There’s a moment every SOC analyst knows — the split second between “this looks like a normal alert” and “this is ransomware.” Everything changes in that moment. The alert queue stops mattering. The coffee goes cold. What happens in the next fifteen minutes often determines whether an organization is dealing with one encrypted server or an entire network down for days.
This isn’t a theoretical checklist. It’s a walkthrough of what actually happens, minute by minute, when ransomware is confirmed — the decisions, the tradeoffs, and the reason speed matters more than almost anything else in this window.
Minute 0–2: Confirm It’s Real
The first job isn’t containment — it’s confirmation. A single alert about mass file encryption or an unusual ransom-note file being dropped could be a false positive, a misconfigured backup job, or a legitimate encryption tool behaving oddly. Analysts move fast but don’t skip this step, because isolating the wrong system on a false alarm costs trust and time later. The tell-tale signs — a spike in file-rename or file-modification events across multiple machines in a short window, unusual processes touching shared drives, or an actual ransom note appearing — are usually enough to confirm within a minute or two.
Minute 2–5: Isolate, Don’t Investigate Yet
Once ransomware is confirmed, the instinct to dig deeper has to wait. The immediate priority is stopping the spread — disconnecting affected machines from the network, disabling compromised accounts, and in more severe cases, segmenting whole network zones or pulling critical systems offline entirely. This is usually the most consequential decision made in the entire incident, and it’s made under real time pressure: isolate too little, and the encryption keeps spreading; isolate too aggressively, and you risk unnecessary business disruption on systems that were never actually touched.
Most mature teams have this step pre-planned rather than improvised — a documented isolation procedure that doesn’t require debate in the moment, because debate is exactly what costs the minutes that matter.
Minute 5–8: Loop In the Right People, Immediately
Ransomware isn’t a problem the SOC solves alone. Within minutes, the right people need to know: incident response leadership, IT operations, and depending on severity, legal and executive stakeholders. This isn’t about assigning blame or preparing a report — it’s about getting decision-makers moving in parallel rather than in sequence. Legal may need to start thinking about breach notification obligations. IT operations needs to know which systems are coming offline. Leadership needs enough information to make fast calls about business continuity, without yet knowing the full scope.
Minute 8–11: Start Scoping — Fast, Not Thorough
With spread contained and the right people looped in, the focus shifts to a fast, rough scope of the damage: which systems are affected, whether backups appear intact, and whether there are early indicators of data exfiltration in addition to encryption — a distinction that matters enormously, since many modern ransomware groups steal data before encrypting it as extra leverage. This early scoping is deliberately imperfect. The goal isn’t a full forensic picture yet; it’s enough situational awareness to guide the next set of decisions, especially around whether backups can be trusted for recovery.
Minute 11–13: Preserve Evidence Before Anything Gets Touched
It’s tempting to start cleaning up immediately, but a rushed team that starts wiping and rebuilding machines before preserving evidence can destroy information needed later — for the investigation, for law enforcement, for cyber insurance claims, and for understanding how the attacker got in in the first place. Wherever possible, affected systems are preserved in their current state (via snapshots, memory captures, or simply leaving isolated machines powered on but disconnected) before any remediation work begins.
Minute 13–15: Set Up the War Room
By the fifteen-minute mark, the goal is to have moved from chaos to a structured response: a dedicated incident channel or bridge line is stood up, a rough timeline of what’s known so far is documented, and clear ownership is assigned for the next phase — deeper forensic investigation, backup verification, communications planning, and the much longer work of eradication and recovery that’s just beginning. The first fifteen minutes don’t solve the incident. They set the conditions for everything that follows to go well or badly.
Why Those First Minutes Matter So Much
Ransomware response isn’t really won or lost in the days after an attack — it’s shaped enormously by what happens in this opening window. Teams that isolate fast limit the blast radius. Teams that loop in the right people early avoid decisions being made in silos. Teams that preserve evidence before rushing to rebuild keep options open that panicked teams accidentally close off.
None of this happens by improvising well under pressure alone — it happens because the organization rehearsed it beforehand. The teams that handle those first fifteen minutes calmly are, almost without exception, the ones who ran the tabletop exercise months earlier and already knew exactly who picks up the phone first.
This post is part of an ongoing look at real-world incident response. Up next: what happens in the hours after containment — backup verification, the exfiltration question, and the ransom-payment decision nobody wants to make.




Leave a Reply