
This is a representative scenario, not a specific client. It's a composite of how a ransomware response actually unfolds, written to show the order we work in and why. Real incidents vary, and the details here are deliberately general.
A staff member at a Perth office can't open a file. Then another. Someone notices every document has a strange new extension, and a text file has appeared on the desktop with a ransom demand and a countdown. Within a couple of minutes it's clear: this is ransomware, and it's spreading.
What happens in the next hour matters enormously — but here's the honest truth we'll come back to at the end: most of the outcome was decided months ago, by whether the right preparation was in place. Here's how we work the first hour regardless.
Minutes 0–10: contain first, investigate second
The instinct is to figure out what happened. The correct first move is to stop it spreading. Ransomware often keeps encrypting across network shares and connected machines while everyone's still working out what's going on, so we contain before we diagnose:
Isolate affected machines — disconnect them from the network (unplug ethernet, disable Wi-Fi), but do not power them off if we can help it. Shutting down can destroy evidence in memory and, with some strains, corrupt any chance of recovery.
Cut the spread path — disconnect network shares and, if the scale warrants it, isolate the affected part of the network or pull the internet connection so the attacker loses their live foothold.
Protect the backups immediately — this is the single most important early action. If backups are reachable from the encrypted network, modern ransomware hunts for and destroys them first. We make sure the backup system is isolated and intact before it can be touched.
Minutes 10–30: establish scope and stop the attacker's access
With the bleeding stopped, we work out how big it is:
What's encrypted? Which machines, which servers, which cloud data. This tells us how much we're recovering.
How did they get in, and are they still in? A stolen password, a phishing click, an exposed remote-access port. We reset credentials, revoke active sessions and enforce MFA so the attacker can't simply walk back in while we're recovering.
Was data stolen, not just encrypted? This is the part businesses miss. Modern ransomware usually steals a copy of your data before encrypting it, then threatens to leak it — so this isn't only an availability problem, it's potentially a data breach, which in Australia can trigger obligations under the Notifiable Data Breaches scheme. We assess exfiltration early because it shapes everything that follows.
Two things we don't do in this window: panic, and rush to pay. Paying is a last resort that funds crime, often doesn't fully work, and marks you as a payer for next time — and it's almost never necessary if the preparation was there.
Minutes 30–60: begin recovery from clean backups
Once we know the scope and the attacker is locked out, recovery begins:
Verify the backups are clean and pre-infection, then start restoring critical systems and data from the isolated, immutable copy. This is the moment a tested backup earns its entire existence.
Rebuild rather than trust compromised machines — wiping and reimaging is safer than hoping an infected device is "clean now."
Document everything — timeline, systems affected, evidence — for insurers, the OAIC if a notifiable breach applies, and to make sure the same hole is closed for good.
For a business with immutable, tested, offsite backups, this is where a catastrophe turns into a bad day or two: systems come back from a clean copy, the ransom demand becomes irrelevant, and the leverage the attacker was counting on largely evaporates.
Why the first hour is really won months earlier
Here's the uncomfortable part. Two Perth businesses can be hit by the same ransomware on the same morning and have completely different weeks:
The one with immutable offsite backups, EDR, MFA everywhere, network segmentation and patched systems contains it, restores from clean copies, and is back running — no ransom paid.
The one without faces an impossible choice: pay criminals with no guarantee, or lose the data. That's not a technical failure in the first hour; it's the absence of preparation before it.
Every one of those safeguards is exactly what proactive managed security puts in place — and it's why we keep coming back to the same message in pieces like the four IT gaps small businesses overlook and our Essential Eight guide. The Essential Eight controls — patching, application control, MFA, and regular, tested backups — exist precisely because they're what decides the first hour of an incident like this.
The takeaway
If ransomware hit your business this morning, the questions that would decide your week are simple, and you can answer them today: Are our backups immutable, offsite, and — most importantly — have we actually tested restoring from them? Is MFA on everywhere? Is our network segmented so one infected machine can't reach everything?
If you're not sure of the answers, that uncertainty is the risk — and it's fixable calmly now, rather than at 9am on the worst day. Talk to the Computer Mechanics team or call (08) 9325 1196 for an honest review of where you'd stand. We've protected and recovered Perth businesses since 1997, and the goal is always the same: make the first hour a non-event.



