What should you do in the first 30–60 minutes?
The goal of the first hour is not "fixing it": it is stopping the spread without destroying evidence. In this order:
- Isolate the affected machines from the network — without powering them off. Unplug the network cable, disable Wi-Fi or shut the port at the switch; in the cloud, tighten security groups. Isolation cuts the attacker's communications and stops the spread; powering off, by contrast, destroys volatile memory.
- Do not shut down or reboot. RAM contains the attacker's processes, live connections and — during an encryption in progress — sometimes the keys. That content vanishes on shutdown, and it is gold for forensic analysis and, in some ransomware cases, for decryption.
- Cut off the obvious remote access. Temporarily disable the VPN or remote desktop if they are the suspected vector, and revoke sessions on clearly compromised accounts — always from a clean machine. Mass credential rotation is best coordinated with the response team, so you don't tip off the attacker prematurely.
- Preserve logs and evidence. Export or copy firewall, VPN, email (Microsoft 365 / Google Workspace), EDR and server logs before they rotate. Take screenshots of what you see: alerts, strange processes, attacker messages.
- Keep a timeline. Who noticed what, at what time, and every action taken from that moment on, with time and author. That timeline underpins the forensic analysis, the AEPD notification and the cyber insurance claim.
- Activate your incident response plan, if you have one. Name a single decision-maker and a single point of communication. If there is no plan, this list is your interim plan.
- Communicate only through clean channels. If corporate email may be compromised, the attacker reads what you write. Use the phone or messaging on personal devices not connected to the affected network.
The rule most often broken. The instinct to "switch everything off" is understandable and almost always counterproductive: disconnecting from the network achieves the same thing (isolating the attacker) without burning the forensic evidence you will later need before the AEPD, your insurer or a judge.
If this is happening to you right now, don't just keep reading: call +34 910 13 98 27 and our incident response team will guide you through triage while containment is activated.
What should you NOT do during a cyber attack?
The first hours are when irreversible mistakes get made. The five most expensive ones:
- Paying the ransom without advice. It guarantees nothing, does not stop publication of exfiltrated data, may carry legal implications depending on the group behind the attack, and marks you as a payer. It is a business and legal decision to be taken with information — not a panic reaction.
- Reformatting, reinstalling or restoring backups "to get back up quickly". You destroy the evidence that explains how they got in and, if the entry vector remains open or the backup was already compromised, you get reinfected with the job half done. You restore once eradication is verified — not before.
- "Trying things" on affected systems. Ad-hoc antivirus sweeps, deleting suspicious files, running hastily downloaded clean-up tools: every action alters timestamps and artefacts that forensic analysis needs intact.
- Coordinating the response over compromised corporate email. If the attacker controls the mailbox, they know what you have detected, what you plan to do and when. Clean channels, always.
- Hiding the incident. Besides aggravating legal liability where personal data is involved, internal silence delays containment. Incidents get managed; secrets get discovered.
What if it is ransomware and your files are encrypted?
Ransomware adds decisions of its own to the list above. Besides isolating without powering off:
- Photograph the ransom note — in full, with the victim ID and the contact addresses — and note the extension of the encrypted files. That is how the ransomware family gets identified, along with its known techniques and whether a public decryptor exists.
- Do not negotiate blindly. Do not enter the attacker's chat "just to see what they want": every message gives away information and starts pressure clocks. If negotiation ever happens, it happens with professional advice and a defined strategy.
- Verify the real scope of the encryption. Which servers, which shares, which endpoints. And face the uncomfortable question: today's groups usually exfiltrate before encrypting (double extortion), so you must look for signs of data theft, not just of encryption.
- Check your backups without connecting them to the compromised network. Attackers try to encrypt or delete backups before launching the encryption. Verify their integrity from a clean environment: the state of your backups is the variable that shapes everything else.
Here is what this looks like in practice: in our real case of ransomware response at a law firm, early containment and verified backups made it possible to restore operations without paying the ransom. It is not always possible — but the first hours decide whether it is.
What are your legal obligations in Spain?
While the technical team contains, someone has to watch the legal clock. The essentials in Spain:
- AEPD — 72 hours if personal data is involved. If the breach affects personal data, Article 33 of the GDPR requires notifying the Spanish data protection authority (AEPD) within 72 hours of becoming aware of it, unless the breach is unlikely to pose a risk. Notification may be phased if you do not yet have all the information. If the risk to the individuals affected is high, they must be informed as well.
- INCIBE-CERT and the 017 helpline. INCIBE-CERT is Spain's reference incident response centre for businesses and citizens; you can report the incident and get free guidance through the 017 helpline.
- Police report where a crime has been committed. A cyber attack usually involves a criminal offence: you can report it to the cybercrime units of the Policía Nacional or the Guardia Civil. The report is also, in practice, usually required for the cyber insurance claim.
- NIS2, DORA and ENS, depending on your sector. If you operate in essential or important sectors (NIS2), are a financial entity (DORA) or work for the Spanish public sector (ENS), additional notification obligations to the competent authority or reference CERT may apply. Verify which ones with your legal counsel.
- Your cyber insurer — as early as possible. Policies set deadlines and sometimes panel response providers. Late notice can jeopardise cover — we explain this in our cyber insurance guide for businesses.
Why the timeline matters. Every one of these obligations requires explaining what happened, when it became known and what was done. The timeline and the evidence you preserve in the first hour are exactly what you will be asked for afterwards.
When should you call a DFIR team, and what will it do?
Call a DFIR (digital forensics and incident response) team if any of these is true: encryption is in progress or complete, you suspect data theft, privileged accounts are compromised, you cannot determine the scope with your own means, or you have notification obligations that require a defensible investigation. In practice: if you are wondering whether you need one, you need one.
What a professional team — ours included — does when activated:
- Containment with judgement. Isolating what needs isolating (and no more), cutting the attacker's communications and stopping the spread without taking the whole business down or trampling the evidence.
- Forensics with a chain of custody. Acquiring disk and memory images, preserving logs and reconstructing the timeline: entry vector, lateral movement, accounts used and data affected. All with a documented chain of custody, so the evidence stands up before the AEPD, the insurer or a court — the same rigour we apply in the expert work of our digital forensics service.
- Eradication. Removing the attacker's persistence mechanisms, accounts and backdoors, closing the entry vector and verifying no active presence remains before rebuilding anything.
- Verified recovery. Restoring in waves starting with what is critical, validating each system before returning it to production, with post-incident hardening so the same route does not work twice.
Hard2bit has been responding to incidents for Spanish businesses since 2013, with an in-house DFIR team and a standard we also hold ourselves to: we are ISO 27001 certified and accredited under Spain's ENS at the High category. We do not promise miracles; we promise method, evidence and honesty about what can be recovered. You can activate us on demand through incident response, or have the team already under contract with the IR retainer.
How do you prevent the next incident?
Once the incident is closed, the best investment is making sure the next one does not happen — or finds you prepared. Four measures with the most impact per euro:
- An incident response retainer. A contract, an SLA and a team that already knows your environment before the next 3 a.m. call. It is the difference between activating in minutes and shopping for a provider mid-crisis.
- Immutable or offline backups — tested ones. Backups an attacker with domain control cannot encrypt or delete, plus a recent restoration test proving they actually work.
- MFA on every remote access and privileged account. The control that stops the most intrusions relative to what it costs.
- EDR with real eyes on it (SOC/MDR). Endpoint detection and response with continuous monitoring of the alerts: incidents detected in hours cost a fraction of those detected in weeks.
Frequently asked questions
I run a small manufacturing firm and this morning every file on the server is encrypted, with a ransom note. Should I switch the machines off so it doesn't spread?
Do not switch them off: disconnect them from the network (cable and Wi-Fi) and leave them running. RAM holds the attacker's processes and, sometimes, the keys of an encryption still in progress; powering off destroys that evidence and may kill any chance of decryption. Photograph the ransom note, do not touch your backups from affected machines, and call an incident response team before taking any further decisions.
Our sysadmin has been seeing odd remote connections since yesterday. How do we find out whether data has been stolen?
Only through the logs: review firewall, VPN, email and server records for anomalous outbound transfers, out-of-hours access and compression or transfer tools nobody installed. Do not delete anything, and preserve those logs now — many rotate within days. Confirming or ruling out exfiltration rigorously requires forensic analysis, which is one of the reasons to activate a DFIR team as early as possible.
We run an accountancy firm and we still don't know what data was taken. Do we notify the AEPD now, or wait until we know everything?
Do not wait for the full picture: the deadline under Article 33 of the GDPR is 72 hours from becoming aware of the breach, and the regulation allows notification in phases, adding information as the investigation progresses. Notifying early with partial data beats arriving late with the complete report. Document the timeline and every decision — you must also be able to demonstrate diligence.
Should I pay the ransomware ransom?
Not blindly, and never as a first reaction. Paying does not guarantee recovery, does not stop publication of exfiltrated data, may carry legal implications depending on who is behind the attack, and marks you as a payer for future attacks. Before deciding anything: verify the real state of your backups, the scope of the encryption and any possible exfiltration, and take the decision with DFIR and legal advice.
How quickly does Hard2bit's response team activate?
With a retainer in place, initial triage activates within minutes through an emergency channel backed by a contractual SLA. Without a retainer, we handle emergencies subject to availability: call and we will assess the case immediately. In both scenarios we work with a chain of custody from the first minute, so the evidence stands up before the AEPD, your insurer or a court.
Will I get all my data and systems back?
Nobody can honestly promise you that, and you should distrust anyone who does. What we can do: contain the incident so it stops growing, establish what happened with solid evidence, eradicate the attacker's presence, and restore operations in a verified way, critical systems first. The factor that most shapes the outcome is your backups — their state gets checked at the start, not at the end.