24/7 ransomware incident response - Dubai & United Arab Emirates +971 52 758 9336
Fast Response

The first 60 minutes after a ransomware attack

The decisions made in the first hour determine how much data comes back. Most of them are about what not to do.

A-Lab briefing · 6 minute read · For owners, IT managers and first responders

It is usually discovered early in the morning. Files will not open, a note is sitting in every folder, servers are unreachable and the phone starts ringing. The instinct is to fix things fast. In a ransomware incident, "fast" often destroys the evidence and the partially intact data that make recovery possible. This checklist is what we ask every client to do before anything else.

Minute 0 to 10: contain without destroying

  1. Disconnect affected systems from the network. Unplug the cable or disable the Wi-Fi and, if you can, isolate the network segment at the switch or firewall. This stops the encryptor from reaching more systems.
  2. Do not power servers off unless you cannot isolate them. Running processes and memory can contain encryption keys, the running malware and logs that will be lost forever on shutdown. This is also the guidance of CISA and every major incident-response body.
  3. Do not reboot "to see if it helps". Some encryptors run their final passes on reboot. Others are only recoverable while they are still resident.
  4. Use out-of-band communication. Coordinate by phone or personal mobile, not company email or chat, which the attacker may be reading.

Minute 10 to 30: preserve

  1. Keep the ransom note. Copy it, photograph it, do not delete it. It identifies the family and often the exact build.
  2. Keep the encrypted files exactly as they are. Do not rename them, do not remove the new extension, do not "clean up".
  3. Do not format, reinstall or restore over affected disks. The encrypted originals and the deleted-but-recoverable data live on those disks. Restoring on top of them overwrites both.
  4. Do not delete encrypted backups. Veeam files, VHDX files and SQL dumps that appear to be encrypted are frequently repairable. See when the backups are encrypted too.
  5. Preserve logs. Firewall, VPN, domain controller and endpoint protection logs are needed to establish how the attacker got in and to satisfy regulators and insurers.
Do not run "free decryptor" tools found through a search engine. Many are fake, several are themselves malware, and a wrong tool run against the wrong family can permanently corrupt files that were recoverable. Identification must come first.

Minute 30 to 60: decide and engage

  1. Do not contact the attackers. Engaging starts a clock, signals that you are considering payment and gives them information. A recovery assessment tells you whether you ever need to consider it. See why contacting the attackers is the weakest option.
  2. Inform leadership, legal counsel and your cyber insurer. Many policies require notification within a fixed period and may specify approved responders.
  3. Send the laboratory what it needs. The ransom note, two or three encrypted files of different types (a document, a large file such as a database or backup fragment, an image), the file extension and a short description of the environment: number of machines, hypervisors, backup product, when it happened.
  4. Note UAE reporting obligations. Depending on sector and licensing, incidents may need to be reported to the UAE Cybersecurity Council, the Dubai Electronic Security Centre, the Central Bank, or the relevant free-zone authority.

What happens next

Within hours of receiving the samples, A-Lab identifies the ransomware family and version, tests recovery against the samples and reports what is recoverable, how long it will take and what it will cost. There is no obligation. If the data cannot be recovered, there is no fee.

Summary. Isolate, do not power off, preserve everything, do not run unknown tools, do not contact the attackers, send samples to the laboratory. Every one of these steps protects your recovery options.

In the first hour right now?

Send the note and samples on WhatsApp. An engineer responds around the clock.