CyberSafe LogoCyberSafe
← Blog

Guide · 18 Jun 2026 · 9 min

Ransomware: the first 72 hours if you do not have a SOC

Contain, preserve, communicate, recover. In that order. Print the checklist before you need it.

Hour 0–4: isolate affected segments and identity. Do not wipe yet. Do not pay from the same machine that is encrypted. Call your insurer and your IR path — retainer or CyberSafe contact — before you negotiate with a leak site.

Hour 4–24: preserve logs, snapshots, and mailbox evidence. Name a single commander. Legal and comms get facts, not hope. Assume email is hostile if the phish started there.

Hour 24–72: restore from backups you have actually tested. Rebuild identity before you rebuild file shares. Tell customers only what you can verify. Then run a post-incident that names the control that would have shortened this.

Download the printable checklist in Resources. If you are in it now, skip the essay and call +264 81 390 6697.

Need this applied to your estate?

Briefings are free to read. Hunts, retainers, and assessments are scoped work.

Talk to CyberSafe