Ransomware Response Plan: First 60 Minutes Checklist

Ransomware Response Plan: First 60 Minutes Checklist

Ransomware response plan - Jaymon Security

1. Introduction

Ransomware remains the threat that causes the most economic damage to businesses, and the moment that defines the outcome is not the first encrypted file: it is the 60 minutes that follow. A well-defined ransomware response plan turns the initial chaos into an ordered sequence of decisions and prevents the incident from becoming a legal, reputational and financial problem that drags the business down for months.

Most organizations are not ready for that moment. When the first ransom note appears, the temptation is to power off servers, unplug disks and call the administrator who knew the systems years ago. None of that is part of a professional response. In this article you will find the first-hour operational checklist ordered by time windows, the decisions management must make and the legal obligations that cannot wait.

2. The Attack Chain in Six Phases

To respond well you need to understand how the attacker got in. The book “Practical Cybersecurity Protocols and Procedures” describes the typical chain in six phases: initial access (misconfigured RDP, phishing, pirated software or exposed services), persistence and reconnaissance, lateral movement and privilege escalation, data exfiltration before encryption, mass encryption and, finally, the ransom note with its countdown. When the alarm goes off, the attacker has been inside the network for days or weeks: it is almost never their first step.

In MITRE ATT&CK terms, large-scale encryption corresponds to T1486 (Data Encrypted for Impact) and the destruction of snapshots and copies to T1490 (Inhibit System Recovery). This terminology is not academic: it lets your team define which telemetry triggers the ransomware response plan — not only encryption alerts, but also shadow volume deletion, antivirus deactivation or administrative tools running outside working hours.

The most common entry point in 2026 is still the path of least resistance: remote desktop services exposed on the internet can be located on Shodan in seconds, and credential stuffing with infostealer logs makes the rest trivial. That is why the first 60 minutes of your incident response playbook also include identifying where the lock was left open: the answer defines both the notification and the permanent fix, and it usually points to the same three vectors — exposed RDP, unpatched VPN appliances and email accounts without strong authentication.

3. Why Backups Are the First Target

There is a reason why backup protection appears in the first minute of the checklist: 94% of ransomware attacks attempt to compromise backups, and 57% succeed. The attacker does not encrypt data to destroy your business: they encrypt so that your only apparent way out is to pay. If they delete or encrypt the copies first, paying stops being an option and becomes the only one. That is why the first reaction when encryption is detected is not to look at the attacked server, but to check that the backups are still intact.

This silent phase also explains why response is a process and not a configuration: if backup administration credentials are the same as production ones, the attacker has them all from the start. The person who takes over backup protection at minute five must know which repository is considered trustworthy, who holds separate credentials and where the offline copy is, without needing to open documentation that should already be ready on the table.

4. Checklist for the First 60 Minutes

Here is the complete first-hour checklist, ordered by time windows. Do not read it when the incident happens: rehearse it with your team, so every responder knows their task and management knows what is decided and when.

# Ransomware response plan checklist: the first 60 minutes
# 00:00-05:00  Contact the security lead. Never wait until Monday.
# 05:00-15:00  Isolate the affected host on the network WITHOUT powering it off.
# 15:00-25:00  Confirm the immutable backup is safe and disconnected.
# 25:00-40:00  Activate the crisis committee: management, IT, legal, comms.
# 40:00-50:00  Block the C2 if the SOC or EDR confirms it: cut anomalous egress.
# 50:00-60:00  Capture logs and a memory dump before any other action.
# 60:00+       Assess AEPD notification (72h), CSIRT and police report.

Fig. 1 – Operational ransomware response plan checklist: the first 60 minutes.

The first line of the checklist deserves a comment: “isolate without powering off”. A server being encrypted still holds the attacker’s processes, their connections and sometimes their own tools in memory; powering it off freezes the evidence in the wrong place and can speed up the spread of the encryption. Network isolation — disconnecting the virtual cable or the segment at the switch, not the machine — preserves the scene and stops the damage with the same effect.

5. The Crisis Committee: Who Decides What

The first hour is not the time to improvise roles. The crisis committee must be defined in writing long before: management takes strategic and budgetary decisions, IT executes the isolation, the data protection officer assesses notification obligations, communications manages the internal and external message and legal counsel documents every step. Knowing who is in charge when alerts fire is as important as the checklist itself in a ransomware response plan.

Role First-hour decision Deadline
Management Activate the committee and budget for external IR 0-60 min
IT / CISO Network isolation, protect backups, preserve evidence 0-60 min
Legal / DPO Assess the breach notification and alert the insurer 60 min
Communications Prepare internal messaging and prevent rumors 60 min
External IR Forensic analysis with chain of custody 60-120 min

Fig. 2 – Crisis committee roles during the first hour of response.

A common mistake is letting the technician decide about the ransom at three in the morning, with monitors full of extortion notes. The evidence is clear: around 8% of organizations that pay never recover their data, and payment does not prevent the stolen data from being published on the leak site. It is a management decision, with legal advice and based on a cost analysis; only in exceptional cases — no reliable backups, an outage that threatens lives or a downtime cost higher than the ransom — does negotiating make sense.

6. Legal Obligations and Notifying on Time

In the EU the deadline is set by Article 33 of the GDPR: if the incident involves personal data, the notification to the supervisory authority must arrive within 72 hours of becoming aware of the breach. The notification does not need to be exhaustive: a preliminary report describing the nature of the incident, the categories of data affected and the expected impact meets the deadline, and it is completed later with the final report. For essential service providers, the NIS2 Directive also requires an early notification to the CSIRT within 24 hours.

The police report is also prepared from minute one: the digital forensic analysis with chain of custody is the basis of any judicial process. Insurers usually require notification within contractual 24 to 72-hour windows. Three obligations with independent clocks, all starting in the first hour: another reason to keep this checklist out of the drawer.

7. After the First Hour: Recover and Reinforce

Once the hour is over, the goal changes from containment to recovery. Before restoring, verify the integrity of the copies and choose a backup that predates the first reasonable sign of compromise, not the most recent one. Restore first in an isolated environment, confirm with the EDR or with forensic analysis that no indicators of compromise remain, and promote the restoration gradually into production. Change every password — email, VPN, banking, administration — and rotate the domain krbtgt password twice if Active Directory was compromised.

When decryption is viable, the No More Ransom project, backed among others by Europol, maintains a free collection of decryptors for the most widespread families. Do not promise impossible deadlines: real restorations take days, and the RTOs written in the documentation are usually optimistic. After the incident, hold an honest post-mortem following NIST SP 800-61 lessons learned, with owners and dates, and reinforce the specific entry vector: if it came through RDP, close it and move to VPN with MFA; if it came through phishing, harden DMARC and awareness.

The numbers explain why this is not a bureaucratic exercise: 60% of small and medium-sized businesses that suffer a ransomware attack close within six months. A rehearsed ransomware response plan does not prevent the attack; it does prevent many of its consequences: the outage is shorter, evidence is preserved and notifications arrive on time.

After recovery, measure what the incident taught you: time to detect, time to contain, time to restore. Those metrics, tracked against the phases of the attack chain, turn the ransomware response plan from a document into a program that improves. In the post-mortem, give every finding an owner and a date, and rehearse the checklist again six months later: response plans decay faster than the tools they describe.

8. Conclusion

Ransomware is a management problem, not just an IT one. The first 60 minutes determine whether the incident stays a costly outage or becomes a months-long problem with fines, lost trust and recovery bills. The checklist you have seen in this article is a starting point: adapt it to your organization, make sure the immutable copies are real and rehearse the crisis committee at least once a year.

If the incident has already happened, the sequence does not change: isolate without powering off, protect the backups, notify on time and decide on the ransom with the facts on the table. You can go deeper into what to do when your business is already a ransomware victim and understand the most exploited entry vector in our analysis of ransomware and remote desktop RDP. At Jaymon Security we help organizations build and rehearse their ransomware response plan, so that the first hour is not the hour of panic.

Need help with Ransomware response plan?

At Jaymon Security, we help organizations protect their systems. From security audits to SIEM/SOC implementation, our expert team designs custom solutions.

Contact us for a free infrastructure assessment.

No puedes copiar el contenido

ENES