Every ransomware incident is different, but the order of the first decisions rarely is. The timeline below shows where each phase usually sits. Treat the timings as a guide for planning a tabletop exercise, not a target you will always meet.
First hour
Confirm, isolate, mobilise
Ransomware is confirmed, affected hosts are isolated rather than switched off, the named team is called on an out-of-band channel and the insurer is told.
Hours 1–12
Contain and preserve
Compromised accounts are disabled, remote access is cut, backups are protected, and logs and a sample of encrypted files are preserved.
Hours 12–48
Scope and decide
The variant, entry point and affected systems are known. Backups are checked. If there is a ransom demand, legal and sanctions screening run before any decision on contact.
Days 2–7
Rebuild and restore
Identity is rebuilt, the way in is closed, and systems come back tier by tier with sign-off at each step.
Within 72 hours of awareness
Regulator decisions
If personal data may have been taken, the GDPR and UK GDPR clock for notifying the regulator is running. Other sector deadlines can be shorter.
Reporting duties depend on your sector and location, so confirm them with counsel. In the US, the Treasury’s Office of Foreign Assets Control warned in its September 2021 advisory that ransom payments to sanctioned persons can breach sanctions law, and that prompt reporting to law enforcement and cooperation count as mitigating factors. The Cyber Incident Reporting for Critical Infrastructure Act of 2022 will require covered entities to report ransom payments to CISA within 24 hours of paying and covered incidents within 72 hours, but those duties start only once CISA’s final rule takes effect, which had not happened as of October 2026. SEC registrants must disclose a material incident on Form 8-K within four business days of determining that it is material. HHS treats ransomware on systems holding electronic protected health information as a presumed HIPAA breach unless a low probability of compromise can be shown.
In the UK, the government confirmed in July 2025 that it will ban ransom payments by public sector bodies and regulated critical national infrastructure, require other organisations to notify the government before paying, and introduce mandatory reporting of ransomware attacks. The legislation had not been passed as of October 2026, so check the current position before relying on it. The ICO and NCSC have both said that paying a ransom does not protect the data or reduce regulatory penalties. In the EU, entities covered by NIS2 must send an early warning of a significant incident within 24 hours. Phase 7’s reporting tasks can be edited as these rules change.