Cyber security
Ransomware Attack Recovery: What to Do in the First 24 Hours
If you suspect ransomware, stop and contact your organisation’s incident lead or IT provider immediately. Avoid clicking through the ransom message, contacting the attacker, deleting files or attempting a rushed restoration. If it is safe and within your approved procedure, disconnect an obviously affected device from wired and wireless networks to limit further communication.
Every incident is different. Turning a device off may reduce ongoing damage in one situation but destroy useful volatile evidence in another. Network isolation may also interrupt critical operations. The first-hour actions should therefore follow a documented response plan and specialist direction wherever possible.
This guide gives Australian business owners a practical structure for the first 24 hours. It is general information, not legal, forensic or incident-specific advice. During a live event, use the Australian Cyber Security Centre’s current reporting guidance and obtain qualified technical, legal and insurance advice.
Why the First 24 Hours Matter Most
Ransomware can create several problems at once. Files may be encrypted, systems may be unavailable and information may have been stolen before the ransom demand appeared. An attacker may also have access to accounts, backups or remote-management tools.
Early decisions affect:
- whether the disruption spreads;
- whether evidence is preserved;
- whether clean backups remain available;
- how quickly advisers can understand the event;
- whether legal or contractual notification periods are met;
- what staff and customers are told; and
- how safely systems can return to service.
The goal is not to rebuild everything in 24 hours. It is to contain the incident, establish reliable decision-making and prepare a safe recovery path.
Hour-by-Hour Response Checklist
Here’s your recovery guide for the critical first 24 hours of a ransomware attack. Keep this checklist handy, or better, build it into a documented incident response plan before you ever need it.
0–1 Hour: Isolate and Contain
This is about containment, plain and simple.
- Disconnect infected devices from Wi-Fi and wired networks immediately
- Disable Wi-Fi and any remote access tools across the office
- Isolate affected systems from the network to stop ransomware from spreading further
- Leave devices powered on where possible, as this preserves data for forensic analysis later
- Do not attempt to restart or “fix” anything yourself
The goal in this first hour is simple. Stop the ransomware from reaching more of your network.
1–4 Hours: Assess and Notify
Once you’ve contained the incident, it’s time to assess and notify.
- Identify which affected systems and data have been hit
- Check whether your secure backups are intact and untouched
- Notify your leadership team and IT provider
- Begin logging every action taken, and every system checked, with timestamps
- Notify staff not to open any suspicious emails or files in the meantime
Good logs matter here. A clear log of what happened and when will support any forensic analysis, insurance claim, or regulatory report down the track.
4–12 Hours: Engage Cyber Security Melbourne Experts
This is when specialist support earns its keep. A managed IT service provider Melbourne businesses already work with can move faster than a scramble to find help mid-crisis.
- Bring in cybersecurity experts to run a forensic analysis of the attack
- Determine the type of ransomware involved and how the attacker gained access
- Identify any vulnerability that allowed the initial breach, from an unpatched system to a phishing email
- Check for signs of data exfiltration, since many ransomware variants steal sensitive data before encrypting it
- Loop in your cyber insurance provider if you hold a policy
12–24 Hours: Begin Recovery and Communication
With containment and assessment underway, focus shifts to recovery options and communication.
- Begin restoring from clean, tested backups where confirmed safe
- Avoid reconnecting restored systems until you’re confident there’s no reinfection risk
- Prepare a clear message for staff, customers, and any affected third parties
- Confirm your legal obligations around notifying customers or regulators
- Start planning next steps for a longer recovery plan and root cause fix
Common Mistakes Businesses Make During an Attack
Even well-prepared Melbourne businesses can trip up under pressure. Watch out for these mistakes:
- Rushing to restart systems before confirming the ransomware has been contained can trigger reinfection
- Restoring from backups too early, before checking that those backups weren’t also encrypted or compromised
- Skipping the log, which leaves gaps that make forensic analysis and insurance claims harder later
- Paying the ransom without advice, which doesn’t guarantee a working decryption key
- Delaying notification, both internally and to any relevant authority, can create legal and reputational problems
- Assuming a firewall or antivirus alone will catch everything, when layered security measures work far better together
Should You Pay the Ransom?
This is one of the hardest calls a business owner will face, and there’s no single right answer. It depends on your situation, your backups, and your legal obligations.
The Australian Cyber Security Centre’s guidance is clear: it does not recommend paying a ransom. Paying does not guarantee you’ll get a working decryption key, and it doesn’t guarantee that stolen data won’t still be leaked. It can also mark your business as a soft target for future ransomware attacks.
That said, some businesses do face situations where the ransom payment feels like the only option, particularly without secure backups to fall back on. Since May 2025, Australian businesses with an annual turnover of $3 million or more must comply with a mandatory ransomware reporting regime for any ransomware payment made. Always get advice from your legal team, your cyber insurance provider, and law enforcement before deciding.
For full, current guidance, refer to the ACSC’s advice on ransomware.
How a Managed IT Service Provider Melbourne Businesses Trust Can Help Before It Happens
The best ransomware recovery is the one you never need. A managed IT service provider Melbourne firms can rely on builds resilience into your systems long before an attacker comes knocking.
Backup strategy
- Immutable backups that attackers cannot alter or delete, even with admin access
- Following the 3-2-1 rule, with copies stored offsite and offline
- Regular restore testing, so you know your backups actually work when you need them
Endpoint detection and response
- Real-time monitoring across every device on your network
- Automatic isolation of a compromised device before ransomware spreads
- Faster detection means less dwell time for an attacker inside your systems
Incident response retainer
- A documented incident response plan, agreed and tested before a crisis hits
- Guaranteed rapid response times when a ransomware incident is reported
- A clear escalation path so your team knows exactly who to call, and when
Building Ransomware Resilience Long-Term
Recovering from one ransomware incident is only half the job. True cyber resilience means reducing the odds of a repeat.
- Patch known vulnerabilities promptly, since unpatched systems remain one of the most common entry points
- Enforce multi-factor authentication across all accounts, especially admin-level access
- Run regular staff awareness training, since phishing remains a leading cause of ransomware infections
- Review your Essential Eight maturity each year, not just once
- Revisit your network security checklist regularly as your business grows
- Keep your cyber insurance policy current and understand exactly what it covers
Don’t wait for an attack to find out where your gaps are. A proactive review now is far cheaper, in time and stress, than a scramble during a live ransomware incident. For a broader look at everyday protections, see our guide to cybersecurity best practices for Melbourne businesses, and if you haven’t reviewed your cover recently, our piece on what business leaders need to know about cyber insurance is a good next read.
Ready to make sure your business is prepared before an attack happens? Book an incident response readiness review with Telco ICT Group today.
FAQs
What should I do first if I suspect a ransomware attack?
Disconnect the affected device from the network straight away. Then isolate any connected systems and call your IT provider before doing anything else.
Should I pay the ransom to get my data back?
The ACSC advises against paying a ransom. It doesn’t guarantee recovery, and it can mark you as a repeat target. Always get legal and insurance advice first.
How long does ransomware recovery typically take?
It varies widely depending on backup quality and attack scope. Businesses with tested, secure backups tend to recover far faster than those without.
Can a managed IT service provider prevent ransomware attacks?
No provider can guarantee prevention, but layered defences, like MFA, patching, and endpoint detection, significantly lower your risk.
Do I need to report a ransomware attack in Australia?
Businesses with turnover over $3 million must report ransomware payments within 72 hours under current laws. Reporting is encouraged for all businesses.
Table of contents
Related Posts
We’ll handle the tech
so you can get on with
running your business.