7 Things to Do in the First 10 Minutes of a Ransomware Attack
Cybersecurity 2026-10-08 CentralComputer Team

7 Things to Do in the First 10 Minutes of a Ransomware Attack

7 Things to Do in the First 10 Minutes of a Ransomware Attack

7 Things to Do in the First 10 Minutes of a Ransomware Attack

Sorry, not to scare you — but this might be the most important article you read this year.

After years of IT support and dozens of ransomware cases, we've found a brutal pattern: what happens in the first 10 minutes determines the outcome. Get it right, lose a day. Get it wrong, lose a month — or the business.

These 7 steps come from blood-and-tears experience. Print them out, stick them on the IT room door, or send them to the company group chat.

1. Don't panic. Breathe. (Minutes 0–1)

Sounds useless, but it's the most important. I've seen too many cases ruined by panic:

  • A client saw the red ransom screen and immediately shut down — wiping decryption clues from RAM
  • An accountant panicked and deleted all "weird files" — including the ransom note, making identification impossible
  • A boss told everyone to power off — then nobody knew which machine was patient zero

Remember: ransomware won't encrypt faster because you panic, nor stop because you're calm. Your calm is for making the right calls.

2. Disconnect! Now! (Minutes 1–2)

The most critical technical action:

  1. Unplug the Ethernet cable: Not disabling WiFi — physically unplug. The malware may have already disabled your WiFi toggle.
  2. Turn off WiFi: On laptops, hit the hardware WiFi switch or disable in settings.
  3. Don't power off: Keep it on (RAM may hold clues, as discussed).
  4. Server room: Don't unplug one by one — too slow. Go to the switch room, pull the uplink cable or kill the switch power. One move kills the whole network.

Why the rush? Ransomware spreads over the network. One minute of delay can mean one more infected machine. The worst we've seen: 1 machine to 30 office PCs in 15 minutes.

Disconnect mantra: "Unplug, don't power off, kill WiFi too; server room — pull the uplink." Memorise it.

3. Photograph the evidence (Minutes 2–4)

Use your phone (not the infected PC) to photograph:

  • The full ransom note / warning screen (must show victim ID, contact method, Bitcoin address)
  • Several encrypted filenames (original + new names)
  • Desktop wallpaper (if changed)
  • System time (proving when discovered)

Why? You'll need these for ID Ransomware identification. And if you report to police later, this is evidence.

Don't: don't delete the ransom note, don't rename files, don't try to "fix" anything. Preserve the scene.

4. Find patient zero and scope (Minutes 4–6)

Three questions:

  1. Which machine got hit first? Ask colleagues who saw anomalies first. Usually whoever opened a suspicious email or download.
  2. How many machines are affected? Walk around quickly (don't power on, just look) — count wallpapers changed or ransom notes present.
  3. Are servers / NAS hit? Most critical. Check server status from a separate clean machine (your phone) — don't operate from infected PCs.

Write this down (pen and paper, not the infected PC). When professionals arrive, hand them this — they'll start immediately instead of investigating from scratch.

5. Don't pay, don't contact criminals (Minutes 6–7)

Decide in the first 10 minutes: no ransom, no dark-web negotiation.

Why?

  • Payment doesn't guarantee recovery (as covered before — 40% chance of total loss)
  • Pay once and you're on the "willing payer" blacklist
  • Everything you say to criminals can leak company info ("we're listed" = charge them more)

The right mindset: "Assume the files are gone; think about rebuilding other ways." You'll be calmer and decide better.

6. Call professionals (Minutes 7–8)

Don't DIY. Ransomware isn't an ordinary PC problem — one wrong move can make things ten times worse.

Who to call?

  • If you have an IT outsourcer: Call them immediately — they should have an incident response process.
  • If not: Call us at +852 6558 6806 (24-hour). Tell us: ① what malware (if identified) ② how many machines ③ whether servers are hit ④ whether backups exist. We'll give immediate advice; critical cases get same-day on-site.
  • Large companies: Also notify management and legal — potential data breach may require privacy commissioner notification.

Stay calm when describing. Give them what you collected in step 4. Professionals dread "I dunno, it just won't turn on."

7. Notify the right people (Minutes 8–10)

Finally, notify (by phone, not company email — the mail server might be hit too):

  • Boss / management: So they're mentally prepared for possible downtime. Be clear: current situation, estimated impact duration, whether to call police.
  • IT lead: So they don't do anything unhelpful (like reinstalling systems).
  • Key clients (if needed): If deliveries are affected, early warning beats last-minute surprises. But don't panic-notify before you understand the situation.

Don't: announce "we've been ransomware'd" in the company-wide group — it causes panic. Let management decide how to communicate.

After 10 minutes: wait for professionals

Done these 7, you've done 90% of the right things. Wait for professionals — don't touch the infected machines further.

What professionals will do:

  1. Confirm malware family and version (ID Ransomware)
  2. Assess available backups / shadow copies / cloud versions
  3. Devise a recovery plan + quote
  4. Execute recovery + hardening

Real comparison: right vs wrong

Two real cases showing the difference:

Done right (Kwun Tong trading): Staff spotted anomaly, unplugged, photographed, called the boss; boss called us. When we arrived, only two PCs were hit, server clean. 90% recovered in three days. Cost: HK$8,500.

Done wrong (Tsuen Wan company, adapted real case): Staff saw the ransom screen and immediately powered off, told colleagues to do the same. Boss arrived, told IT to "just reinstall". IT reinstalled three PCs, then discovered the NAS was hit too — but shadow copies were wiped during reinstall. No backups survived. Paid 0.5 BTC (~HK$250,000), recovered half the files. Total damage: HK$250,000 ransom + HK$30,000 our rescue fee (still incomplete) + two weeks downtime.

Same ransomware. One cost HK$8,500, the other HK$280,000+ unresolved. The difference was the first 10 minutes.

FAQ

1. Q: Why can't I just power off immediately?

A: RAM may hold decryption clues (key remnants) — powering off wipes them. And powering off doesn't stop spread — it's already on disk and resumes at boot. Correct: disconnect, don't power off.

2. Q: Can I find decryptors online myself?

A: You can check No More Ransom from a separate clean PC, but don't browse from infected machines and don't download shady "decryptors". Best to wait for professionals.

3. Q: Should I call the police?

A: Recommended. Hong Kong Police's Cyber Security and Technology Crime Bureau takes reports — not to catch anyone (hard), but to document your response. Keep the report number.

4. Q: Do these 7 steps apply to all ransomware?

A: Yes. Whether .rox, LockBit, .wman or others, the first-10-minutes principles are universal: disconnect, preserve evidence, don't fiddle, call professionals.

5. Q: How to prepare in advance?

A: ① Print this and post it visibly ② Run a simulation drill (like a fire drill) ③ Verify backups actually work ④ Save our 24-hour line in the company directory: +852 6558 6806.

Summary: the value of one sheet of paper

These 7 steps fit on one A4 page. But during an attack, that page is worth hundreds of thousands.

Remember the mantra: "Don't panic, disconnect, photograph, find patient zero, don't pay, call pros, notify." Seven words that save companies.

Want us to run a ransomware response drill for your company? WhatsApp +852 6558 6806 — we offer this service. For day-to-day protection, see our ransomware protection guide.

Found this article helpful?

Feel free to share it with your friends or colleagues.

Call Us