Guide · 18 Jun 2026 · 9 min
Ransomware: the first 72 hours if you do not have a SOC
Contain, preserve, communicate, recover. In that order. Print the checklist before you need it.

Hour 0–4: isolate affected segments and identity. Do not wipe yet. Do not pay from the same machine that is encrypted. Call your insurer and your IR path — retainer or CyberSafe contact — before you negotiate with a leak site.
Hour 4–24: preserve logs, snapshots, and mailbox evidence. Name a single commander. Legal and comms get facts, not hope. Assume email is hostile if the phish started there.
Hour 24–72: restore from backups you have actually tested. Rebuild identity before you rebuild file shares. Tell customers only what you can verify. Then run a post-incident that names the control that would have shortened this.
Download the printable checklist in Resources. If you are in it now, skip the essay and call +264 81 390 6697.
