Cyber AssessValydex™by iFeelTech
Implementation Guide

Ransomware First 30 Minutes Playbook (2026)

Critical containment and communication decisions for SMB incident response

Practical crisis checklist for the first 30 minutes of a ransomware incident, including containment, reporting, evidence handling, and controlled recovery setup.

Last updated: September 24, 2026
3 minute read

If ransomware is suspected now

  • Isolate affected systems from the network to limit spread; do not wait for a perfect diagnosis.
  • Activate your incident lead and technical responder through a trusted contact channel.
  • Preserve the timeline and available evidence; coordinate disruptive changes.
  • Protect backups and identity systems, then scope recovery before restoring.

Last updated: September 24, 2026

The first 30 minutes is a decision window, not a guaranteed containment deadline. The actual sequence depends on what is affected and who can respond. CISA's ransomware response checklist starts by identifying and isolating impacted systems, including network-level isolation when many systems are involved. Follow your organization's incident plan and get qualified help when the scope is unclear.

First decision: isolate what you know is affected

Disconnect an affected device from Wi-Fi and Ethernet or ask IT to isolate it centrally. If multiple devices or shared storage are involved, the responder may need to take a segment offline. Tell staff not to reconnect devices or use the same credentials on another system. Avoid wiping, reinstalling or casually powering down affected machines; your responder may need volatile or disk evidence. If isolation is impossible, ask the technical incident lead for the least damaging containment step.

Second decision: activate the right people

Contact the incident lead, IT provider or security responder, operations owner and the person responsible for backups. Use phone numbers or channels already documented outside the affected email tenant. Assign one person to record times, systems, actions and decisions. Notify the bank immediately if payment systems or transfers may be involved. Contact the insurer and legal adviser where relevant; they can help determine contractual and regulatory obligations. The full incident-response guide includes roles and a runbook structure.

Third decision: protect recovery and evidence

The technical lead identifies affected devices, accounts, cloud drives and backup repositories. Check whether backup credentials or consoles might also be compromised, and restrict access before restoring. Save ransom notes, relevant logs, alerts and user reports according to the responder's instructions. Do not assume a backup is safe or complete simply because its dashboard is green. Test the required restore path in a clean environment before reconnecting production.

Do nowWait for a scoped response decision
Isolate known affected devices and notify respondersWipe or reimage systems
Record the earliest alert and affected servicesRestore over possibly compromised production
Protect backup and administrator accessMake payment or public statements
Use trusted contacts for bank, insurer and specialist helpPromise a recovery time before testing

Reporting and recovery

The FBI Internet Crime Complaint Center accepts cybercrime reports. Follow the advice of your responder, insurer and legal adviser for any other reporting duties; timing and scope depend on the incident and affected data. After containment, document the entry route, remove persistence, reset affected credentials, restore from validated backups and monitor for recurrence. NIST SP 800-61 Rev. 3 places response and recovery within ongoing risk management, including lessons learned.

A printed copy helps

Keep incident contacts and this first-response sequence available outside the systems that may be unavailable. Practice the decisions before an incident using the 90-day roadmap.

Sources checked September 24, 2026: CISA StopRansomware Guide, NIST SP 800-61r3, and FBI IC3. This page is general incident guidance, not a substitute for a responder's advice on a live event.