
Ransomware Response: 24-Hour Executive Playbook
Cybersecurity, Crisis Leadership, Ransomware Response
Ransomware Just Hit Your Business: A 24-Hour Executive Playbook You Can’t Afford to Get Wrong
You have one chance to handle this correctly. This step-by-step playbook shows you exactly what to do in the first 24 hours after a ransomware attack is discovered—written for CEOs, owners, and COOs, not your IT team.
The Moment You Hear the Words “We’ve Been Hit”
The first minutes after a ransomware attack are disorienting. Systems are locked, staff are confused, and your phone is buzzing with questions you can’t yet answer. You will feel pressure—from your team, from your own fear, and possibly from the attackers’ countdown clock—to “do something” immediately.
This is exactly when leaders make their most expensive mistakes. Paying too quickly. Powering down the wrong systems. Letting well-meaning staff “try things” before counsel or insurance are involved. Saying the wrong thing in an all-hands email that later appears in court or in the press.
You have one chance to handle this correctly. The following 24-hour playbook is designed specifically for executives—not technical responders—so you can make strong decisions under pressure, protect your company’s legal and financial position, and give your team the calm, confident leadership they need from you.
📌 Key Takeaway: Your role is not to “fix the computers.” Your role is to control decisions, communication, and risk while experts handle the technical work.
Hour 0–1: The Three Non‑Negotiable Decisions You Must Make First
1. Do Not Pay the Ransom (Yet)
Attackers often design their messages to provoke panic: countdown timers, threats to leak data, or warnings that your business will “never recover” if you don’t pay immediately. As the decision-maker, your first rule is simple: do not authorize any payment or negotiation before you have legal, insurance, and technical input.
Paying too early may violate sanctions, void insurance coverage, or encourage further attacks.
In many cases, you may be able to restore from backups or partially resume operations without paying at all.
Even if you ultimately decide to negotiate, doing so without specialist support is risky and unnecessary.
⚠️ Warning: An employee quietly paying a ransom with a company card to “save the day” can create legal, regulatory, and insurance nightmares. Make it clear: no one is authorized to pay or contact attackers without executive and legal approval.
2. Isolate Affected Systems—But Do Not Power Them Off
Your IT team’s instinct may be to shut everything down. That feels safe, but it can destroy critical forensic evidence and complicate recovery. The instruction you want to give is: “Isolate, don’t power off.”
Direct IT to disconnect affected machines and servers from the network (physically unplug network cables or disable Wi‑Fi), but keep them powered on unless outside counsel or your incident response firm says otherwise.
Instruct staff not to plug in external drives or personal devices to “try to save files.” That can spread the infection and complicate cleanup.
You do not need to manage the technical details, but you must set the boundary: no large-scale system changes until counsel and insurance are engaged.
3. Call Counsel and Insurance Before Any Major Technical Action
This is the single most important executive move in hour one: loop in your outside counsel and cyber insurance carrier before you authorize forensic work, negotiations, or public statements. The order matters, because it affects privilege, coverage, and your options later.
Contact outside counsel (ideally with cyber/breach experience). Ask them to direct the incident response under attorney–client privilege. They may have pre-vetted forensic and negotiation firms they can bring in quickly.
Notify your cyber insurance carrier or broker. Most policies require prompt notice and may specify approved vendors. Acting without them can reduce or eliminate coverage for response costs, ransom payments, and business interruption losses.
Only then authorize deep technical work. Once counsel and insurance are aligned, green‑light the forensic team to investigate, contain, and plan recovery in coordination with your internal IT staff.
💡 Pro Tip: Store your counsel’s and carrier’s 24/7 breach hotlines in both your phone and a printed incident response binder. You may not have access to email or shared drives when you need them most.
Hour 1–3: Communicating Internally Without Causing Panic
Once your immediate decisions are underway, eyes will turn to you for answers. How you communicate in these first hours sets the tone for the entire response. Your goals are to: maintain trust, prevent rumors, and keep people focused on what they can control.
Who Needs to Know Right Away
Executive leadership team: They need situational awareness to coordinate operations, finance, HR, and communications. Keep this group small and disciplined in messaging.
IT and security leads: They will work directly with external responders; ensure they understand the “isolate, don’t power off” directive and the chain of command through counsel and insurance.
Key operational owners: Leaders responsible for customer service, manufacturing, logistics, or other critical functions need to prepare for disruptions and manual workarounds.
What to Say to Your Team (and What to Avoid)
You do not need all the answers to communicate effectively. In fact, over‑promising or speculating can damage credibility later. A strong initial internal message should be: clear, calm, and honest about what you know and what you don’t.
Consider a short, company-wide message along these lines (reviewed by counsel first):
“Earlier today, we identified a cybersecurity incident that is affecting some of our systems. We are working with external experts and our legal and insurance partners to understand the scope and restore operations safely. For now, please do not attempt to restart or ‘fix’ any affected systems on your own. We will share specific instructions and updates as we learn more. Our priorities are protecting our people, our customers, and the long‑term health of the business. Thank you for your patience and professionalism as we work through this.”
Avoid language that:
Minimizes the incident (“Just a small IT glitch”)—you may need to revise this later, eroding trust.
Assigns blame (“This happened because…”) before the facts are known.
Promises specific timelines for full recovery when you do not yet have a forensic assessment.
💡 Pro Tip: Designate a single internal communication channel (for example, a specific email alias or messaging channel) for official updates. Ask managers not to “fill in the gaps” with their own interpretations.
Supporting Your People While Systems Are Down
Ransomware incidents are stressful for employees. They worry about job security, customer reactions, and whether they did something wrong. Your job is to provide psychological safety while maintaining operational discipline:
Acknowledge the disruption and thank people for their flexibility and professionalism.
Give clear, practical instructions: what work can continue, what should pause, and where to report issues or suspicious activity.
Remind staff that the goal is to protect the business and its stakeholders, not to assign blame. Forensic experts will handle root‑cause analysis later.
Hour 3–8: When and How to Involve Law Enforcement
Many leaders hesitate to involve law enforcement, worried it will slow things down or invite unwanted scrutiny. In reality, agencies like the FBI or national cybercrime units can be valuable partners—and your regulators or insurers may expect that you notify them, especially if sensitive data is involved.
Coordinate Through Counsel, Not on Your Own
As the executive, you should not be the one cold‑calling law enforcement. Instead: work through your outside counsel and, if applicable, your incident response firm. They understand what information is helpful, how to preserve privilege, and how to avoid making statements that could be misunderstood later.
Counsel can advise whether your situation triggers any specific legal reporting obligations (for example, sector‑specific rules in healthcare, finance, or critical infrastructure).
Law enforcement may have intelligence on the ransomware group you’re dealing with, including whether paying them would violate sanctions or be technically pointless.
What to Expect From Law Enforcement Involvement
Law enforcement is unlikely to “solve” your incident in real time, but they can:
Provide guidance on whether the group is known, active, and associated with sanctioned entities.
Share best practices for evidence preservation and victim support resources.
Demonstrate to regulators, boards, and customers that you treated the event as a serious crime, not a private IT issue.
📌 Key Takeaway: Law enforcement involvement is less about dramatic raids and more about responsible governance and compliance. Let counsel lead those conversations.
Hour 3–8: What Your Cyber Insurance Carrier Needs in the First Hours
Cyber insurance can be the difference between a painful incident and a business‑ending one. But coverage is not automatic. In the first hours, your carrier or broker will want specific information to open a claim and deploy their resources. As the executive sponsor, your job is to ensure they get what they need and that your team follows policy requirements.
Typical Initial Information Requests
Basic incident description: When the issue was first detected, what systems are affected, and what the visible symptoms are (for example, ransom note on screens, encrypted files, systems unavailable).
Initial containment steps: High‑level actions taken so far (such as isolating systems), especially anything done before you contacted the carrier.
Suspected data impact: Whether systems with personal, financial, or health data appear to be affected, even if details are not yet confirmed.
They may also ask for copies of your incident response plan, key vendor contacts, or recent security assessments. You do not need to have everything at your fingertips, but you should designate a single point of contact—often your CFO, COO, or risk manager—to coordinate with the carrier and keep you updated.
Why Following Their Playbook Matters
Many policies require you to use approved vendors for forensics, breach counsel, and negotiation. Going off‑panel without permission can reduce reimbursement or void coverage entirely.
Carriers often have pre‑negotiated rates and established relationships with incident response firms, saving you time and money when every hour counts.
They can advise on documentation needed to support business interruption claims, such as detailed logs of downtime, lost revenue, and extra expenses.
💡 Pro Tip: Ask your carrier early: “What do you need from us today to protect coverage?” Then assign someone to track that checklist and report back to you twice a day.
Hour 8–24: Why Public Disclosure Timing Matters More Than You Think
At some point, word will start to leak: customers notice systems are down, employees talk, suppliers experience delays. You may feel pressure to “get ahead of the story” with a public statement. At the same time, regulators and contracts may impose specific notification deadlines if personal or regulated data is involved.
Balancing Speed, Accuracy, and Legal Risk
Public disclosure timing is a strategic decision that should be made jointly by you, outside counsel, and (if applicable) your communications team and board. The risks of moving too fast or too slow are real:
Too fast: You may share inaccurate information about what was accessed, who is affected, or how long recovery will take. Corrections later can look like backtracking or cover‑ups, damaging trust and inviting litigation.
Too slow: Stakeholders may feel misled, regulators may see delayed notification as negligence, and the narrative may be shaped by rumors rather than facts.
Principles for Effective Public Communication
Coordinate with counsel and insurers. Ensure your statements do not contradict legal positions or policy requirements and that they reflect what is known from forensics at that time.
Focus on action and care. Emphasize that you are working with experts, prioritizing the security of data, and supporting affected parties, rather than dwelling on technical details or blame.
Avoid naming the attacker or sharing negotiation details. Publicly discussing ransom demands or your willingness to pay can complicate negotiations and encourage copycat attacks.
📌 Key Takeaway: Public disclosure is not a one‑time press release; it is an evolving narrative. Start with what you know, commit to updates, and let facts—not speculation—drive your message.
The Three Biggest Mistakes Leaders Make in Hour One
Even seasoned executives can stumble in the chaos of a ransomware event. Understanding the most common early mistakes can help you avoid turning a bad day into a catastrophic one.
Mistake #1: Authorizing Payment Before You Understand Your Options
Under pressure, some leaders see paying the ransom as the “fastest way back to normal.” In reality, early payment can:
Violate sanctions or anti‑money‑laundering rules if the group is on a prohibited list.
Encourage attackers to hit you again, knowing you will pay quickly.
Fail to restore all systems or prevent data leaks; there is no guaranteed “reset button.”
Always involve counsel, insurers, and professional negotiators before you consider payment. Many organizations discover they have viable alternatives—or that a much more favorable negotiation is possible—once experts are engaged.
Mistake #2: Letting IT “Clean Up” Before Legal and Insurance Are Involved
Your IT team wants to help. Their instinct may be to reimage machines, delete ransom notes, restore backups immediately, or install new tools. While well‑intentioned, this can:
Destroy forensic evidence needed to understand the attack, meet legal obligations, or support an insurance claim.
Miss backdoors or persistence mechanisms, leading to reinfection after you think you’re clean.
Breach policy conditions that require the use of approved forensic vendors or specific documentation steps.
💡 Pro Tip: Frame the pause for IT as protection for them, not a criticism. “We need to preserve evidence so no one can later say we mishandled this. External experts will work alongside you.”
Mistake #3: Saying Too Much, Too Soon—On Email, Chat, or in Public
In an effort to be transparent, leaders sometimes overshare early theories, blame specific vendors or employees, or speculate about data loss in writing. Those messages can later appear in litigation, regulatory investigations, or the media. Over‑sharing can also create unnecessary panic among staff and customers.
Keep early written communications factual and measured, reviewed by counsel wherever possible.
Use live briefings for more nuanced discussions, and remind participants not to speculate or assign blame.
Strong leadership does not mean having instant answers; it means creating structure, protecting the organization’s interests, and guiding people through uncertainty with discipline and care.
Your 24‑Hour Executive Checklist: Turn Chaos Into a Controlled Response
In the middle of a ransomware crisis, you will not have the mental bandwidth to remember every step of this playbook. That’s why you should prepare—and when the worst happens, reach for a simple, actionable checklist that keeps you on track.
We’ve created a downloadable, executive‑friendly “First 24 Hours After Ransomware” checklist you can print, share with your leadership team, and keep in your incident response binder. It walks you through:
The immediate “do nots” (don’t pay, don’t power off, don’t freelance communications).
The exact sequence of calls to make—to counsel, insurance, IT leadership, and your board.
Key internal and external communication templates to adapt under legal guidance.
Documentation points your carrier and regulators will expect from you.
📌 Download:Executive Ransomware First 24 Hours Checklist (PDF) — Print it, walk your leadership team through it once, and keep a copy off‑network so it’s available when you need it most.
Final Thought: You Have One Chance to Get the First 24 Hours Right
Ransomware is no longer a rare, worst‑case scenario. For many organizations, it is a question of when, not if. The difference between a survivable incident and a business‑ending one often comes down to leadership decisions made in the first day: whether you preserved evidence, protected coverage, controlled the narrative, and kept your people aligned.
As CEO, owner, or COO, you don’t need to become a cybersecurity engineer. But you do need a clear, practiced playbook for moments like this. That means:
Knowing your first three moves: don’t pay yet, isolate but don’t power off, call counsel and insurance first.
Communicating calmly and consistently inside the company so your team stays focused, not fearful.
Involving law enforcement and your carrier in a way that supports, rather than complicates, your recovery.
You cannot control when an attacker chooses to target you. You can control how prepared you are to respond. Take 15 minutes now to download the checklist, save your critical contacts, and brief your leadership team. When the worst‑case scenario becomes your reality, you’ll be ready to lead with clarity instead of reacting in panic—and that can make all the difference for your business, your customers, and your people.
