WorldTech Blog

What to Do in the First Hour After a Ransomware Attack

Written by WorldTech Team | Aug 7, 2026, 6:51:00 PM

You see the ransom note on the screen. Files are locked. Your stomach drops. What you do in the next hour has an outsized effect on how much this costs you — in data, downtime, and dollars. Here's a calm, clear plan. (Print this and keep it somewhere accessible, because you won't want to search for it mid-crisis.)

Step 1: Isolate — don't power off

Ransomware spreads across networks, so your first job is to stop it. Disconnect affected devices from the network — unplug the ethernet cable, disable Wi-Fi. If it's spreading fast, disconnect your internet at the router to contain it.

Important: isolate, but don't immediately shut machines down. Powering off can destroy forensic evidence and, in some cases, data that could aid recovery. Disconnect from the network and leave the devices running until an expert advises otherwise.

Step 2: Call your IT/security team immediately

This is not a fix-it-yourself moment. Contact your managed IT or security provider right away. The faster professionals are engaged, the more they can contain the damage and preserve your options. If you have cyber insurance, notify your carrier early too — many have required response procedures.

Step 3: Don't pay, and don't negotiate on your own

It's a natural instinct, but do not pay the ransom or contact the attackers on your own. Payment doesn't guarantee you'll get your data back, may mark you as a willing target, and can carry legal complications. Let professionals assess recovery options first.

Step 4: Document everything

Photograph the ransom note. Note the time you discovered it, which systems are affected, and anything unusual you noticed. This helps responders, your insurer, and any required reporting.

Step 5: Preserve backups — carefully

Your backups are your best path to recovery, so protect them. Do not connect backup drives to infected systems. If backups are isolated and clean, they're your way out — which is exactly why modern ransomware tries to reach them first.

Step 6: Prepare to notify

Depending on your industry and the data involved, you may have legal obligations to notify clients, patients, or regulators. Loop in legal counsel early to get this right.

What NOT to do

  • ❌ Don't keep working on infected devices
  • ❌ Don't power everything off in a panic
  • ❌ Don't pay or contact attackers on your own
  • ❌ Don't connect backups to infected machines
  • ❌ Don't assume it's contained until an expert confirms it

The best response is preparation

Every business that handles a ransomware attack well prepared for it in advance — with isolated, tested backups, monitored systems, and a response plan already written. If you're reading this before an incident, that's the work to do now. WorldTech provides the security and data recovery that limit an attack's damage — and the planning that helps prevent one. Contact us to assess where your business stands.