Skip to main content

Cyber security articles

Ransomware in the first hour: what to do, what not to destroy

Practical first-hour ransomware actions for Australian organisations: isolate without panic, preserve evidence, and know which official reports come next.

The first hour of a ransomware incident is where evidence is lost, containment is delayed, and well-meaning staff pay or wipe things they cannot undo. This is not a playbook for every estate. It is a short list of actions that usually help, actions that usually harm, and the Australian reporting questions you will be asked later, when you can least afford to have destroyed the answers.

If anyone is in physical danger

Call Triple Zero (000). Industrial, hospital and building systems can turn a cyber incident into a safety incident. Everything below assumes people are safe enough for you to think about networks and disks.

Usually help

  • Isolate affected machines from the network if you can do it without a chaotic site-wide power cut.
  • Switch communications for the response to a channel you believe is clean, not the same estate that just displayed the ransom note.
  • Photograph or copy the ransom note, attacker email, Bitcoin address and any reference IDs. Those are evidence and negotiation artefacts, even if you do not intend to pay.
  • Leave powered-on systems in a known state where possible so memory and active sessions can be captured.
  • Start a simple timeline: who noticed what, at what time, on which host. Approximate times are better than none.

Usually harm

  • Paying immediately. Payment does not guarantee a key, does not remove the access path, and may create further reporting issues. ASD does not encourage payment.
  • Mass reimaging before anyone has collected logs, disk images or the sample.
  • Uploading the encryptor or a stolen-data sample to a public sandbox.
  • Resetting every password from an infected administrator workstation.
  • Negotiating from the compromised mail environment.

Australian reporting questions to expect

You do not need to complete these in the first hour, but you should not destroy the material they rely on.

  • ReportCyber: cybercrime reporting for individuals and businesses via cyber.gov.au.
  • OAIC notifiable data breaches: if personal information is involved, the Privacy Act scheme may apply. See OAIC NDB.
  • Agency and critical-infrastructure duties: government and some operators have additional reporting paths. Use your existing incident plan; do not invent one in the form on this website.

What to tell a specialist (and what not to paste into a website)

On Get incident help we ask for a safe contact, a broad impact category, timing, and whether an essential service or physical safety is involved. That is enough to call you back. Do not paste samples, patient lists, password dumps or OFFICIAL: Sensitive detail into the form.

After the first hour

Containment is not recovery. Recovery is not eradication. A clean restore from backup onto an estate the attacker can still enter is how incidents restart. The later work, malware analysis of the implant, closing the access path, and validating that restored systems are actually clean, is described on ransomware response and recovery.

Sources

Accountability

Published by Cybersecurity Engineering Pty Ltd, trading as MalwareAnalysis.app. This is general guidance, not advice about your incident. A named expert profile will be attached once approved for publication. Review this page again after 5 March 2027, or sooner if official ASD or OAIC guidance changes.

Related: Get incident help · Ransomware response service · Malware analysis.

Use the evidence in context

This article reflects understanding at its stated publication and review dates. It is general information, not advice about your specific incident, system or legal position.