Back to Blog
Cybersecurity

The First 48 Hours of a Ransomware Attack: What Actually Happens to a Small Business

An hour-by-hour walkthrough of what a ransomware attack looks like from inside a small business — discovery, containment, the pay-or-restore decision, and what determines whether a company survives it.

Laurel FullerOwnerAugust 13, 20269 min read

Most of What You've Heard About Ransomware Is Wrong

The popular image of a ransomware attack is a sudden splash screen locking your computer, followed by a frantic scramble. In reality, the attack has been underway for days or weeks before you see that screen. And the first 48 hours after discovery are less about fighting hackers and more about making decisions that determine whether your business survives.

Here's what actually happens, hour by hour, based on how real attacks unfold at small and mid-sized businesses. Not the Hollywood version — the operational reality.

Before the Lock Screen: What You Don't See

Ransomware attackers typically gain access days or weeks before they deploy the encryption. They enter through a phishing email, an exposed remote desktop protocol (RDP) port, or an unpatched vulnerability. Once inside, they move laterally through your network, stealing credentials, identifying your backup systems, and mapping your data.

This phase is silent. You won't know it's happening. The first 48 hours described below begin at the moment you discover the attack — usually when files start encrypting or systems stop responding.

The First 48 Hours: An Incident Timeline

TimeWhat's happeningWhat you should be doing
Hour 0Files begin encrypting. Staff report they can't open documents. Systems slow or unresponsive.Disconnect affected machines from the network immediately. Do not turn them off — preserve evidence.
Hour 1You realize this is ransomware, not a glitch. Panic sets in.Contact your IT provider or incident response team. Do not try to fix it yourself.
Hour 2Attack is still spreading. Every connected system is at risk.Isolate the network. Shut down unaffected systems if you can't isolate them. Disable Wi-Fi.
Hour 4Initial assessment underway. IT team determining scope.Identify which systems are affected, which are clean, and where your backups are.
Hour 8Containment or failure. Either the spread is stopped or it continues.If contained, begin triage. If not, physically disconnect everything.
Hour 12Attacker's ransom note appears with payment instructions and deadline.Do not respond to the attacker yet. Document everything. Contact your cyber insurance provider.
Hour 16Insurance and legal notifications begin. Law enforcement may be involved.Your insurance carrier will assign a breach coach (attorney) and may approve a forensic firm.
Hour 24Forensic investigation starts. Determining how they got in.Cooperate with investigators. Do not communicate with the attacker without legal guidance.
Hour 32The pay-or-restore decision begins to take shape.Assess whether your backups are intact and usable. This is the single most important question.
Hour 40If backups are intact, restoration planning begins. If not, the ransom conversation gets serious.Calculate the cost of downtime vs. the cost of rebuilding from scratch vs. the ransom.
Hour 48A decision is made. Either restoration from backups is underway, or you're negotiating payment.Either way, you're now in recovery mode — and it will take days to weeks, not hours.

The Pay-or-Restore Decision

This is the decision that defines whether your business survives the attack. And it comes down to one factor almost every time: the state of your backups.

If your backups are intact and recent, you restore from them. You lose whatever was created between the last backup and the attack, but you're back in business. Total cost: downtime, IT labor, and whatever data was lost. No ransom payment. No dealing with criminals.

If your backups were destroyed, encrypted, or never existed, the math changes. You can rebuild from scratch — re-entering data, recreating files, contacting clients — if that's even possible. Or you can pay the ransom, with no guarantee you'll get your data back, and no guarantee the attacker won't leak it anyway. The FBI does not recommend paying, but for many small businesses, it becomes the only viable option.

This is why attackers target backups first. They know that if your backups survive, their leverage disappears.

What Determines Whether a Company Survives

The businesses that survive ransomware attacks share a few characteristics:

  • They had working backups that the attackers couldn't reach — typically an air-gapped or offline backup.
  • They had cyber insurance, which covered forensic investigation, legal counsel, and recovery costs.
  • They acted fast — isolating systems within the first hour rather than hoping it would resolve itself.
  • They had an incident response plan, even a basic one, so people knew who to call and what to do.

The businesses that don't survive are the ones without backups, without insurance, and without a plan. For them, the 48-hour timeline above becomes a 48-day timeline of rebuilding, and many never reopen.

Before It Happens: Your Prevention Shortlist

If you take one thing from this article, let it be this: the decisions that determine your ransomware outcome are made before the attack, not during it.

  • Implement an air-gapped backup. A backup that's disconnected from your network is a backup ransomware can't reach. This is the single most important control.
  • Patch aggressively. Most attacks exploit known vulnerabilities that already have fixes available. Automated patching closes the door.
  • Enable multi-factor authentication everywhere. Especially on remote access, email, and any administrative accounts.
  • Train your team on phishing. The initial access point is almost always a phishing email. One-click training reduces the risk dramatically.
  • Have an incident response plan. A simple document that says who to call, what to disconnect, and where your backups are. It doesn't need to be elaborate — it needs to exist.
  • Get cyber insurance. The cost is modest compared to the cost of an attack, and it gives you immediate access to forensic and legal resources.

For a deeper look at prevention, here's how to protect your business from ransomware. An air-gapped backup is the one control that makes recovery possible when everything else fails.

If you want to understand why synced cloud backups aren't enough, read our companion piece on air-gapped backups explained. The short version: if your backup is connected to your network, the ransomware can reach it.

Ransomware is the most destructive threat facing small businesses today, and the difference between surviving it and not comes down to preparation. Dytech Group builds layered defenses and backup strategies for Central Florida businesses. Our data protection services include the offline backup architectures that make recovery possible when everything else fails.

Get a Free Consultation

As a family-owned business, we treat every client like a neighbor — not a number. Talk to a real local technician and discover what personalized IT support feels like.