This is the sequel to The First Hour of a Cyber Incident. Read that one first if you have not - it covers isolating machines, touching nothing, and getting help on the phone. This one starts where it ends: the machines are off the network, nothing has been wiped, the note has been photographed, and someone competent is on their way or on the line.
The first hour is instinct. The next twenty-four are a different discipline: communication in the right order, two tracks of decisions running at once, and a business that has to keep functioning while its systems are evidence. Here is how that day actually goes.
The order matters more than the speed. Getting it backwards - telling customers before counsel, or the whole staff before leadership - creates problems you cannot take back.
Your response team and your IT provider, if they are not already engaged from the first hour. One channel, one place where updates live, so you are not re-explaining the situation to each party separately.
Your cyber insurance carrier, through the notice process in your policy, and your attorney - ideally one who handles incidents - early in the day, not after decisions have been made. These two calls shape everything else. The carrier because the policy controls what is covered, what must be pre-approved, and often which outside specialists you use. The attorney because questions that arrive in the next day - what must be reported, to whom, whether the note should be answered, what you can say to employees and customers - are legal questions wearing technical clothes, and some of the work that follows should run under counsel's direction.
Your leadership and owners, plainly and without reassurance you do not yet have. What happened, what is affected, what is being done, when the next update comes. Then keep the promise on updates even when the update is "nothing new."
Your staff, with a short, controlled message: systems are down due to an incident, do not attempt to fix or work around it, do not discuss it outside the company, route anything unusual to a named person. Staff who are not told a story will invent one, and the invented version reaches customers.
Bank and financial contacts, if there is any chance payment systems, banking credentials, or financial data were in reach of the affected machines. Fraud attempts following an intrusion are common enough that the call is cheap insurance.
Customers and partners come last and only on advice - once you know what happened, whether their data or their service is affected, and what you are required or committed to tell them. What those obligations are, and their deadlines, varies by state, by regulation, and by contract; that is a determination for counsel, made from the facts as the investigation establishes them, not from the ransom note.
Read the notice and cooperation clauses of your policy the day this starts, not from memory. In practice, the carrier will want:
If you do not have a policy, everything in this section becomes out-of-pocket decisions to make with counsel and the response team - and the discipline is the same minus the approvals.
The note gives you an address and invites contact. Do not use it, and do not let anyone else in the company use it.
The practical reasons first. Anything you say begins a negotiation you are not equipped to run, against people who run them daily, and everything you write is evidence - in an investigation, in a coverage dispute, potentially in litigation. A reply also tells the attacker the address is read, which raises the value of everything they demand next. And payment is not a simple transaction even if you were inclined: it sits in a thicket of sanctions rules and legal exposure that counsel has to evaluate, it may or may not be reimbursed under your policy, and it reliably produces a working decryptor less often than the note implies. There is also the quieter problem: attackers share lists. A business that responds, let alone pays, is a business that gets approached again.
That does not mean the note goes unanswered forever. It means any contact - including the decision to make none - goes through counsel and, if it comes to it, professional negotiators retained through the carrier or the response team. Your job in this lane is to preserve the note, photograph it, and say nothing into it.
Two tracks run through the day and they move at different speeds. Mixing them up is how businesses make the expensive mistakes - rushing the slow track, dithering on the fast one.
Cannot wait:
Must wait - for facts, forensics, counsel, or the carrier:
Assume the systems are gone for longer than a day and plan the interim operation like it has to survive the week.
Start with the work that has a date on it: payroll, invoices due, shipments, appointments, court or filing deadlines. For each, write down how it was done before the system existed, because that is how it is done now - paper ledgers, printed order forms, a phone tree, a whiteboard schedule. Pull the records that live outside the affected systems: the contact list in someone's phone, the price book in a drawer, the bank's own website reached from a clean machine, the backups the accounting software vendor keeps on their side. Most small businesses discover they know more than they feared, once they stop reaching for the server and start asking people what they remember.
Set a clean communications channel - personal phones, a new group chat on accounts that never touched the company network - and tell staff and key customers to use it. Assume the attacker can read company email until told otherwise.
And set expectations honestly with customers: you are experiencing a systems issue, here is how to reach us, here is what is unaffected. Most customers have lived through someone else's outage and will work with a business that answers the phone. They will not work with one that vanishes.
The response team's first day is partly investigation and partly intake, and the intake questions are predictable. Every item you gather in advance is an hour you do not pay for later.
Hand this over as it is, gaps included. The team has seen worse, and a candid inventory beats a polished one that turns out to be wrong.
Once the first hour is handled, the day becomes a management problem more than a technical one. The businesses that come through it best do three things: they communicate in the right order - response team, carrier, counsel, leadership, staff, bank, and only then customers; they keep the fast decisions (shutdown scope, credentials, interim operations) moving while refusing to rush the slow ones (ransom, rebuild, notification); and they treat the notes, the backups and the inventory as deliverables, because every one of them is something the carrier, the forensics team or counsel will ask for within the day.
Two things to take from this before you ever need it. The call order above assumes you already know who your carrier's hotline, your counsel and your response partner are - if those names are not written down somewhere that works when the network doesn't, that is the fix, and it takes an afternoon. And the entire "running on paper" section gets radically easier if critical contact lists, vendor details and a copy of the plan live somewhere off the network by design.
This article is the second half of a pair - The First Hour of a Cyber Incident covers what precedes all of this. If you are inside the day right now, call +1 (888) 966-7228. If you are reading it calmly, our DFIR retainers and response work and the security self-check are the two ways to make sure you never improvise any of it.
Disclaimer. This article is provided for general information only. It is not legal, regulatory, or professional advice, and reading it does not create a client relationship with WOM Technology Management Group. Regulations, threats, and vendor products change; specific obligations depend on your industry, jurisdiction, contracts, and data. Verify anything you plan to rely on against the primary source and consult qualified counsel or a security professional before acting.
Sources are cited as of the last-reviewed date shown above. Where a linked source has moved or been withdrawn, the citation reflects what was verifiable at review time.