Metaluxo we run incident response for SMEs. The first 24 hours follow a pattern. This post documents it.
Hour 0–2: Confirm and classify
Do not assume it is a false alarm. A ransom note is evidence of unauthorised access. The attacker has been in your network for days or weeks. The encryption is the final act, not the first.
Convene the incident response team.
- Incident commander (CEO or CTO)
- Technical lead (senior engineer or IT manager)
- Legal and compliance contact
- Communications lead
If you do not have an incident response plan, name these four roles now. The person who discovers the attack should not be the person who decides whether to pay the ransom.
Classify the scope.
- How many endpoints are encrypted?
- Is the server infrastructure affected?
- Has data been exfiltrated? (Check for large outbound transfers in firewall logs)
- Are backups accessible and clean?
This classification determines everything that follows. A localized ransomware infection on three laptops is not the same as domain-wide encryption with data theft.
Hour 2–6: Contain
Isolate affected systems.
- Disconnect encrypted endpoints from the network (physically unplug, do not trust remote commands)
- Disable remote access (VPN, RDP, SSH) until you know which credentials are compromised
- Preserve logs. Copy firewall, endpoint, and authentication logs to offline storage before they rotate
Preserve evidence.
Create forensic images of affected systems before you do anything else. This is not optional if you intend to:
- File an insurance claim
- Report to law enforcement
- Pursue legal action
- Understand how the attacker got in
Do not:
- Delete logs to “clean up”
- Run antivirus on encrypted systems (it will not help and may destroy evidence)
- Restore from backups before you know the entry point
Hour 6–12: Assess and notify
Assess backup integrity.
- When was the last backup taken?
- Is it stored offline or in a separate cloud account?
- Can you restore a test file?
- Are backup logs clean (no sign of attacker access)?
If backups are clean and recent, you have options. If backups are encrypted or missing, the decision becomes harder.
Contact your cyber insurer.
Most policies require notification within 24 hours. Call the hotline, not your broker. The insurer will assign a case manager and may approve emergency spending on forensics, legal counsel, or credit monitoring.
Contact law enforcement.
In the UK: Action Fraud or the National Cyber Security Centre. In Poland: the national police cybercrime unit. Law enforcement cannot decrypt your files, but they can preserve evidence, issue takedown notices, and trace payments.
Engage legal counsel.
Your solicitor needs to assess:
- GDPR notification deadlines (72 hours to the ICO or UODO)
- Customer contract obligations
- Whether paying the ransom violates sanctions
- Regulatory reporting requirements
Hour 12–24: Decide and communicate
Decide on the ransom.
This is a legal and business decision, not a technical one. Consider:
- Do you have clean backups? If yes, do not pay.
- Is the data irreplaceable? If yes, the calculation changes.
- Will payment violate UK/EU sanctions? Your legal counsel must check.
- Does your insurance cover the ransom? Most policies do not.
Draft internal communications.
Staff need to know:
- What happened
- What they should do (do not log in to affected systems, report suspicious emails)
- What they should not do (discuss on social media, contact journalists)
Draft customer notifications (if required).
If customer data was accessed, you may need to notify affected customers. The notification should say: what happened, what data was involved, what you are doing, and what they should do. Do not send without legal review.
Plan recovery.
Recovery is not restoration. Restoration means putting systems back online. Recovery means putting them back online without reintroducing the attacker.
Your recovery plan should include:
- Rebuild from clean backups (verify integrity first)
- Patch the entry point (close the vulnerability, revoke stolen credentials)
- Re-image critical systems (do not try to disinfect — you cannot prove a negative)
- Validate before reconnecting (scan for malware, verify configurations)
When to call for external help
Call an incident response firm within the first hour if:
- You do not have a technical lead who understands your network
- More than five endpoints are encrypted
- Personal data is involved and you are subject to GDPR
- You have cyber insurance that covers response costs
- You do not have clean, tested backups
At Metaluxo we provide emergency incident response for SMEs across the EU, with a 12-hour engagement commitment. If you are reading this during an active incident, contact us now. If you are reading this before an incident, print this timeline, name your four roles, and test your backups this week.
Common questions
Should we pay the ransom?
Law enforcement advises against it. Payment does not guarantee decryption, may violate sanctions, and funds criminal activity. The decision requires legal counsel.
How long does ransomware recovery typically take?
Isolated incidents: 48–72 hours. Widespread ransomware with data exfiltration: 2–6 weeks. Full business recovery: 1–3 months.
Do we need to report ransomware to regulators?
If personal data was accessed, GDPR requires notification within 72 hours. NIS2 requires reporting within 24 hours for in-scope entities.