Ransomware is no longer a rare event for professional services firms. Criminal groups know that law firms hold sensitive data and face tight deadlines, which creates pressure to pay quickly. The best preparation is a plan you have rehearsed. This walkthrough lays out a realistic first 72 hours, based on general incident response practice and CISA's published ransomware guidance. Your own steps should be shaped by your insurer, your counsel and your IT provider.
Consider a hypothetical 25-attorney firm where, at 6:30 on a Tuesday morning, an assistant finds files renamed and a ransom note on the screen. Here is how the first three days should ideally go.
Hour 0 to 1: Contain
- Disconnect affected machines from the network by unplugging network cables or turning off Wi-Fi. Do not power them off unless advised, since memory may hold evidence.
- Call your IT provider and the incident lead by phone. Do not use email if it may be compromised.
- Notify the managing partner, who declares an incident under the plan.
- Do not delete anything, and do not try to run random cleanup tools.
- Isolate backups if possible, so they cannot be reached and encrypted.
Hour 1 to 4: Mobilize
- Call your cyber insurance carrier. Many policies require prompt notice and may direct you to approved forensic and legal vendors. Acting before engaging vendors on your own can matter for coverage.
- Engage breach counsel, ideally through the carrier, so that the investigation can be conducted under privilege where appropriate.
- Start an incident log recording who did what and when.
- Switch communication channels to phones or a pre-arranged messaging group.
- Assess operations: which matters have imminent deadlines, and what can be done manually?
Hour 4 to 24: Scope
Understand what happened
Forensic investigators work to determine how the attacker got in, how long they were present, which systems were affected and whether data was copied out. Many ransomware groups steal data before encrypting, which turns a recovery problem into a confidentiality problem. Scoping drives everything that follows, including notification duties.
Preserve evidence
Take images of affected systems as directed, preserve logs and avoid wiping machines before investigators finish.
Reset credentials carefully
After you know how the attacker entered, reset passwords, revoke tokens, and enforce MFA everywhere. Doing it too early may tip off an attacker who still has access, so follow your responders' advice.
Day 2: Decide how to recover
- Verify the backups. Confirm they are intact and predate the intrusion, since attackers sometimes sit inside for weeks.
- Rebuild before restoring. Restore into a clean, rebuilt environment, not onto systems that may still be compromised.
- Prioritize by your recovery tiers: email, practice management, documents and calendars first.
- Set expectations with partners about realistic timelines. Full recovery may take days.
The ransom question
Paying is a business and legal decision with no guarantee of getting data back or of preventing leaks, and it may raise legal considerations, including sanctions rules. Government guidance generally discourages payment. Decide only with counsel, your carrier and law enforcement input, and never on the attacker's schedule.
Day 2 to 3: Communicate and report
- Clients: ABA Formal Opinion 483 discusses a lawyer's duty to notify current clients when a breach involves material confidential information, and Rule 1.4 addresses keeping clients informed. Counsel should help determine timing and content.
- Regulators and law enforcement: report to the FBI through IC3 or a local field office, and consider CISA reporting. Check state breach notification laws.
- Staff: brief them with clear instructions on what to say and not say.
- Courts and counterparties: if a deadline is at risk, counsel can advise on seeking extensions, with appropriate candor.
Day 3: Stabilize
Begin restoring in priority order, monitor closely for reinfection and keep logging decisions. Plan a post-incident review for the following weeks.
Lessons for preparation
- Keep offline or immutable backups and test restores.
- Enforce MFA on everything, including backup consoles.
- Run monitored endpoint detection.
- Keep the insurance claim number, counsel contacts and plan printed offline.
- Rehearse with a tabletop exercise.
Next steps
Counsel Cyber builds incident response plans, runs tabletop exercises and supports recovery for law firms. Ask us to run a ransomware scenario with your partners so the first 72 hours are not your first attempt.