Just like a first-aid kit matters after an injury, having a clear plan for after an attack matters just as much as trying to prevent one in the first place.
The instinct to immediately shut everything down or delete things can accidentally destroy evidence needed to understand what actually happened — and understanding what happened is what actually prevents it from happening again. Panic makes people erase the exact trail that would tell investigators (or automated tools) how the attacker got in.
Disconnect the affected device or account from the network so whatever happened can't spread further, without destroying anything that might be useful evidence. This single step — contain without destroying — is exactly what separates organizations that recover in days from ones that take months, and the data backs this up clearly. Ransomware recovery speeds have genuinely improved industry-wide: only 22% of organizations recovered within a week in 2023, rising to 35% in 2024, and reaching 53–54% by 2025.1 That's a real, measurable shift toward faster containment and recovery, driven by better backup infrastructure and more organizations actually having a tested plan rather than improvising one mid-crisis.
The gap between having a tested, automated response process and improvising one live is bigger than most people expect. Organizations using automated recovery playbooks contained breaches in a median of 51 days, compared to 79 days for organizations without them.2 That's not a marginal difference — it's roughly a month of additional exposure, additional cost, and additional opportunity for an attacker to do more damage, purely from the absence of a plan that already existed and just needed to run.
Who needs to know goes beyond your own IT team. Depending on what was involved, that can include law enforcement, regulators, affected customers, and business partners — and in many places, some of these notifications are legally required within a specific window, not optional or discretionary. Involving law enforcement specifically has a measurable practical benefit too: victims who did so were more likely to avoid paying a ransom at all, since investigators sometimes have decryption tools or intelligence that isn't publicly available. Waiting to notify anyone until you've "figured everything out" usually just burns the notification window without actually buying useful clarity.
Prioritize email and financial accounts first — email especially, since it's often the key to resetting everything else. If ransomware or extortion is involved specifically, one more decision looms: whether to pay. The trend here is encouraging — in 2025, 63% of ransomware victims refused to pay, up from 59% the year before, while the share who paid dropped correspondingly to 37%.3 Law enforcement guidance consistently discourages payment, since paying doesn't guarantee data recovery and directly funds further attacks — and more victims each year are choosing not to.
A good incident response process ends with understanding exactly what happened and what changes would prevent it from happening the same way again — not with everyone simply relieved it's over and eager to move on. Skipping this step is one of the most common, and most costly, mistakes: without a genuine post-incident review, the same gap that let the attacker in the first time is often still sitting there, wide open, for the next attempt.
A real review covers more than just the technical root cause. It should also honestly assess how well the response itself went: were the right people notified quickly enough, did the plan (if one existed) actually match what the situation needed, and how long did each stage genuinely take compared to what was assumed going in. This is uncomfortable to do well, since it means examining decisions made under pressure with the benefit of hindsight — but it's exactly that discomfort that makes the next response faster and more effective than this one was.
The single biggest factor separating a costly, drawn-out incident from a contained, manageable one is whether a real plan existed before it happened. A few practical takeaways: