The first hour decides how much you lose. The goal is not to fix everything. It is to stop the spread, protect what you can still recover from, and get the right people involved before anyone starts cleaning up.
The first sixty minutes
- Disconnect affected computers from the network. Unplug the cable or turn off Wi-Fi, but do not power them off unless told to
- Call your IT provider first, then your cyber insurance contact if you have one
- Check that your backups are offline or out of reach, and stop any job that could overwrite them
- Change passwords and end active sessions for admin accounts, from a device you know is clean
- Write down what you see: ransom notes, file names, times, and who noticed first
What not to do
- Do not wipe or reinstall machines yet. You may need them to find out how the attacker got in
- Do not contact the attacker or pay before getting advice
- Do not restore from backup until you know the attacker is out, or they may encrypt it again
The fastest recoveries happen at companies that had already tested a restore and knew who to call.
Preparation is what makes the first hour manageable. Gravity builds cybersecurity and backup and disaster recovery so the plan exists before the bad day.