We use cookies on this website.

By clicking "Accept," you agree to the storage of cookies on your device to improve your browsing experience, analyze site usage, and contribute to our marketing efforts. See our privacy policy for more information.

Cybersecurity

Ransomware: What Should You Do in the First 24 Hours?

Is a ransomware cyberattack underway? Checklist of actions from H+0 to H+24, ANSSI and CNIL contacts, should you pay the ransom, and how IT Systèmes responds in an emergency.

Ransomware: What Should You Do in the First 24 Hours?

Key Takeaways

  • Never turn off infected computers: doing so would destroy the digital evidence needed for the investigation and to file a complaint.
  • Isolate without shutting down: Unplug the network cable or turn off Wi-Fi. The ransomware is spreading across the network—every minute counts.
  • Do not pay the ransom: ANSSI’s official position. Paying the ransom does not guarantee that the data will be recovered, funds cybercrime, and may expose the company to penalties if the group is subject to sanctions.
  • Notify the CNIL within 72 hours if personal data has been compromised—or face GDPR penalties of up to 4% of global revenue.
  • File a report within 72 hours: This is required to activate your cyber insurance coverage (LOPMI Act of 2023).
  • Call 17cyber or contact cybermalveillance.gouv.fr to be connected with an approved security incident response provider (PRIS).
  • IT Systèmes can deploy a crisis response team within hours for small and medium-sized businesses under an Hypergérance or MSP contract.

H+0 — The First 30 Minutes: Stopping the Spread

Ransomware encrypts your data and spreads across the network at a rate measured in minutes. Every additional workstation affected increases the complexity of the remediation process and the cost of the incident.

Immediate actions, in this order:

1. Physically isolate the suspect machines. Unplug the Ethernet cable. Disable Wi-Fi (using the physical button or Device Manager, not through Windows—the system may already be compromised). Do not shut down the machines: the encryption keys may be stored in RAM and are useful for the investigation.

2. Disable shared access. If you have a file server or NAS, disconnect it from the network immediately. Ransomware primarily targets shared network drives.

3. Do not delete anything, and do not reinstall anything. Any rash action can destroy evidence or complicate the investigation. The "format and start over" reflex is the worst possible reaction—it erases the attacker’s traces and makes it impossible to understand how they gained access.

4. Take photos of the ransom notes. Use a phone. These photos are used for the investigation, to file a police report, and for insurance purposes.

5. Notify management and the IT manager (whether in-house or a vendor). If you have an MSP or MDR contract, contact your vendor immediately—this is exactly the kind of situation you’re paying for this service to handle.

H+0 to H+2 — Assess the extent of the damage

Once the spread has been stopped, the goal is to quickly assess the extent of the damage.

Questions to be answered as a priority:

  • How many computers have been encrypted or are displaying the ransom note?
  • Are the servers compromised? Are the backups accessible, or are they encrypted as well?
  • Is there any personal data (customers, employees, partners) among the data that may have been leaked?
  • Is the attacker still active in the system? (Ransomware groups often remain active for several weeks before encrypting data.)

This assessment determines the following decisions: who to notify, which service provider to contact, and whether the backups will allow for a quick recovery.

Do not attempt to decrypt files on your own without expertise. There are tools available online, but most are ineffective or even dangerous (some are malware themselves).

H+2 to H+6 — Mandatory Legal Notifications

This is the stage where legal obligations come into play. Failing to meet these deadlines exposes the company to penalties unrelated to the attack itself.

Table of Mandatory Notifications

Organization Deadline Who is affected? How to
CNIL 72 hoursafter discovery Any company that processespersonal data—Virtually all of them notifications.cnil.fr
ANSSI
24 hours 72 hours
Initial notification / report
NIS2 Entities:Significant or Critical cyber.gouv.fr/in-case-of-an-incident
Police / Gendarmerie 72 hours maxAs soon as possible Allbusinesses: Required for insurance reporting Local police station or precinct
Cyber Insurance Provider 48–72 hoursAs specified in the contract Companies with cyber insurance Contract Emergency Number
AMF / ACPR and other regulators By thresholdMateriality threshold Financial Institutions DORA Relevant regulatory authority

An important point regarding the CNIL: notification is only required if personal data has been compromised (accessed, copied, modified, or destroyed). In practice, ransomware that encrypts your files has likely already exfiltrated data. Therefore, assume that you must notify the CNIL and seek advice if you have any doubts.

Key point regarding the claim: If a claim is not filed within 72 hours, most cyber insurance providers will refuse to cover the payment of any ransom or remediation costs. This is a requirement under the LOPMI law (January 2023).

Contact cybermalveillance.gouv.fr

For small and medium-sized businesses that do not have a contracted incident response provider, cybermalveillance.gouv.fr connects them with ANSSI-approved PRIS (Security Incident Response Providers) service providers. You can also call 17cyber, the national helpline for victims of cyberattacks.

Regional CSIRTs (Regional Cyber Incident Response Centers) provide free support to small and medium-sized businesses and mid-sized companies during the initial hours; they can help assess the nature of the incident and refer them to the appropriate service providers.

Should You Pay the Ransom? The Clear Answer

That's the question every leader asks themselves in the first few hours. Here's what the facts clearly show.

Argument for Paying | Reality: “I’ll get my data back.” The actual recovery rate is around 50% even after payment. The decryption keys provided are often incomplete or faulty. “It’s faster.” Remediation is necessary in all cases: even with the key, you must identify how the attacker gained access and patch the vulnerability."It’s covered by insurance"Since the LOPMI Act (2023), insurers can only pay out if a police report was filed within 72 hours. And some policies exclude ransom payments.""Otherwise, my data will be published"Ransomware groups publish the data in 40% of cases, even after payment. Paying does not guarantee confidentiality.

ANSSI's official position: Do not pay. Paying directly funds criminal groups, encourages future attacks, and may expose the company to sanctions if the group is listed on international sanctions lists (U.S. OFAC, EU regulations).

The real question isn't "to pay or not to pay," but "do you have working backups?" If your backups are intact and have been tested, restoring your data is always preferable to paying the ransom. If your backups are also encrypted—which happens when the attacker had access to the network for several weeks before encrypting the data—the situation is more complex and requires expert advice.

H+6 to H+24 — Remediation and Communication

Technical Remediation

Remediation does not begin until after the initial investigation. It follows this sequence:

Identifying the entry point: How did the attacker gain access? Phishing, a VPN without MFA, an exposed RDP, a compromised service provider, an unpatched vulnerability? Without an answer to this question, recovery is pointless—the attacker will return.

Cleaning or rebuilding: Depending on the extent of the issue, either restoring from clean backups or completely rebuilding the systems from scratch. Rebuilding takes longer but is safer; restoring from a compromised image could reintroduce the backdoor.

Verifying backups before restoration: Make sure the backup itself isn't infected. Ransomware groups often target backups first.

Crisis Communication

Communicate early, even if you have limited information. Silence is interpreted as a cover-up by your customers, partners, and employees.

Internally: Inform employees not to use the affected systems, to report any suspicious activity on their workstations, and not to speak to the press.

To customers and partners: If data concerning them may be involved, inform them promptly and clearly. Transparent communication protects the relationship better than a cover-up that is discovered later.

To the press: Prepare a brief, factual statement. Do not speculate on the cause or extent of the incident until the investigation is well underway.

The Role of IT Systems in a Ransomware Crisis

For SMEs under contract Hypergérance or MSP from IT Systèmes, the crisis protocol is activated as soon as the first call is received:

Proactive Detection: The HelpyBot platform continuously monitors for abnormal behavior (massive file encryption, unusual connections, antivirus deactivation). In most cases, an alert is triggered before the user even notices anything.

Automatic isolation: Using Microsoft Defender for Endpoint, IT Systèmes can isolate a workstation from the network in just a few seconds from the administration console, without the need for physical on-site intervention.

Crisis Response Team: IT Systems engineers coordinate the initial investigation, communication with ANSSI and CNIL as needed, and recovery from supervised backups.

Post-Incident Recovery: IT Systèmes supports the recovery of the information system and the strengthening of access controls (MFA, Conditional Access), and the implementation of a business continuity plan to prevent the same attack from succeeding a second time.

For small and medium-sized businesses without a pre-existing contract, IT Systèmes can provide emergency support, but the turnaround times and costs are significantly higher than with an active MSP contract. The cybersecurity training for your teams is also part of prevention: 82% of ransomware attacks enter via phishing, and a trained employee is the first line of defense.

FAQ — Ransomware and Crisis Management

Should you shut down computers during a ransomware attack? No. This is one of the most common mistakes. Encryption keys may reside in RAM and are valuable for investigation and, in some cases, data recovery. Shutting them down also destroys in-memory logs that are useful for forensic analysis. The correct course of action is to isolate the device from the network (by unplugging the cable or disabling Wi-Fi) without turning it off.

Does ransomware spread via email or internal messaging systems? Not directly. Ransomware that has encrypted a computer does not send itself via email. However, it actively spreads to network shares accessible from the infected machine (network drives, NAS devices, file servers). If it is running with administrator privileges, it can also spread laterally to other computers using network exploitation techniques (SMB, RDP).

How long does it take to recover from a ransomware attack for an SME? Between 3 days and 3 weeks, depending on the extent of the damage, the availability of backups, and the complexity of the IT system. Restoring data from clean backups takes 24 to 72 hours for an SME with 20–50 workstations. A complete recovery (if the backups are also compromised) can take more than 2 weeks. Without a specialized service provider, the time required doubles or triples.

Does cyber insurance reimburse ransom payments? Since the LOPMI Act of January 24, 2023, the insurer may only reimburse a ransom payment if the company filed a police report within 72 hours of becoming aware of the attack. Some policies completely exclude reimbursement of ransom payments. Read your cyber insurance policy before you find yourself in a crisis situation, and keep your insurer’s emergency number in an offline document.

Should you call the police if you’re hit by ransomware? Yes, and quickly. Filing a police report is required to trigger insurance coverage and serves as legal proof of the incident. Go to the nearest police station or gendarmerie post. You can also file a report online through the cybercrime reporting portal if your department has enabled it. You can simultaneously report the incident on cybermalveillance.gouv.fr.

Our backups are also encrypted—so what should we do? This is the most challenging scenario. Ransomware groups prioritize targeting backups to maximize the pressure. If your local and cloud backups are compromised, immediately contact an ANSSI-certified PRIS service provider (via cybermalveillance.gouv.fr). Decryption tools exist for certain ransomware families; the website nomoreransom.org lists the decryption keys available for free. Do not pay until you have checked this resource.

How can you prevent a second attack after remediation? The attacker gained access to your network. They mapped your systems and may have left backdoors behind. Remediation must include the following: identifying and patching the initial entry point, resetting all passwords (user and service accounts), enabling MFA for all access points, verifying admin accounts and deleting accounts created by the attacker, and deploying or strengthening EDR. Without these steps, a second attack within 3 months is statistically likely.

See also

Our latest articles

See more
software
Development & automation

"I'm afraid to install software"

In 1996, I took my first steps in computing on an Excel spreadsheet where I filed cheat codes for my favorite video games. 🕹️Le the beginning of a passion for office tools (to each his own 😅 ). There were 3,000 machines connected to the internet! 😶 But what happened next?
July 3, 2026
fishing
Cybersecurity

Phishing 2026: Definition, Examples, and Protection for Small and Medium-Sized Businesses (Comprehensive Guide)

Spear phishing, BEC, voice deepfakes: why training alone isn’t enough, the true cost of an incident (€275,000), and the security measures that will work in 2026
June 26, 2026
backup-vs-retention
Cloud & infrastructure

Comparing backup VS retention

Backup VS retention: here's the match everyone's been waiting for!!!! 🥊 (okai not at all but I needed a catchy title..🤫)
July 3, 2026