Ransomware: how an executive should react in the first 48 hours

novembre 2, 2025
Réponse à incident cybersécurité et gestion de crise

Your organisation has just been hit by ransomware. The decisions you take in the first 48 hours are decisive.

What ransomware actually is

Ransomware is malicious software that encrypts your organisation’s data and demands a ransom to decrypt it. In 2024, the average cost of a ransomware attack for a mid-sized company exceeded 1.5 million euros, including remediation costs, lost business and reputational damage.

The first 48 hours: your executive checklist

H+0 to H+2: immediate containment

  • Isolate infected systems from the network, disconnecting them without shutting them down
  • Alert your CISO or CIO immediately
  • Activate your crisis team
  • Do not pay the ransom at this stage
  • Document everything: time of detection, systems affected, actions taken

H+2 to H+8: assessment and notification

  • Assess the extent of the attack with your technical team
  • File a police report, which is generally required to trigger your insurance
  • Notify the national cybersecurity authority if you are a NIS2 entity
  • Notify the data protection authority if personal data is compromised, within 72 hours
  • Contact your cyber insurer

H+8 to H+48: controlled recovery

  • Analyse the backups available and verify their integrity
  • Prioritise the critical systems to restore first
  • Communicate internally and externally, to clients, partners and media where necessary
  • Decide on the ransom with your legal counsel and the national authority
  • Plan full remediation

80 % of organisations that pay the ransom are attacked again within the year. Paying does not guarantee data recovery and it funds the criminals.

What an executive must decide and cannot delegate

Facing a ransomware attack, certain decisions are yours alone and cannot be delegated:

  • To pay or not to pay: a strategic, legal and ethical decision
  • Whether to communicate: to clients, partners and media
  • Whether to activate the continuity plan
  • What level of service to maintain during the crisis
  • What budget to allocate to remediation and recovery

Prevention: the five priority measures

  1. 3-2-1 backups: three copies, two different media, one off-site and air-gapped.
  2. Multi-factor authentication on all critical access.
  3. A tested continuity plan: an untested plan is a plan that does not work.
  4. Staff training: 90 % of ransomware enters through phishing.
  5. Network segmentation: limit propagation in the event of infection.

What you must never do

  • Shut down infected machines
  • Use backups connected to the infected network
  • Communicate over compromised corporate systems
  • Pay without consulting the national authority and your insurer
  • Ignore the 72-hour data protection notification

Prepare before the attack

The CyberMasterClass Executives prepares you to manage a cyber crisis: simulation, action plan and executive reflexes.

Publications

Get the next publications.

One analysis per publication on cyber governance, resilience and compliance.

Take action in 90 minutes

Our CyberMasterClasses train executives, sales teams and HR on cyber issues, without technical jargon.

See the masterclasses