ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX · Serving TX, AR, LA, OK & KS
(737) 325-2520

Ransomware Recovery Timeline: What the First 72 Hours Look Like

A realistic outline of the first three days after a ransomware attack on a law firm, from isolation and triage to restoration choices and client communication.

3 min readBy Counsel Cyber Team

Nobody wants to rehearse a ransomware attack, but firms that have thought through the first three days respond better than those improvising. This timeline is a general outline, not a prediction. Real incidents vary widely in scope and speed, and your insurance carrier, counsel and incident response provider will shape decisions.

Think of it as a framework for what needs to happen, in roughly what order.

Hour 0 to 4: Detect and Contain

What happens

Someone notices files that will not open, a ransom note on a screen, or alerts from endpoint monitoring. The first decision is speed. Every minute the infection spreads, more systems are affected.

Priorities

  • Isolate affected systems from the network by disconnecting network cables or disabling Wi-Fi. Do not power off unless advised, as memory may contain useful evidence.
  • Preserve evidence. Do not wipe or reimage anything yet.
  • Call your incident response contacts: IT provider, cyber insurance carrier hotline and breach counsel, following the order in your incident plan.
  • Protect backups. Confirm whether backups are intact and disconnected from the affected network.
  • Disable compromised accounts and, if directed, reset administrative credentials from a clean device.
  • Do not contact the attackers or pay anything without professional guidance.

Hour 4 to 24: Assess and Plan

Scope the damage

Investigators try to determine what happened: how the attacker got in, which systems are encrypted, whether data was stolen, and whether the attacker is still present. This affects both recovery and legal obligations.

Establish command

Name one decision-maker, usually a managing partner, and one coordinator, often the firm administrator. Keep a written log of decisions and timing. Set up an out-of-band communication channel, because email may be compromised or unavailable.

Internal communication

Tell staff what to do and not do: stay off affected devices, avoid rumors, do not discuss externally, and direct client or media questions to a named person. Provide a phone tree.

Think about client matters

Identify deadlines in the next days. If systems are down, attorneys may need to contact courts about extensions, and ABA Model Rule 1.4 on communication with clients is relevant to how and when clients are informed. ABA Formal Opinion 483 discusses obligations after a data breach. Counsel can advise on your state's requirements.

Hour 24 to 48: Eradicate and Begin Restoring

Remove the attacker's access

Restoring systems before eliminating the attacker's foothold invites reinfection. Investigators identify and close the entry point, such as a compromised credential or exposed service, and look for persistence mechanisms.

Decide the restoration approach

Options usually include restoring from clean backups, rebuilding systems from scratch, or, in rare cases and only with expert and legal guidance, obtaining a decryptor. Backups must be verified clean and restored to a clean environment. This is where earlier investment pays off: firms with tested, isolated backups have far more choice.

Prioritize

Use your recovery goals. Typically identity services come first, then email, document and practice management, billing and trust accounting, and then the remainder.

Data theft questions

If data was exfiltrated, counsel will help determine notification duties to clients, individuals, regulators and insurers. Do not guess; legal requirements vary by state and by type of data.

Hour 48 to 72: Restore and Verify

  • Bring priority systems online in stages
  • Verify data integrity and completeness, including document metadata where relevant
  • Force password resets and enforce MFA everywhere
  • Add monitoring to catch any return of the attacker
  • Provide staff with clear instructions for reconnecting devices
  • Prepare initial client communications in coordination with counsel

What Often Goes Wrong

  • Restoring before removing the attacker
  • Backups encrypted because they were reachable
  • No printed contact list when systems are down
  • Confusion about who decides
  • Inconsistent messages to clients
  • Exhausted staff making errors in hour 60

After 72 Hours

Recovery usually continues for days or weeks: cleaning stragglers, completing notifications, reviewing lessons, strengthening controls and updating the incident plan. Hold a blameless review and turn findings into assigned actions with dates.

Prepare Now

  1. Print your incident contact list and store copies offline
  2. Test restores, including a full-system scenario
  3. Run a tabletop exercise with partners
  4. Know your insurance policy's notice requirements
  5. Keep immutable or offline backups

How Counsel Cyber Helps

Counsel Cyber builds recovery plans for law firms, runs tabletop exercises, and provides incident response support. We would rather rehearse with you now than meet you for the first time during an incident.