Files start showing up with strange extensions, there’s a ransom note on the desktop and machines begin falling one after another. At that moment you don’t need a treatise on cybersecurity: you need to know what to do in the next sixty minutes. Because what you decide right there —and above all what you do out of sheer panic— is the difference between a bad day and two weeks with the business at a standstill.
This is not a prevention article. It assumes it’s already happening and gives you the incident response plan step by step: what to touch, what not to touch, who to call and in what order to recover. Save it before you need it, because when you do need it you won’t have time to go looking for it.
Why the first few hours decide everything
Ransomware doesn’t encrypt at the speed of light. By the time you see the ransom note, the encryption is still spreading across the network: every minute an infected machine stays connected means more shared folders, more servers and —what hurts most— more backups falling. The window to contain the damage is measured in minutes, not hours. That’s where it’s decided whether you open tomorrow or not.
The other enemy in that first hour is panic. The instinctive reaction —shut everything down, reboot servers, start deleting whatever looks infected, pay the ransom to get it over with quickly— is almost always the wrong one. Containing isn’t reacting fast; it’s reacting in the right order. A company that isolates with a cool head recovers from backup in two days. One that improvises on frayed nerves ends up with the incident spread wide, the evidence destroyed and no clean backup to fall back on.
Ransomware doesn’t punish technical failure; it punishes improvisation. Those with a written plan execute; those without one argue while the encryption spreads.
The right first steps, in order
This is the script for the first hour. Don’t improvise it: follow it exactly, from top to bottom.
- Isolate the affected machines from the network. Unplug the cable, turn off Wi-Fi, cut the VPN. The goal is to stop the spread immediately. Isolation comes first, always, before investigating anything.
- Don’t shut things down blindly. Disconnecting from the network is not the same as powering off cold. Shutting down wipes volatile information that helps you understand what happened and how they got in, and in some cases it even complicates data recovery. Isolate, but leave the machines running unless the person leading the incident tells you otherwise.
- Protect the backups right now. Before anything else, make sure the backups can’t be reached from the compromised network. If the ransomware gets to them, the conversation is over. Disconnect them or verify that they are isolated and immutable.
- Cut off remote access and privileged accounts. VPN, remote desktop, vendor access and administrator accounts. Whichever way they got in they can get in again, and often the attacker is still inside watching how you react.
- Preserve the evidence. Photograph the ransom note, note the time, don’t delete logs or encrypted files. That information is gold for understanding the scope, for the insurer and, if needed, for the police report.
- Activate the plan and put one person in charge. Someone coordinates, decides and communicates; everyone else executes. Alert your managed cybersecurity provider and start documenting what’s affected. In a crisis, five people deciding in parallel do more damage than the attack itself.
With this done, the fire is contained. Now it’s time to assess the scope calmly: what’s encrypted, what isn’t, and whether there are signs that data was also stolen —what’s known as double extortion— because that changes your legal obligations.
What NOT to do under any circumstances
Half of a good response is not making the mistakes that turn an incident into an irreversible disaster. These are the four that cost the most.
- Don’t pay blindly. Paying doesn’t guarantee you’ll get your data back —many decryptors fail or only work halfway—, it marks you as someone who pays and it funds the next attack. It’s the last option, never the first, and only after thoroughly assessing whether you can restore from backup.
- Don’t restore over the infected system. Recovering your data on a system that’s still compromised, or without closing the entry point, restarts the nightmare within hours. First you clean or reinstall; then you restore.
- Don’t hide it. Keeping the incident quiet so nobody finds out exposes you to penalties for failing to notify and destroys trust when it eventually comes out —and it will come out. Well-managed transparency protects you; silence makes it worse.
- Don’t delete logs or files. “Cleaning up” on your own destroys the evidence you need to understand the scope, comply with the law and collect on the insurance. Don’t touch the logs: they’re your best ally.
Notification and obligations: the legal clock is ticking too
While you contain and recover, there’s a second clock running that many people ignore until it’s too late. If the attack compromised personal data —of customers, employees or suppliers—, the GDPR requires you to notify the breach to the supervisory authority within 72 hours of becoming aware of it. It doesn’t wait until you’ve recovered the service and it’s not optional: failing to notify adds a fine on top of the disaster you already have.
And there are more fronts to handle in parallel, without leaving them for the end:
- Communication to those affected. If the breach poses a high risk to customers or employees, on top of the supervisory authority you have to inform them directly. Prepare a clear, honest message, not an empty statement.
- Notice to the insurer. If you have a cyber-risk policy, report it as soon as possible: many require immediate notification and give you access to a response team. Acting on your own can leave you without cover.
- Police report and authorities. Filing a report and alerting the reference channels such as the national cybersecurity authority creates an official record and gives you support. The documentation you preserved in the first hour is exactly what’s needed here.
Having identified in advance who drafts the notification, who talks to the insurer and who talks to the customers is what lets you meet these deadlines without stalling the technical recovery. Improvising it with the business at a standstill is the recipe for missing all three.
How MagicBoxDesk helps you: incident response and recovery from a clean backup
All of the above sounds simple written down in calm. At three in the morning, with the business down and the phone ringing, it isn’t. That’s why the greatest value isn’t having the plan in a PDF, but having someone on the other end who executes it with you. At MagicBoxDesk we build, maintain and trigger that response plan as a service, as part of your outsourced IT, with remote and on-site support across Spain.
- Incident response with a defined, rehearsed plan: who isolates, who decides, who gets alerted and in what order, so you act in minutes instead of improvising for days.
- Containment and scope analysis: we isolate what’s affected, preserve evidence and determine whether data was stolen, without destroying the information you’ll need later.
- Immutable, isolated backups, with restores tested regularly, so that when the moment comes there really is a clean copy to go back to.
- Recovery in the right order: identity and authentication first, then whatever bills or produces, then email and files, and the workstations last, reinstalled from a clean image.
- Support with legal obligations: breach notification on time, communication to the insurer and to those affected, with the paperwork in order.
- Closing the entry point before reconnecting, so the attack doesn’t start all over again the moment everything comes back up.
Ideally we should talk before the incident, not during. Preparing the plan, the backups and the access costs a fraction of what a ransom or two weeks of downtime costs, and it’s what turns a crisis into a rough moment. If you already have it on top of you, we’re here to help you contain and recover too.
At MagicBoxDesk we take care of your security and your response plan so you can focus on your business. Ask for a no-obligation quote and we’ll tell you what you really need so that the first hours of a ransomware attack work in your favour and not against you.



