The first hour is about decisions, not certainty
When files stop opening, a workstation displays unusual messages, or an administrator receives suspicious alerts, an office rarely knows the full cause immediately. The first-hour plan should not assume that ransomware is confirmed, that data was or was not stolen, or that every system is affected. It should help staff limit additional harm while preserving the information needed by responders.
CISA’s StopRansomware guidance recommends maintaining offline, encrypted backups, testing their availability and integrity, prioritizing restoration using a critical-asset list, and preparing incident-response and business-continuity procedures. Those recommendations become useful only when employees know who may act and how the business will continue.
Minute 0–10: report and stabilize
Employees should use a known reporting path that does not depend entirely on the potentially affected email system. Record the time, device, user, visible message, recent actions, and any unusual sign-in or payment activity. Preserve screenshots and suspicious messages.
A trained responder may instruct staff to disconnect affected devices from wired and wireless networks. Employees should not randomly power off every system, delete files, run unapproved cleanup tools, or repeatedly attempt to sign in. Volatile evidence can matter, and an improvised response may spread disruption or destroy useful records.
Call the designated IT or incident-response contact using a verified number. If a provider is involved, record who accepted the incident and the escalation reference.
Minute 10–20: protect identity and backups
Determine whether administrator, remote-access, email, or backup credentials may be exposed. Do not use a possibly compromised account to make broad changes. A qualified administrator should work from a trusted device and follow the response plan for session revocation, credential changes, and account containment.
Protect unaffected backups from further access. CISA notes that ransomware actors may try to delete or encrypt accessible backups. Confirm whether offline or immutable copies exist, who can administer them, and whether production credentials can alter retention or delete recovery points. Do not begin restoration until responders define a safe recovery sequence.
Minute 20–35: activate business continuity
Identify the minimum services the office must provide during the next business day. Depending on the organization, these may include answering phones, scheduling, payroll, payment processing, access to client or patient records, field dispatch, or statutory filings.
For each service, identify an approved temporary method. Examples include a clean alternate communication channel, a secured paper schedule, an offline contact list, a preapproved manual payment procedure, or a secondary device that has been verified safe. Do not move sensitive information into personal email or an unapproved cloud service simply because the primary system is unavailable.
Assign one person to track decisions, owners, and timestamps. This incident log should avoid speculation and record confirmed facts separately from assumptions.
Minute 35–50: contact decision partners
The incident leader should determine when to contact the cyber insurer, legal counsel, financial institution, law enforcement, and relevant regulators. Insurance policies may require approved vendors or prompt notice. Legal obligations depend on the information involved, the organization’s role, contracts, and jurisdiction.
If fraudulent payments or changed banking instructions are involved, contact the financial institution immediately using a known number. For internet-enabled crime, the FBI’s Internet Crime Complaint Center may be an appropriate reporting channel. Reporting does not replace technical containment or guarantee recovery of funds.
Minute 50–60: set the recovery gate
Before restoring systems, define what must be true:
- The affected scope is sufficiently understood.
- Trusted administrator access is available.
- A clean recovery point has been selected.
- Required logs and evidence have been preserved.
- Restored systems will be scanned and validated.
- Business owners approve the restoration priority.
- Users know when and how to reconnect.
Recovery should follow business impact, not simply whichever system is easiest to restore. Identity, communications, line-of-business applications, finance, and shared data may have dependencies that change the order.
Confirmed versus uncertain
Confirmed: CISA recommends offline encrypted backups, routine restoration testing, incident planning, and restoration priorities based on critical assets. Confirmed: a completed backup job does not prove that data can be restored safely within the needed time.
Uncertain: the presence of encrypted files alone does not establish whether information was copied, which actor is responsible, or whether a payment would restore data. Those questions require evidence and qualified investigation.
Test the plan before an incident
Run a 60-minute tabletop exercise twice a year. Disable primary email for the exercise, require participants to use the printed contact list, and test one actual file restoration afterward. Record unclear authority, missing phone numbers, inaccessible credentials, and untested recovery assumptions.
A strong first hour does not solve the entire incident. It keeps the business from making avoidable mistakes while specialists establish facts and the office protects its ability to recover.

