What Actually Happens During a Ransomware Incident Response
Ammon Gleason
Director of AI & Engineering
July 10, 2026
5 min read
What Actually Happens During a Ransomware Incident Response
Nobody plans for the day their files get encrypted. Most business owners I talk to have thought about ransomware in the abstract, as a scary headline, but not as an actual Tuesday morning where screens start showing a ransom note and the phones will not stop ringing. I want to walk through what that morning really looks like, step by step, because knowing the shape of it in advance is most of what keeps people calm enough to make good decisions.
The first ten minutes matter more than people think
The instinct when something looks wrong is to start clicking around trying to fix it. Resist that. The first move in a real incident response is containment, not repair.
That means disconnecting affected machines from the network immediately, not shutting them down. Powering off a machine can destroy evidence and sometimes memory-resident information that helps identify what happened. Pulling the network cable or disabling Wi-Fi isolates the problem without erasing the trail.
At the same time, somebody needs to be figuring out how far this has spread. Is it one laptop, or is it touching the file server? Ransomware moves fast once it has a foothold, so the scope question gets answered in parallel with containment, not after it.
Who actually gets called, and in what order
A real response has a short list of people who need to know immediately, and the order matters.
Your IT team or provider, first. Whoever manages your systems needs to be in the loop within minutes, not after you have tried a few things yourself. Every minute spent guessing is a minute the incident is still spreading.
Your cyber insurance carrier, early. Most cyber insurance policies require notification within a specific window, and many require you to use an approved incident response vendor to stay covered. Calling your insurer late, or not at all, can jeopardize a claim you are going to need.
Legal counsel, if data may have been exposed. Depending on what was accessed, you may have notification obligations to customers, employees, or regulators. This is not a step to guess your way through.
Law enforcement, generally the FBI's Internet Crime Complaint Center for US businesses. They will not always be able to intervene in real time, but reporting matters for the broader effort against these groups, and some cases do get investigated.
Notice what is not on this early list: the attacker. Do not engage with the ransom note or the criminals directly until you have talked to your insurer and, ideally, an incident response professional. That conversation has real strategy behind it, and doing it alone tends to go badly.
Figuring out what actually happened
Once things are contained, the work shifts to understanding the full picture. This usually runs in parallel across a few tracks:
- What got encrypted, exactly. Which systems, which drives, which shares.
- What got accessed or copied before encryption. Modern ransomware groups frequently steal data before locking it, then threaten to publish it as extra leverage. This changes your notification obligations even if you can restore from backup.
- How they got in. A phishing email, an exposed remote access point, a stolen credential. Without this answer you cannot be confident the door is actually closed once you clean up.
- Whether backups are intact. This is the moment every backup and disaster recovery decision you made months ago either pays off or does not.
The actual recovery
If backups are clean and isolated from the compromised network, which is exactly why isolated backups matter so much, recovery means rebuilding affected systems from a known-clean state and restoring data. This is rarely instant. Depending on how much data there is and how the backups were structured, this can run anywhere from hours to more than a week for a full environment.
If backups were also compromised, or never properly isolated, the options narrow considerably and get much more expensive, which is the scenario every part of this process is trying to help you avoid.
Throughout recovery, systems typically get rebuilt clean rather than simply cleaned in place. You do not want to restore a system that still has a hidden foothold sitting on it, waiting to start the whole thing over in a month.
After the fire is out
The incident is not over when systems come back online. A real response includes a follow-up phase that most people do not picture:
- A written record of what happened and when, partly for insurance, partly so you actually learn from it.
- Closing the specific hole that let the attacker in, whether that is a phishing gap, a missing patch, or weak remote access controls.
- Rotating every credential that could plausibly have been exposed, not just the obvious ones.
- Any required notifications to customers, employees, or regulators, handled properly and on time.
Skipping this phase is how businesses get hit twice by the same kind of attack within a year, which happens more often than people expect.
Why having a plan before the incident changes everything
Every step above goes faster and calmer when it was decided in advance rather than figured out live under pressure. Knowing who to call, having isolated backups already in place, and having an IT partner who already knows your systems turns a chaotic morning into a bad but manageable one. That is the entire difference between an incident and a crisis.
The bottom line
Ransomware response is not a single dramatic moment. It is a sequence: contain fast, call the right people in the right order, figure out what actually happened, recover from clean backups, then close the hole so it does not happen again. Most of what determines whether that sequence goes smoothly was decided weeks or months before the attack, not during it.
We walk clients through building that plan before it is needed, from managed IT fundamentals to the cybersecurity controls that make containment and recovery actually possible. If you read this and realized you do not know who you would call first, that is worth fixing this week, not after. Reach out and we will help you put a real plan in place.

Ammon Gleason
Director of AI & Engineering
Graduate student in Artificial Intelligence at the University of Utah, building on a BS in Computer Science with an emphasis in Machine Learning. 5+ years of hands-on IT experience and 4+ years of programming and ML engineering — leading G8's AI automation, custom software, and applied machine-learning practice.
Talk to a human about this.
We do the work the article describes. Two ways in: