Insights

The first 24 hours: what to do when ransomware hits

6 October 2026

Use this ransomware response checklist to isolate devices, preserve evidence, plan recovery and assess reporting obligations for Australian SMBs.

Ransomware can turn an ordinary workday into an operational emergency: files become unavailable, systems stop responding and staff cannot serve customers. Huntress has published commentary featuring UnderDefense’s Nazar Tymoshyk about the opening hours of an attack. For Australian SMBs, the practical lesson is to prepare decisions before disruption forces them.

This ransomware response checklist sets out first-day priorities. The time windows are guides, not waiting periods: containment, investigation and legal assessment often need to run together. Treat suspected ransomware as an incident immediately, without waiting for a ransom note.

First hour: ransomware response checklist for containment

Your first objective is to limit further damage while keeping responders able to investigate.

  • Isolate affected devices. Disconnect Ethernet and WiFi. Where an authorised security team can isolate an endpoint through its management platform, use that capability to retain the response channel.
  • Do not routinely restart or shut down devices. Shutdown can destroy volatile evidence. If encryption continues and isolation is impossible, seek urgent responder guidance; stopping damage may take priority.
  • Keep backup media disconnected. Do not attach a backup drive to check whether files can be recovered.
  • Escalate shared-system exposure. Tell IT immediately if affected devices can reach file servers, virtual infrastructure, cloud administration or backups. Broader network isolation should be coordinated by someone who understands those dependencies.
  • Stop staff experimenting. Do not run downloaded decryptors, delete suspicious files or reinstall systems before the response lead authorises it.

Use a known-clean device and a trusted communication channel. A compromised mailbox or internal chat account may expose your response plans.

Record what was isolated, by whom and when. Containment changes are necessary, but they should not become an undocumented second problem.

Hours 1–4: appoint a lead and activate incident contacts

Choose one incident lead with authority to coordinate technical work and business decisions. Assign a separate person to maintain the incident log if staffing allows.

Your ransomware response checklist should identify these contacts by name and include an alternative phone number:

  • Your managed IT provider and cyber security response team.
  • An executive authorised to approve emergency spending and service shutdowns.
  • Your cyber insurer or broker, including any required incident-response hotline.
  • Legal or privacy advisers who can assess notification duties.
  • Operations, finance and communications representatives.
  • Critical software, hosting and backup providers.

Check insurance conditions early. Some policies require approval before appointing forensic specialists or incurring particular costs. Do not delay urgent containment while resolving administration, but document decisions.

Report the incident through ReportCyber. For urgent cyber security assistance, the Australian Cyber Security Hotline is 1300 CYBER1 (1300 292 371). A police or cyber incident report does not automatically satisfy privacy, contractual or sector-specific reporting duties.

Give staff a short instruction: stop using affected systems, report unusual behaviour through the nominated channel and do not contact the attacker. Nominate one person to approve external messages.

Hours 1–6: preserve evidence and establish scope

A ransom note is evidence of an incident, not a complete explanation of it. Responders need to establish how access occurred, what the attacker controlled and whether information was taken before encryption.

Preserve the following under responder direction:

  • Photographs or screenshots of ransom messages, including visible identifiers.
  • The original suspicious email, attachments and message headers where available.
  • Endpoint alerts, firewall and VPN logs, remote-access records and backup audit logs.
  • Microsoft 365 sign-in, audit and relevant mailbox activity records.
  • A timeline of symptoms, user reports, system changes and response actions, with time zones.

Store collected evidence in a restricted location outside the suspected compromised environment. Record who collected it and retain originals. Specialist responders should handle memory capture and forensic imaging where required; staff should not delay isolation to attempt these tasks.

Ask investigators to distinguish confirmed findings from possibilities. Which systems are affected? Were administrator accounts used? Is there evidence of data transfer, new accounts or disabled security controls?

The absence of an obvious download alert does not establish that no data was stolen. Our Microsoft 365 hardening checklist covers identity and configuration controls worth reviewing once immediate containment is underway.

Hours 4–12: protect access and stabilise operations

Device isolation alone may leave the attacker with working credentials, active sessions or remote administration access.

From clean administrative equipment, have your technical team disable compromised accounts, revoke relevant sessions and tokens, and rotate exposed credentials in a controlled sequence. Include service accounts and backup administration where exposure is suspected. A password reset alone may not remove every access path.

Check remote management tools, privileged accounts and application permissions. Our guide to rogue remote management abuse explains why legitimate support tools also need scrutiny.

Meanwhile, operations should identify safe temporary workflows. Can orders be recorded offline? Can appointments be confirmed by phone? Can finance continue without relying on potentially altered bank details?

Keep temporary records controlled and recoverable. Do not move customer information into personal email or unapproved file-sharing services. Tell customers what is unavailable and when the next update will arrive, without claiming the incident is contained before that is established.

Hours 6–24: decide what can be recovered safely

The recovery question is not simply whether a backup exists. It is whether you can restore trusted systems without restoring the attacker’s access.

Before approving recovery, confirm:

  • Backup integrity: backups remain available, protected and testable without exposing them to compromised systems.
  • Recovery point: the selected copy predates known malicious activity, not just the appearance of encryption.
  • Clean destination: the recovery environment is separated from compromised infrastructure.
  • Access remediation: exploited weaknesses, exposed credentials and known persistence mechanisms have been addressed.
  • Validation: security checks and business owners can verify restored applications and records.

Prioritise dependencies as well as business importance. An invoicing application may need identity, networking and database services restored first. Reconnect systems in stages with monitoring and explicit approval.

Ransom payment does not assure data recovery or prevent publication of stolen information. Government guidance discourages payment. Any consideration of payment requires executive, legal, insurer and law-enforcement input, including sanctions and reporting implications. Staff should never negotiate independently.

Our hybrid data protection guide provides a useful starting point for reviewing recovery coverage across cloud services, laptops and servers.

During day one: assess reporting obligations

Add a reporting register to your ransomware response checklist. Record each potential obligation, its trigger, deadline, owner and advice received.

Under the Privacy Act’s Notifiable Data Breaches scheme, covered entities must assess suspected eligible data breaches. Where an assessment is required, take all reasonable steps to complete it within 30 calendar days. That is not permission to wait: once there are reasonable grounds to believe an eligible breach occurred, notification to the OAIC and affected individuals is required as soon as practicable. Consult the OAIC’s breach guidance.

Also check mandatory ransomware payment reporting. Under the Cyber Security Act 2024 framework, covered businesses meeting the $3 million annual turnover threshold, and certain critical infrastructure entities, must report qualifying ransomware or cyber-extortion payments within 72 hours. Payments made on an entity’s behalf can also be relevant. Confirm coverage and the applicable trigger using Home Affairs guidance and legal advice.

Critical infrastructure, regulated industries, contracts and insurance policies may impose separate duties or shorter deadlines. Being below a turnover threshold does not resolve every obligation.

End day one with a written handover

Document what is contained, what remains uncertain, which services are unavailable and who owns the next actions. Set the next executive update and recovery approval checkpoint.

Tech Engine Australia can help you review your cyber security, incident contacts and recovery readiness. Call 1300 088 324 or email sales@techengine.au to identify gaps before an incident forces the decisions.

Want this applied to your business?

Request an AI Blueprint and we will map the processes worth automating first.

Request an AI Blueprint