By the time most organisations call an incident responder, the ransomware has usually already run. What happens in the first hour after that determines almost everything about how the rest of the incident goes — whether it's a contained, well-documented recovery, or a multi-week fire drill with a lawyer on every call.

Here's roughly how that first hour plays out on our retainer engagements.

Minute 0–10: Confirm and contain

The first job isn't investigation, it's containment. We isolate affected hosts from the network, disable the accounts or access paths being actively used, and confirm — quickly — whether this is genuinely still spreading or whether it's already run its course. Every minute spent debating instead of isolating is a minute the encryption process keeps running.

Minute 10–30: Stakeholder communication

In parallel, someone needs to be talking to leadership. Not with a full picture — there isn't one yet — but with what's known, what's being done, and what decisions need to be made in the next hour, like whether to take specific systems fully offline. Silence at this stage is what causes panic; a short, honest update every 20–30 minutes is what prevents it.

Minute 30–60: Evidence preservation and next steps

Once the immediate spread is contained, the priority shifts to preserving evidence before anything gets rebuilt or wiped — memory captures, relevant logs, and the initial access vector if it's identifiable. This is also when we start scoping what a safe recovery actually looks like, rather than restoring from backup straight back into the same unpatched entry point.

The organisations that recover fastest aren't the ones with no incidents. They're the ones who'd already rehearsed what the first hour looks like.

None of this works without a plan in place before the incident starts. Knowing who has authority to isolate a production system at 2am, and having that agreed in advance, is what turns a chaotic first hour into a contained one.