← All articles

Ransomware: the first 72 hours

One Monday morning, the files won't open and a ransom note fills every screen. What happens in the next 72 hours decides almost everything: the bill, the length of the outage, the legal obligations — and sometimes the survival of the business. Here's the hour-by-hour playbook, and the moves that make the difference.

Ransomware: the first 72 hours

Monday, 6:47 a.m. The first employee into the office boots up their machine: every file on the server has a strange extension and won't open. On the Windows desktop, a text file: "Your data has been encrypted." The reception printer is spitting out the same note, page after page. At 7:15, the president's phone rings.

Quebec SMBs live this scenario every week. The Canadian Centre for Cyber Security ranks ransomware as the country's top cybercrime threat, and according to Sophos' annual study of 3,400 affected organizations, the recovery bill alone — before anyone even mentions a ransom — averages $1.53 million USD. But that figure hides a more useful truth: the gap between companies that recover in days and those that lose months is carved out almost entirely in the first 72 hours.

Here's what happens in them, hour by hour.

Hour 0: understand what just happened

First thing to know: the encryption you discovered this morning isn't the beginning of the attack — it's the final step. The intruder has typically been inside your systems for days, sometimes weeks: mapping the network, locating the backups, and often copying your data out before locking everything down. That's "double extortion": pay to decrypt, then pay again so your stolen data isn't published.

That reality changes everything about the response: you're not dealing with a corrupted file. You're managing a crime scene that's still warm.

Hours 0 to 2: the three moves that save you

Isolate — without powering off. Unplug network cables from affected machines, kill the Wi-Fi, cut off the compromised segments — ransomware spreads from machine to machine as long as it has a path. But resist the urge to shut computers down: their memory holds traces that specialists will use to understand the attack, and sometimes to recover encryption keys. Off the network, but powered on.

Get off compromised channels. If the attacker had access to your systems, they may still be reading your email. All crisis coordination happens by phone or on a messaging platform outside company systems — not in the Teams or Outlook they might be watching.

Call for help immediately. Your IT provider or incident-response team first, and your insurer very early: most cyber insurance policies require prompt notice and impose their own experts (forensic accountants, specialized counsel, negotiators). Acting without them can jeopardize your coverage. It's also the moment to check one thing, just one: are your backups intact? Attackers target them first — which is exactly why offline backups exist .

And the two classic first-hours mistakes: restoring immediately over infected machines (you destroy evidence and sometimes restore the backdoor along with the data), and replying to the ransom note yourself to "buy time." Both get expensive.

The question everyone asks: do we pay?

Canada's official position is clear: Get Cyber Safe, the federal government's awareness program, states that best practice is to never pay. Paying guarantees nothing — not a working decryption key, not the destruction of stolen data, which remains in criminal hands. And a company that pays marks itself as a company that pays.

On the ground, the reality is more nuanced: about half of affected organizations end up paying, according to Sophos, and those who do negotiate — payers hand over on average 85% of the initial demand. It's a heavy business decision, made with your insurer and legal counsel, never alone, never in the panic of the first night.

But the real answer to that question isn't given during the crisis. It was decided beforehand: a company with clean, isolated, tested backups almost never has to ask it.

Day 1: the obligations nobody feels like handling

While the technical response gets organized, a second clock is ticking: the legal one.

In Quebec, if personal information — clients, employees, suppliers — was accessed, copied or lost, you are dealing with a confidentiality incident under Law 25. Three obligations kick in: take reasonable measures to limit the harm, assess whether the incident presents a risk of serious injury, and record it in the incident register every business must keep — even when the risk isn't deemed serious. If the risk is serious — and ransomware with data theft almost always is — you must notify the Commission d'accès à l'information and the affected individuals. The law doesn't set a deadline in hours: it requires acting "with diligence," which in practice is measured in hours and days, not weeks. The penalties on the books run into the millions; improvisation here costs more than preparation.

You also need to report the attack to the authorities: your local police service, the Canadian Anti-Fraud Centre and the Canadian Centre for Cyber Security. This isn't empty paperwork — these reports feed investigations and, in some cases, unlock access to known decryption tools.

Days 2 and 3: rebuild on solid ground

Restoration starts only once the experts have answered two questions: how did the attacker get in, and are they still there? Restoring before that is reopening the store with the burglar still hiding in the back room.

Then, in order: rebuild critical systems from clean backups, reset every password, turn on multi-factor authentication everywhere it was missing, and seal the entry point — in a third of cases, a known but unpatched vulnerability, which includes systems that no longer receive patches at all . That's exactly the sequence a disaster recovery plan puts in writing — before you need it.

Sophos' numbers show what's at stake: 53% of affected organizations fully recover within a week — but 18% take more than a month. The difference between the two groups is rarely luck.

The 72 hours are won in advance

Everything above becomes ten times simpler when five things already exist: offline backups tested regularly, a printed incident-response plan (the PDF on the server will be encrypted with everything else), the call list — insurer, IT provider, lawyer — reachable without a computer, multi-factor authentication on every access, and up-to-date systems. Nothing exotic: it's the basics, actually executed. Encouragingly, 44% of attacks are now stopped before encryption even happens at organizations equipped to detect them — a record.

The question that remains is the Monday-morning one, 7:15 a.m., when the phone rings: will the person who answers know what to do in the next ten minutes — or will they be searching for a phone number in a system that was just encrypted?

At MMO Techno, we help Quebec SMBs answer that question before it gets asked: managed and tested backups, an incident-response plan, monitoring that catches the intruder before the encryption — and a team that picks up when it happens for real. If your crisis plan amounts to a prayer, let's talk this week .

An IT project or a question?

Talk to an MMO Techno expert. We'll give you a clear, fast answer.

Contact us