The First 60 Minutes After a Ransomware Attack

The First 60 Minutes After a Ransomware Attack

Your operations director’s phone rings at half past nine on a Tuesday. Someone in finance can’t open their spreadsheets. Ten minutes later, someone else says the same thing. By the time anyone thinks to call it what it is, the clock has already been running for fifteen minutes, and nobody quite knows who should call whom next.

This is not a hypothetical. It is the shape of almost every ransomware incident we see across the North East, and the businesses that come through it well are not the ones with the biggest budget. They are the ones who already knew, before any of this started, exactly what happens in minute five, minute twenty and minute sixty.

We built a visual breakdown of that first hour, minute by minute, because the difference between a contained incident and a very bad week comes down to what has already been decided before the attack begins. Below is the walkthrough, along with what changes at each stage depending on whether a plan exists.

Minute 0: the click

Illustration of an employee opening an email attachment that triggers a ransomware payload

An email attachment gets opened. The payload runs quietly in the background. Business carries on as normal, because nothing looks different yet.

This is the part nobody sees. There is no alert, no error message, nothing that would make anyone stop what they are doing. The damage has already started before a single person in the business knows about it.

Minute 5: encryption starts

Diagram showing malware spreading across mapped drives and shared folders

Files begin changing across mapped drives and shared folders. If endpoint detection is in place, an alert fires here. If not, the business is still in the dark.

Five minutes in, the malware is already moving sideways through the network, not just sitting on one machine. This is the point where the gap between having monitoring in place and not having it starts to matter, because one of those two businesses now knows something is wrong and one does not.

Minute 15: someone notices

Screenshots of employee messages reporting file errors, next to a screen showing a ransomware demand

“My files look weird.” “I can’t open anything.” “There’s an error on my screen.” By the time these messages reach IT, encryption has already been running for ten minutes.

The first sign most businesses get is not a security alert. It is a confused message from someone in the team who thinks they have done something wrong. Ten minutes have already gone before that message reaches anyone who can act on it.

Minute 20: decision one

Without a plan

Who do you call? Does anyone actually know where the admin credentials are kept? Where are the backups? Is the backup drive sitting on the same network that has just been compromised?

With a plan

Containment steps start straight away. Affected systems get isolated, and the incident response checklist is already open on someone’s screen.

This is the point where the difference stops being theoretical. One business is asking questions it should have answered months ago. The other is already three steps into a process it has rehearsed.

Minute 35: decision two

Without a plan

The network is down. Someone is calling a break-fix contact who has never dealt with ransomware before. Someone else has quietly started Googling how to pay in Bitcoin.

With a plan

Affected systems are isolated and backups have been confirmed as clean. The IT provider is already on the phone, walking the team through recovery.

Minute 60: decision three

Without a plan

The conversation has shifted to whether to pay. The demand is high, and paying is no guarantee the data comes back at all.

With a plan

A recovery timeline is set. The restore begins from a backup that has actually been tested. The business is on a path back to running, not stuck deciding whether to negotiate with a criminal.

What the numbers say: ransomware is now involved in 88% of breaches affecting small and medium sized businesses, and over 40% of cyber insurance claims are being declined at renewal or claim stage where controls cannot be evidenced. Source: Verizon Data Breach Investigations Report 2025.

What this actually costs a business without a plan

The sixty minutes above only cover the technical response. What follows it is a set of conversations that land on the desks of the managing director and the finance director, usually within the same day. Can the insurer be shown that controls were in place. What does the board get told, and when. What does this do to a supplier contract that depends on a security questionnaire being accurate. None of those questions have good answers if the honest response is that nobody had looked at this before it happened.

A tested incident response plan does not stop every attack. What it does is remove the guesswork from the first hour, which is the hour that decides whether this becomes a contained incident or a multi-week recovery with a very difficult set of conversations attached to it.

Where to start

Most businesses we speak to have some of the pieces, backups, some documentation, maybe an old policy nobody has looked at since it was written. Few have tested whether those pieces work together under pressure. The quickest way to find out is a short, practical assessment rather than guessing.

How prepared is your business right now?

Our five-minute business continuity and disaster recovery check gives you a straightforward view of where you stand today, and a starting point for closing the gaps before something forces the question.

Common questions

How quickly does ransomware encrypt files?

Encryption typically begins within minutes of the initial payload running, often before anyone in the business has noticed anything wrong. By the time the first error message reaches IT, the malware has usually been spreading across shared drives for ten minutes or more.

Should a business pay a ransomware demand?

Paying does not guarantee data is returned, and it does not remove the underlying cause of the breach. Most incident response guidance, including the NCSC’s, advises against payment and recommends restoring from tested, isolated backups instead.

How long does ransomware recovery take with a tested backup?

With a tested backup and a clear incident response plan, systems can typically be isolated and a restore timeline set within the first hour. Without a tested plan, the same hour is often spent working out who to call and where the backups actually are.

Last updated: 8 September 2026

Facebook
LinkedIn
WhatsApp
Email
Print