What Actually Happens in the First 60 Seconds of a Ransomware Attack
Most companies picture ransomware as a slow-building problem. In reality, the encryption itself often takes minutes, which means the first sixty seconds of detection determine almost everything about how bad it gets.
Most people picture a ransomware attack as something that unfolds slowly, an odd email, then a strange file, then eventually a ransom note days later. In reality, once ransomware executes, it can encrypt a meaningful share of a company’s files within minutes. The window that actually matters is the first sixty seconds after detection, not the hours or days before.
Second 0: something triggers detection
Detection usually comes from one of three places: an endpoint detection tool flags unusual file activity, a user notices files becoming inaccessible and reports it, or a backup job fails unexpectedly and someone investigates why. Of these three, automated detection is dramatically faster than the other two, which is the entire argument for having active endpoint monitoring rather than relying on a user to notice something is wrong.
Seconds 0-15: isolate, don’t investigate
The instinct of a well-trained response is to isolate the affected machine from the network immediately, before spending time understanding what’s happening. Every second a compromised machine stays connected to the network is a second ransomware has to spread to file shares, connected drives, and other machines. Investigation matters, but it happens after isolation, not instead of it.
Seconds 15-45: confirm the blast radius
Once the initial machine is isolated, the next step is determining what else might be affected: which network shares that machine had access to, whether the compromise appears to be a single endpoint or has already reached a server, and whether backup systems are still intact and unreachable by the same attack. This is where having current, tested backups completely changes the outcome, a company with clean backups is negotiating from a position of “we can restore,” not “we have to pay.”
Seconds 45-60: activate the actual response plan
This only works if a response plan already exists in writing before the attack happens: who gets called first, who has authority to take systems offline, who talks to law enforcement, and who talks to affected customers or partners if data exposure is a possibility. Companies without a written plan lose critical time in the first hour improvising decisions that should have been made calmly, in advance, when nothing was on fire.
What actually determines the outcome after that first minute
The first sixty seconds set the trajectory, but three things determine how the incident actually resolves: how current and isolated your backups are, whether your team practiced the response plan before they needed it, and how quickly a security team, internal or managed, can move from detection to full containment. Companies that have never rehearsed an incident response plan typically take three to five times longer to contain an active attack than companies that have run through the scenario even once.
The uncomfortable truth about “it won’t happen to us”
Ransomware groups increasingly target small and mid-market companies specifically because they’re more likely to have gaps in monitoring and no formal incident response plan, not because they’re more valuable targets. The size of your company has very little to do with whether you’re a target. It has everything to do with how fast you can respond once you are.
If you don’t know, right now, what your company’s first sixty seconds would actually look like, that’s the gap worth closing before it gets tested for real.
Want us to look at this for you?
Get a free IT assessment, no obligation.