Cybersecurity incident response and ransomware recovery concept

Guides & Blog · 2026-07-06 · eWEB TEC

Ransomware for a 10-Person Sydney Office: First 24 Hours

In the first 24 hours after ransomware, focus on containment, communication, clean recovery and identity — not heroic experiments on infected machines. For a small Northern Beaches or North Shore office, speed and calm process beat panic reinstalls.

Hour 0–1: contain

Hour 1–4: establish facts

Hour 4–24: recover and harden

Related: Microsoft 365 backup, DR one-pager, managed IT.

FAQ

Should we pay the ransom?

That is a legal, insurance and leadership decision. Technical priority is contain, assess backups, and restore cleanly — do not assume payment restores trust.

Is turning everything off correct?

Containment matters, but random power-offs can destroy forensic evidence and shared services. Use a short decision tree with your IT provider.

How do we reduce odds next time?

MFA, least privilege, tested M365 and file backups, patching, and phishing-resistant habits.

Need help containing or recovering?