The First 48 Hours of a Ransomware Attack: What Actually Happens to a Small Business
An hour-by-hour walkthrough of what a ransomware attack looks like from inside a small business — discovery, containment, the pay-or-restore decision, and what determines whether a company survives it.
Most of What You've Heard About Ransomware Is Wrong
The popular image of a ransomware attack is a sudden splash screen locking your computer, followed by a frantic scramble. In reality, the attack has been underway for days or weeks before you see that screen. And the first 48 hours after discovery are less about fighting hackers and more about making decisions that determine whether your business survives.
Here's what actually happens, hour by hour, based on how real attacks unfold at small and mid-sized businesses. Not the Hollywood version — the operational reality.
Before the Lock Screen: What You Don't See
Ransomware attackers typically gain access days or weeks before they deploy the encryption. They enter through a phishing email, an exposed remote desktop protocol (RDP) port, or an unpatched vulnerability. Once inside, they move laterally through your network, stealing credentials, identifying your backup systems, and mapping your data.
This phase is silent. You won't know it's happening. The first 48 hours described below begin at the moment you discover the attack — usually when files start encrypting or systems stop responding.
The First 48 Hours: An Incident Timeline
| Time | What's happening | What you should be doing |
|---|---|---|
| Hour 0 | Files begin encrypting. Staff report they can't open documents. Systems slow or unresponsive. | Disconnect affected machines from the network immediately. Do not turn them off — preserve evidence. |
| Hour 1 | You realize this is ransomware, not a glitch. Panic sets in. | Contact your IT provider or incident response team. Do not try to fix it yourself. |
| Hour 2 | Attack is still spreading. Every connected system is at risk. | Isolate the network. Shut down unaffected systems if you can't isolate them. Disable Wi-Fi. |
| Hour 4 | Initial assessment underway. IT team determining scope. | Identify which systems are affected, which are clean, and where your backups are. |
| Hour 8 | Containment or failure. Either the spread is stopped or it continues. | If contained, begin triage. If not, physically disconnect everything. |
| Hour 12 | Attacker's ransom note appears with payment instructions and deadline. | Do not respond to the attacker yet. Document everything. Contact your cyber insurance provider. |
| Hour 16 | Insurance and legal notifications begin. Law enforcement may be involved. | Your insurance carrier will assign a breach coach (attorney) and may approve a forensic firm. |
| Hour 24 | Forensic investigation starts. Determining how they got in. | Cooperate with investigators. Do not communicate with the attacker without legal guidance. |
| Hour 32 | The pay-or-restore decision begins to take shape. | Assess whether your backups are intact and usable. This is the single most important question. |
| Hour 40 | If backups are intact, restoration planning begins. If not, the ransom conversation gets serious. | Calculate the cost of downtime vs. the cost of rebuilding from scratch vs. the ransom. |
| Hour 48 | A decision is made. Either restoration from backups is underway, or you're negotiating payment. | Either way, you're now in recovery mode — and it will take days to weeks, not hours. |
The Pay-or-Restore Decision
This is the decision that defines whether your business survives the attack. And it comes down to one factor almost every time: the state of your backups.
If your backups are intact and recent, you restore from them. You lose whatever was created between the last backup and the attack, but you're back in business. Total cost: downtime, IT labor, and whatever data was lost. No ransom payment. No dealing with criminals.
If your backups were destroyed, encrypted, or never existed, the math changes. You can rebuild from scratch — re-entering data, recreating files, contacting clients — if that's even possible. Or you can pay the ransom, with no guarantee you'll get your data back, and no guarantee the attacker won't leak it anyway. The FBI does not recommend paying, but for many small businesses, it becomes the only viable option.
This is why attackers target backups first. They know that if your backups survive, their leverage disappears.
What Determines Whether a Company Survives
The businesses that survive ransomware attacks share a few characteristics:
- They had working backups that the attackers couldn't reach — typically an air-gapped or offline backup.
- They had cyber insurance, which covered forensic investigation, legal counsel, and recovery costs.
- They acted fast — isolating systems within the first hour rather than hoping it would resolve itself.
- They had an incident response plan, even a basic one, so people knew who to call and what to do.
The businesses that don't survive are the ones without backups, without insurance, and without a plan. For them, the 48-hour timeline above becomes a 48-day timeline of rebuilding, and many never reopen.
Before It Happens: Your Prevention Shortlist
If you take one thing from this article, let it be this: the decisions that determine your ransomware outcome are made before the attack, not during it.
- Implement an air-gapped backup. A backup that's disconnected from your network is a backup ransomware can't reach. This is the single most important control.
- Patch aggressively. Most attacks exploit known vulnerabilities that already have fixes available. Automated patching closes the door.
- Enable multi-factor authentication everywhere. Especially on remote access, email, and any administrative accounts.
- Train your team on phishing. The initial access point is almost always a phishing email. One-click training reduces the risk dramatically.
- Have an incident response plan. A simple document that says who to call, what to disconnect, and where your backups are. It doesn't need to be elaborate — it needs to exist.
- Get cyber insurance. The cost is modest compared to the cost of an attack, and it gives you immediate access to forensic and legal resources.
For a deeper look at prevention, here's how to protect your business from ransomware. An air-gapped backup is the one control that makes recovery possible when everything else fails.
If you want to understand why synced cloud backups aren't enough, read our companion piece on air-gapped backups explained. The short version: if your backup is connected to your network, the ransomware can reach it.
Ransomware is the most destructive threat facing small businesses today, and the difference between surviving it and not comes down to preparation. Dytech Group builds layered defenses and backup strategies for Central Florida businesses. Our data protection services include the offline backup architectures that make recovery possible when everything else fails.
More articles

Cybersecurity
What Hackers Can Do With Just Your Email Address
5 min read

Cybersecurity
Oviedo Managed IT Security Services: What Dytech Group Provides
4 min read

Cybersecurity
Cybersecurity for Law Firms: Protecting Client Data and Staying Compliant
5 min read

Cybersecurity
How Orlando Cybersecurity Companies Protect Businesses From Ransomware
5 min read