What happens after a ransomware attack: costs, recovery times, and critical decisions in the first 72 hours

By Eduard Bardaji on Aug 27, 2026, 9:00:01 AM

<span id="hs_cos_wrapper_name" class="hs_cos_wrapper hs_cos_wrapper_meta_field hs_cos_wrapper_type_text" style="" data-hs-cos-general-type="meta_field" data-hs-cos-type="text" >What happens after a ransomware attack: costs, recovery times, and critical decisions in the first 72 hours</span>

A company can go from operating normally to having its systems locked down within hours. When ransomware encrypts servers, devices, or shared drives, every minute counts to contain the attack, restore operations, and determine what information may have been exposed.

The cost of downtime can reach between €4,000 and €7,500 per minute, and recovery can take 25% longer than expected.

That is why the first 72 hours are critical to contain the incident, restore systems, and prevent the attack from becoming a prolonged crisis.

The first 72 hours after a ransomware attack

Not all companies face ransomware attacks in the same way. The scope of the attack, the availability of isolated backups, and the ability to identify how far the attacker has reached directly affect recovery time.

Time

Priority

Objective

0–6 hours

Contain the attack

Isolate systems and prevent ransomware from continuing to spread

6–24 hours

Analyze the incident

Determine the scope, preserve evidence, and review potential access

24–72 hours

Recover and coordinate

Define the restoration strategy and manage the obligations arising from the incident

During this phase, the goal should not simply be to restore systems as quickly as possible, but to restore them securely, preventing the attacker from maintaining access to the infrastructure.

What really happens after a ransomware attack?

File encryption is often only part of the problem. When an attack reaches critical systems, services required to issue invoices, manage orders, communicate with customers, or maintain internal processes may be affected.

In addition, many ransomware groups use double-extortion techniques. Before encrypting systems, they may exfiltrate information and later use it to pressure the company by threatening to publish or sell the data.

Therefore, after an attack, it is necessary to answer two different questions: which systems have stopped working and what information may have been compromised.

How can you determine the scope of a ransomware attack?

Before beginning a restoration, it is necessary to understand how far the attack has reached. Several checks can provide an initial picture of the situation:

  • Affected systems: identify which devices, servers, applications, and network drives show signs of encryption or abnormal behavior.
  • Backups: verify whether backups are still available and whether the attacker has attempted to delete or encrypt them.
  • Compromised accounts: review the identities used during the attack and detect administrative access or lateral movement.
  • Data exfiltration: analyze network communications and available logs to determine whether data has been transferred outside the organization.
  • Entry point: identify how the attacker gained access to prevent them from using the same path again during recovery.

This phase is critical because restoring systems without fully containing the attacker's access can put the infrastructure at risk again.

How long can it take a company to recover?

Recovery time depends primarily on the scope of the incident and the organization's level of preparation beforehand.

A company with isolated backups, defined recovery procedures, and properly segmented infrastructure can restore certain services more quickly. When these mechanisms do not exist or backups have also been affected, recovery can take weeks.

In addition to restoring data, affected devices must be cleaned, persistent access must be ruled out, and systems must be validated before being returned to production.

Therefore, having a backup does not necessarily mean being prepared to restore operations. Backups must also be tested regularly to ensure they can be restored and that the attacker cannot access them.

What decisions are critical during the first few hours?

The pressure to restore operations can lead to mistakes that later complicate the investigation or allow the attack to continue.

Isolate before restoring

Affected devices and servers should be isolated to limit the spread. Restoring systems while the attacker still has access can lead to reinfection.

Preserve evidence

Avoid indiscriminately formatting or restarting systems. Logs, affected devices, and other evidence can help determine the origin, scope, and progression of the attack.

Protect identities

Compromised credentials should be reviewed and, where appropriate, revoked. Administrative accounts require particular attention because they may have been used to move laterally through the infrastructure.

Assess data exposure

Do not assume that ransomware has only encrypted information. It is necessary to analyze whether attackers have accessed or extracted personal, financial, commercial, or intellectual property data.

What about legal obligations?

When an incident involves personal data, the company must determine whether a security breach has occurred and what its notification and incident-management obligations are.

The assessment should include what information was affected, whose data was involved, when the access occurred, and what measures have been implemented to contain the incident.

In addition, organizations subject to specific regulatory requirements may have additional incident reporting and management obligations. For this reason, the technical response should be coordinated from the beginning with the teams responsible for compliance and legal matters.

Nueva llamada a la acción

How can you reduce ransomware recovery time?

Recovery begins before an attack occurs. A resilience strategy should make it possible to maintain control of the infrastructure even when part of the systems have been compromised.

  • Isolated and immutable backups: maintaining multiple copies protected against deletion or encryption makes it possible to restore systems without depending on the attacker.
  • Infrastructure segmentation: separating critical systems and services limits ransomware's ability to spread throughout the organization.
  • Continuous monitoring: detecting abnormal behavior, lateral movement, or suspicious access makes it possible to act before encryption reaches additional systems.
  • Recovery testing: regularly verifying that backups can be restored makes it possible to determine the actual time required to restore operations.
  • Response plans: defining in advance who should act, which systems should be isolated, and how recovery will be coordinated prevents improvisation during a high-pressure situation.

ESED, proactive cybersecurity against ransomware

Preparing for ransomware is not only about preventing an attacker from getting in. It also means knowing how long it would take the company to restore operations if an attacker succeeded.

An effective cybersecurity strategy must combine prevention, detection, response, and recovery capabilities. The greater the visibility into the infrastructure and the better prepared the recovery procedures are, the less the organization will have to rely on improvised decisions during an incident.

At ESED, we work with a managed cybersecurity model based on prevention, continuous monitoring, and response, helping companies detect threats, contain incidents, and strengthen their recovery capabilities.

Our fixed monthly fee model allows organizations to keep their systems under continuous supervision and plan their cybersecurity investment without relying on unexpected costs when an incident occurs.

Contact us