Cybersecurity Grants

The First Hour of a Ransomware Attack: What Happens and What to Do

September 28, 2026Cyber Grants Alliance8 min read

The first hour of a ransomware attack doesn't decide whether you get hit. It decides how many options you still have at the end of the day. In those sixty minutes you choose what to unplug, who to call and what to leave alone. Those choices shape your recovery, your insurance claim, your legal duties and, if you're a defense contractor, your federal reporting.

We wrote this for the office manager who notices it first, the executive director who gets the call and the owner who is also the IT department. You don't need a security team to get the first hour right. You need a plan short enough to follow while your heart is pounding.

What does the first hour of a ransomware attack actually look like?

It rarely looks like a movie. Usually someone says a file won't open. Or every document on the shared drive suddenly has a strange extension. Or a note appears on the screen with instructions and a deadline. Sometimes a printer starts printing ransom notes.

By the time the note shows up, the attackers have often been busy for a while. CISA's StopRansomware Guide explains that ransomware groups commonly steal copies of data before they encrypt it, and then threaten to publish it. So the locked files you can see may not be the whole story.

In that moment the instinct is to fix things fast: reboot, run the antivirus, restore from last night's backup, email everyone to stop working. Some of those moves help. Others wipe out evidence you'll need later, or warn an attacker who is still reading your inbox.

So here's a question worth thinking about: who in your organization would notice first, and do they know exactly who to tell?

Should I unplug the computers or shut them down?

Disconnect first. CISA's advice is to cut affected systems off from the network right away: pull the network cable, turn off Wi-Fi on the device and disconnect it from shared drives. Power a machine down only if you can't disconnect it. Shutting down can erase information held in memory, and responders use that information to work out what happened.

A few more things belong in this window:

  • Take photos of the ransom note and any odd screens with a phone.
  • Write down when someone first noticed something wrong, and who it was.
  • Check whether your backups are still connected to the network. If they are, disconnect them before they get encrypted too.
  • Don't wipe, reimage or restore anything yet.

That last one is hard, because restoring quickly looks like progress. But if you restore onto systems the attacker still controls, they may simply encrypt them again. And you'll have erased the trail that shows how they got in.

Who do I call first when ransomware hits?

First, a warning: assume your email and chat tools are compromised. Attackers inside your network may be able to read them. Coordinate by personal cell phone and text until someone qualified tells you it's safe to switch back.

A sensible order for a small organization:

  1. The person who makes decisions. One person needs to own the next several hours, even if that person isn't technical.
  2. Your IT provider or an incident response firm. If you use a managed service provider, find out now whether incident response is part of what they do. Not all of them offer it.
  3. Your cyber insurance carrier, if you have a policy. Many policies expect prompt notice and may require you to use responders they approve. Read your policy before you need it, because bringing in your own firm first can complicate a claim.
  4. Law enforcement. You can report to the FBI through your local field office or its Internet Crime Complaint Center, and to CISA. Reporting helps agencies link your incident to others and share information that may help with recovery.
  5. Legal counsel, especially if customer, donor, patient or employee data may be involved. Most breach notification duties come from state laws, which differ from state to state. Sector rules such as HIPAA add more duties for health data.

If your file server and email were locked right now, where would you find your IT provider's cell phone number? If the answer is "in Outlook," fix that first.

Should we pay the ransom?

Don't make that call in the first hour, and don't let a countdown timer force it. The FBI has said publicly that it does not support paying a ransom. Paying doesn't guarantee you get your data back or that stolen copies are deleted. The Treasury Department's Office of Foreign Assets Control has also warned that paying certain groups can expose you to sanctions.

In the first hour, the job is narrower. Don't reply to the attackers, don't click links in the note and don't try to negotiate on your own. Contain the damage, preserve evidence and get qualified help on the phone. Whatever comes next will be a better decision once you have the facts.

We have a defense contract. What changes in the first hour?

A lot, and the clock may already be running. Check whether your contract includes DFARS clause 252.204-7012. If it does, and the incident affects covered defense information or your ability to provide operationally critical support, the clause requires you to report it to the Department of Defense rapidly. That means within 72 hours of discovery, through the DIBNet portal. Subcontractors also report directly to DoD and give the incident report number to their prime.

Three details catch people out:

  • You need a DoD-approved medium assurance certificate to file that report. Getting one takes time, so put it on this week's list, not on incident day's.
  • The clause requires you to preserve and protect images of affected systems, and relevant monitoring data, for at least 90 days after you submit the report. A panicked wipe and reinstall can put you out of compliance.
  • If you isolate malicious software, the clause directs you to submit it to the DoD Cyber Crime Center.

This week also brought a reminder that courts are looking closely at cybersecurity promises in federal contracts and grants. Crowell & Moring reported that a federal district court dismissed a False Claims Act complaint over cybersecurity compliance for lack of materiality. The firm called it the first dismissal of its kind. But it's one ruling in one court, and it doesn't settle the law. We wouldn't take it as a sign that your security promises matter less. An incident is exactly when any gap between what you told the government and what you actually do comes to light.

Do you know today whether 7012 is in your contract, and who in your company would file the report?

How can a small organization prepare for the first hour?

You don't need an enterprise security program. You need a few things done before the bad day:

  • A one-page first hour plan, printed and kept somewhere other than your network. It names the decision maker and lists phone numbers for your IT help, insurer, attorney, FBI field office and CISA. It also repeats the core rule: disconnect, don't wipe.
  • Backups you have actually restored from. Keep at least one copy offline, or somewhere an attacker with your admin passwords can't reach it. A backup you've never tested is a hope, not a plan.
  • A short list of who has administrator access, plus multifactor authentication on email, remote access and those admin accounts. CISA recommends multifactor authentication as a core protection.
  • Thirty minutes around a table. Read a scenario out loud: it's 8:15 on a Tuesday and the bookkeeper can't open anything. Then ask each person what they would do next. You'll probably find your first gap within minutes.

If you're a defense contractor, add the medium assurance certificate and a printed copy of the 7012 reporting steps to that list.

Which of these could you finish before Friday?

Apply for In-Kind Support

If your organization doesn't have a first hour plan yet, apply for in-kind support from Cyber Grants Alliance and get help closing the gap before the bad day arrives.

Frequently asked questions

What is the first thing to do in a ransomware attack?

Cut the affected devices off from the network by unplugging network cables and turning off Wi-Fi. Disconnect your backups too. CISA advises disconnecting rather than powering down where you can, because shutting down can erase evidence held in memory. Don't wipe or restore anything until responders have looked.

Should I turn off my computer if I get ransomware?

Disconnect it from the network first, and turn it off only if you can't disconnect it. Powering down can destroy information that investigators use to learn how the attack happened and whether data was stolen.

Who should a small business report ransomware to?

Report it to the FBI, through a local field office or the Internet Crime Complaint Center at ic3.gov, and to CISA. Notify your cyber insurer if you have a policy, and ask legal counsel about breach notification duties under state and sector rules. Defense contractors with DFARS 252.204-7012 in their contracts must also report to DoD within 72 hours of discovery.

Should a small business pay a ransomware demand?

The FBI does not support paying ransoms. Paying doesn't guarantee that your data comes back or that stolen files are deleted, and OFAC has warned that some payments carry sanctions risk. Either way, it isn't a decision to make in the first hour, before you know how far the incident reaches.

What does DFARS 7012 require after a ransomware attack?

If the incident affects covered defense information or operationally critical support, the contractor must report it to DoD rapidly, within 72 hours of discovery, through DIBNet. Filing requires a DoD-approved medium assurance certificate. The contractor must also keep images of affected systems and relevant monitoring data for at least 90 days after the report, and submit any isolated malicious software to the DoD Cyber Crime Center.

Why use phones instead of email during a ransomware incident?

Attackers who have reached your network may be able to read your email and chat. Coordinating by phone and text keeps your response plans out of their sight until your systems are confirmed clean.

Call to action

If your organization doesn't have a first hour plan yet, apply for in-kind support from Cyber Grants Alliance at cybergrantsalliance.org.

Ready to Protect Your Business?

Join the businesses strengthening their cybersecurity with CGA.