Back to blog
    Cybersecurity

    Ransomware: The First 24 Hours That Decide Whether You Lose Your Data

    The correct order of actions in a ransomware attack: containment, protecting backups, forensics, legal reporting, and staged recovery — and why paying is not a solution.

    September 14, 2026·By the Namra Tech team
    Ransomware: The First 24 Hours That Decide Whether You Lose Your Data

    A ransomware attack does not begin when the ransom note appears — the note is the end of the operation. For days or weeks before it, the attacker was inside the network escalating privileges and quietly destroying your backups. This guide from Namra Tech and the Rased team sets out the order of actions that genuinely limits the damage.

    Hour one — contain, do not investigate: disconnect affected machines from the network without powering them off (shutdown destroys memory-resident evidence), revoke administrative sessions and keys, stop cloud sync so encrypted files do not overwrite clean copies, and temporarily close remote access.

    Hour two — secure the backups: confirm an isolated, immutable copy exists and block all writes to it. The most expensive mistake is a rushed restore onto an environment that has not been cleaned, which lets the attacker encrypt the clean copy too.

    Document in parallel: the ransom note, the encrypted file extension, the earliest timestamp, affected hosts, and the accounts used. This material is the basis of digital forensics, which identifies the entry point — without it the incident repeats after recovery because the vulnerability stays open.

    Why paying is a bad decision: payment guarantees neither a working key nor deletion of the stolen copy, it marks your company as a repeat target known to pay, and depending on the recipient it can create legal exposure. The practical route is recovery from a clean backup with the vulnerability closed, not buying a promise from an attacker.

    Legal duties and reporting: if customer personal data is affected, Egypt's Personal Data Protection Law imposes notification duties within a defined period, and regulated sectors (banking, fintech, healthcare) have additional channels. Decide in advance who signs off on notification and who speaks to customers.

    Recover in stages, not all at once: rebuild a clean environment, reset every password and key, restore the systems the business cannot trade without first (invoicing, inventory, accounting), then the rest under heightened monitoring for two weeks — attackers usually leave a way back in.

    The prevention that would have stopped this: mandatory two-factor authentication on all administrative and remote access, least-privilege user rights, patched systems, 3-2-1 backups with one immutable copy and periodic restore tests, and continuous monitoring that catches lateral movement before the encryption stage — the core job of the Rased operations center.

    Penetration testing and red team exercises surface the same paths an attacker would use, but at a time you choose and in a report you can act on. See also the SOC guide and securing an online store.

    Rased is the cybersecurity arm of Namra Tech, led by Khalid Namra: monitoring, incident response, forensics, and penetration testing. For a live incident or to build a written response plan before one happens, reach us from the contact page or via rasedsolutions.com.

    Cybersecurity

    Business Cybersecurity: Protect Your Data Before the Breach, Not After

    A practical cybersecurity guide for companies: the most common weaknesses, an incident response and ransomware playbook, and when you actually need 24/7 security monitoring.

    Cybersecurity

    Securing an Online Store: Protecting Your Sales and Customer Data

    A practical guide to e-commerce security: admin hardening, payment safety, order fraud detection, backups that actually restore, and a written incident response plan.

    Cybersecurity

    Security Operations Center (SOC): How 24/7 Monitoring Stops a Breach Before It Spreads

    What a SOC actually does, which signals it watches, how to measure detection and response time, and when managed monitoring beats an in-house team.

    شركات برمجة

    أفضل شركة برمجة في المنصورة 2026: معايير الاختيار والأسعار وليه نمرة تك الترشيح الأول

    دليل عملي لاختيار أفضل شركة برمجة في المنصورة 2026: أربع حقائق تتحقق منها قبل الدفع، أسعار برمجة المواقع والمتاجر والأنظمة بالجنيه، وأسئلة تسألها لأي شركة قبل التوقيع.

    SEO

    شركة سيو في مصر 2026: كيف تختار شركة تحسين محركات البحث المناسبة وكم تكلفة خدمات السيو فعلياً

    دليل عملي لاختيار شركة سيو في مصر والخليج: ما تشمله خدمة السيو، معايير الاختيار، أسعار السيو الواقعية 2026، الوعود الكاذبة التي يجب رفضها، وكيف تقيس النتائج بنفسك من Search Console.

    SEO

    GEO: كيف تجعل موقعك يظهر في ChatGPT وPerplexity وGemini في 2026 (دليل عربي عملي)

    دليل تطبيقي لتحسين الظهور في محركات الذكاء الاصطناعي: كيف تقرأ روبوتات GPTBot وClaude موقعك، ملف llms.txt، كتل الإجابة المباشرة، البيانات المنظمة، تماسك الكيان، وكيف تتحقق بنفسك أن المحتوى مقروء.

    About the founder
    Khalid Namra — Entrepreneur & Founder of Namra Tech
    Read the full bio, vision, and the story behind Namra, Octobus, Namra IQ & Forge.

    النسخة العربية: اقرأ الدليل بالعربية

    Frequently Asked Questions

    Need help applying these strategies?

    Talk to us now