---
title: "The first 72 hours of a ransomware attack: Why restored isn’t recovered "
description: "Restoring servers isn’t the same as recovering the business. Plan ransomware recovery and use AI-assisted investigation to detect attacks sooner."
author: "Taylor Overturf"
date: 2026-10-02
tags: ["cloud siem", "threat detection", "ai security"]
blog_type_id: the-monitor
locale: en
---

You start the day with reports that your employees cannot access critical systems. A ransom note soon explains why: attackers have encrypted them and demand $2 million in bitcoin for a decryption key. Your team contains the attack and confirms that the backups are safe, yet this is only the beginning. Restoring your servers can take weeks, but recovering the business can take much longer. During that time, your teams validate data, reconnect dependencies, work through backlogs, and manage the legal and customer impact. Restoring the systems gets the technology running again. Recovering the business requires much more.

The attack is hypothetical, but the decisions it raises are not. In the webinar "[Surviving a CISO’s Worst 72 Hours in the AI Era](https://www.datadoghq.com/dg/webinars/ciso-dach-2026/)," chief information security officer (CISO) [Florian Jörgens](https://www.linkedin.com/in/florian-j%C3%B6rgens) walked participants through the first 72 hours of a ransomware attack and the decisions you face at each stage. This post follows the incident as it could unfold and highlights the questions to answer *before* a real attack forces them:

- [Day 1: Respond in the first hours of a ransomware attack](#day-1-respond-in-the-first-hours-of-a-ransomware-attack)
- [Day 2: Stop ransomware from spreading as the breach goes public](#day-2-stop-ransomware-from-spreading-as-the-breach-goes-public)
- [Day 3: Restore systems and confront the true cost of recovery](#day-3-restore-systems-and-confront-the-true-cost-of-recovery)

From there, we explain how to [detect ransomware earlier with AI-assisted investigation](#detect-ransomware-earlier-with-ai-assisted-investigation) and [prepare for a ransomware attack before it happens](#prepare-for-a-ransomware-attack-before-it-happens).

## Day 1: Respond in the first hours of a ransomware attack

Late one Sunday night, the first signs appear. Your employees say their computers are behaving strangely and a skull appears on their screens. IT connects the reports, declares a major incident, and calls you, the CISO. 

Shortly after, you receive a ransom demand. A group claims it has stolen customer data and wants $2 million in bitcoin. This isn't a random amount. In a real attack, ransomware groups often [study your finances](https://cloud.google.com/blog/topics/threat-intelligence/ransomware-ttps-shifting-threat-landscape) and set a price that hurts to pay but is still within reach.

![Fictional ransomware attack timeline for the first 24 hours, from ransom note at hour 6 to crisis communications at hour 20.](https://web-assets.dd-static.net/42588/1790952180-first-24-hours-timeline.png)

You declare an emergency and activate your incident response plan. This releases the budget, frees people from regular work, and opens the communication channels needed to coordinate the response. But the plan only works if your team is prepared to move quickly.

One of your first calls is to a forensic partner who can determine how the attackers got in and how far they’ve spread. This relationship should already be in place. During a widespread attack, many companies need the same experts at once and qualified help might be difficult to find.

Your team also needs access to current information without relying on affected systems:

- Where are the printed copies of your crisis documents and current architecture diagrams? 
- Who is responsible for updating them and how often are they reviewed?

## Day 2: Stop ransomware from spreading as the breach goes public

By Monday morning, the ransomware has spread to systems supporting several business locations. Some locations are closed for a public holiday and remain offline. Others can no longer process transactions. You need to decide whether to disconnect the wider network and stop the spread, even though doing so will take more of the business offline.

### What a forensic security report recommends

You receive a forensic security report. It recommends three actions: 

- **Isolate**: Work with the incident response and forensic teams to [contain affected systems](https://www.ncsc.gov.uk/section/respond-recover/medium-large). Where practical, preserve volatile evidence before shutting systems down. The right action depends on the risk of further spread and the circumstances of the incident.
- **Analyze**: Review your identity provider for new or unfamiliar admin accounts. Ransomware groups typically stay in the network, take over accounts with weak or missing multi-factor authentication (MFA), and move deeper.
- **Check**: Trace how the ransomware spread and identify how it first got in. Then scan the wider environment for more malware and confirm your backups are clean, so you can rebuild a clean network segment and restore your backups there.

Before an attack occurs, determine: 

- Who can disconnect systems during a crisis?
- Can they act on their own professional judgment, without waiting for business sign-off?
- When you disconnect, what does that mean in practice: powering systems off, or disconnecting a specific network connection? 

Define in advance which roles can isolate systems and the conditions under which they can act without additional approval. Preauthorization can save critical time before an attack spreads.

### What happens when the breach goes public

Now the outage is public, and the story is spreading across social media. Your head of sales wants to know why the enterprise resource planning (ERP) and customer relationship management (CRM) systems are down. Your press team has 2 hours to respond to a reporter before the paper runs its own version of events. Communication is often the first thing to break in a crisis, so consider:

- Do preapproved statement templates already exist for a breach or outage?
- How would your crisis team communicate with each other if email and chat were down?
- How would you reach employees, customers, and the press during those same outages? 

With email and chat down, even reaching your staff is hard. One low-tech fallback is printed signs at office entrances telling team members the company has had a security incident and not to turn on their computers.

Designate an incident lead and clearly assign responsibility for technical response, legal assessment, business coordination, and external communications. A clear escalation structure helps teams coordinate decisions and avoid conflicting messages.

## Day 3: Restore systems and confront the true cost of recovery

By the third day, IT has cut every connection. The ransomware encrypted the machines it reached, but your backups are safe, so restoration can finally begin. IT starts to estimate how long it will take to restore all systems. In this hypothetical example:

- **A desktop computer**: about 8 hours 
- **A shop system**: about 5 hours
- **A server**: about 2 days
- **An SAP or other enterprise system**: about 3 days

Apply those estimates across the environment, account for dependencies, and decide how much work can happen in parallel. Even with clean backups and a fast response, your IT staff may work 12- to 18-hour shifts for days, and full recovery can still run into months. Answering these questions in advance can shorten that timeline:

- Does your restart plan identify which systems should come back on first?
- Who confirms that a restored system is safe to bring back online? What checks must happen first?
- When your IT teams are working long shifts for days, how do you take care of them and prevent burnout?

Maintain ransomware-resistant backups that are isolated, protected, and regularly tested. They provide a recovery path without relying on an attacker’s decryptor.

![Fictional ransomware recovery timeline: a 72-hour response, weeks of system restoration, and a longer business recovery.](https://web-assets.dd-static.net/42588/1790959243-updated-timeline-2.png)

### Prepare for the impact beyond IT and security

An incident like this doesn't stay contained to IT and security. Your company may face liability, regulatory reporting requirements, and [scrutiny from customers, the press, and the board](https://www.datadoghq.com/resources/ciso-playbook/). If personal data may have been exposed, your legal and data protection teams need to determine whether notification requirements apply.

Under the [General Data Protection Regulation](https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32016R0679) (GDPR), a controller must notify the relevant supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it. Notification is not required if the breach is unlikely to pose a risk to individuals' rights and freedoms. Law enforcement may also help your team understand the attackers' tactics and investigate what happened to stolen data.

Decide in advance who owns regulatory notification, law enforcement contact, and board reporting, so these become assignments you execute rather than questions you debate mid-incident.

### Why paying the ransom won't end the incident

The decision remains: Do you pay the $2 million, or refuse and prepare for the attackers to release your customer data? Even if you pay, there's no guarantee they'll deliver a working key or delete what they've stolen. Either way, you still have to rebuild compromised systems. Ransomware-resistant backups and a tested restart plan give you a way to restore those systems without relying on the attackers, but they do not remove the extortion pressure created by stolen data.

### Recover the business, not just the systems

Even with your servers back online, the business is not yet recovered. Your teams still have to prove the restored systems are clean, reconnect them in the right order, catch up on the work that stopped, and rebuild trust with customers and partners. 

A restored system may still depend on an identity provider, database, network connection, or third-party service that is not ready. Your teams may be working from manual records, customer requests may be waiting in a backlog, and finance may need to reconcile transactions completed during the outage.

Before you consider a recovery complete, ask:

- Have your teams validated the data, not just restored it?
- Are critical business services working from end to end?
- What still needs to be rebuilt rather than restored?

## Detect ransomware earlier with AI-assisted investigation

The earlier you detect and investigate an attack, the smaller the incident you have to recover from. Recovery effort scales with the scope of the compromise. Every system the attackers reach and every account they take over adds more to rebuild, restore, and validate. 

### Reduce the time from alert to decision

Manual response rarely matches [the pace of modern attacks](https://www.datadoghq.com/resources/ciso-playbook/). In 2025, [nearly 30% of known exploited vulnerabilities](https://www.vulncheck.com/blog/state-of-exploitation-2026) were attacked on or before the day their Common Vulnerabilities and Exposures (CVE) record was published. AI-assisted investigation can take on repetitive work, such as gathering context and reviewing related signals and logs. Analysts still decide what the activity means and how to respond, but they can start with the relevant evidence already assembled.

While SIEM modernization has improved visibility, it hasn't changed how analysts work. When you [converge security and observability data](https://www.datadoghq.com/resources/ciso-playbook/) and apply AI across investigation and response, you reduce the time from alert to decision.

### Surface and investigate signals automatically 

Long before the $2 million ransom demand arrives, the attackers may have been inside, creating admin accounts and taking over identities with weak or missing MFA. Many of these early indicators surface first in logs, metrics, and traces. Combining that observability data with security signals gives your team more context, and often earlier warning, than either source alone. Depending on the available telemetry data and detection rules, [Datadog Cloud SIEM](https://www.datadoghq.com/product/cloud-siem/) can help surface activity associated with attacker behavior for further investigation. Cloud SIEM can:  

- [Combine related signals](https://docs.datadoghq.com/security/cloud_siem/detect_and_monitor/custom_detection_rules.md) into one higher-confidence signal, so there's less to review
- Rank entities by risk with [Risk Insights](https://docs.datadoghq.com/security/cloud_siem/triage_and_investigate/entities_and_risk_scoring.md), which scores each user and resource to help you decide what to investigate first
- Map signals to the [MITRE ATT&CK®](https://attack.mitre.org/) tactic and technique of the rule that fired

Once Cloud SIEM surfaces a signal, [Bits Security Analyst](https://www.datadoghq.com/product/ai/bits-security-analyst/) can investigate it automatically. It reviews related logs and historical signals, follows the evidence, and indicates whether the activity appears benign or suspicious. If Bits Security Analyst flags the activity as suspicious, an analyst can escalate the signal into  a single [Cloud SIEM case](https://www.datadoghq.com/blog/cloud-siem-cases.md), then trigger a response workflow directly from the case. 

### Hunt for threats without a preexisting rule 

These ransomware campaigns rarely happen in isolation. Attackers often target specific company types, industries, or geographies. [Bits Threat Hunting](https://www.datadoghq.com/product-preview/bits-threat-hunting/) in Datadog Cloud SIEM helps you stay ahead of breaches by finding signs of attacker persistence before you’ve written a detection rule. From any source of intelligence, such as a campaign report, an RSS feed, or a threat brief, you can launch an autonomous, hypothesis-driven threat hunt. The hunt helps determine the scope of potential impact, recommends next steps, and generates detection rules to catch similar incidents later.

## Prepare for a ransomware attack before it happens

Recovery is not complete when the servers come back online. It’s only complete when employees can work, customers can rely on the business, and teams can trust the systems and data they restored. The decisions you make before an attack can affect how long recovery takes.

If this scenario happened tonight, how long would it take your company to recover? Decide in advance who can disconnect systems and how the team will communicate when normal tools are unavailable. Test the full recovery process, including your backups and restart plan, so you know what works and where the gaps are before you need it. 

Watch the webinar, "[Surviving a CISO's Worst 72 Hours in the AI Era](https://www.datadoghq.com/dg/webinars/ciso-dach-2026/)," for the full exercise created by [Florian Jörgens](https://www.linkedin.com/in/florian-j%C3%B6rgens) and his discussion with Datadog Field CISO [Rob Aragao](https://www.linkedin.com/in/rob-aragao). 

To see how stream-based detection and autonomous investigation work in practice, visit the [Datadog Cloud SIEM documentation](https://docs.datadoghq.com/security/cloud_siem.md).

If you're not already a Datadog customer, <!-- Sign-up trigger (sign up for a free 14-day trial) omitted -->.