Ransomware Response: What to Do in the First 60 Minutes
The first hour of a ransomware incident is about containment, evidence preservation and communication — not improvising a payment decision.
Security decisions should protect accounts, reduce excessive software permissions and preserve a path to recovery. Authentication, backups and incident response are complementary tasks, not interchangeable fixes. The right first action depends on what you know about the threat.
Use phishing-resistant credentials when supported and plan recovery before losing a device. Assess browser extensions by the permissions necessary for their functions. An apparent deepfake is best evaluated through provenance and corroboration, not isolated image artifacts.
Review browser access lists, test real data restoration and maintain a response procedure for suspected compromise. Avoid claims of guaranteed detection or total privacy. When an incident is active, preserve relevant evidence and follow trusted organizational escalation processes.
The first hour of a ransomware incident is about containment, evidence preservation and communication — not improvising a payment decision.
Extensions can be extremely useful, but broad permissions may expose browsing data and page contents. A five-minute audit reduces unnecessary access.
Visual glitches are becoming a weaker test for synthetic media. Provenance, context and independent verification are increasingly more useful than trying to spot a strange blink.
Passkeys replace shared secrets with cryptographic credentials tied to your devices. The result can be both easier logins and stronger resistance to phishing.
Compare passkeys, two-factor authentication, security keys and synced credentials, including phishing resistance and recovery when devices are lost.
A few practical browser changes can reduce tracking and security exposure without making the web painful to use.
Protect irreplaceable family photos using independent copies, offsite storage, privacy safeguards and real restore tests.
Learn more about our editorial standards and institutional byline.
Reporting, explainers and practical analysis.
The first hour of a ransomware incident is about containment, evidence preservation and communication — not improvising a payment decision.
Passkeys replace shared secrets with cryptographic credentials tied to your devices. The result can be both easier logins and stronger resistance to phishing.
Visual glitches are becoming a weaker test for synthetic media. Provenance, context and independent verification are increasingly more useful than trying to spot a strange blink.
A few practical browser changes can reduce tracking and security exposure without making the web painful to use.
Extensions can be extremely useful, but broad permissions may expose browsing data and page contents. A five-minute audit reduces unnecessary access.