Incident Response
The first 90 minutes of a ransomware event
Tomás Reyes · 22 Apr 2026
A breakdown of the decisions that determine containment scope, drawn from anonymised patterns across Merrow's retainer caseload.
Almost every ransomware engagement we've run shares the same pattern in its first 90 minutes: a narrow window where containment scope is still genuinely a choice, followed by a much longer period where the team is managing consequences of decisions already made.
The single highest-leverage decision in that window is usually the least technical one — who has the authority to isolate a segment without waiting for a change-approval process built for a calmer day. Firms with a pre-agreed incident authority structure consistently contain faster than firms with excellent tooling and no such structure.
None of this is an argument against good detection tooling. It's an argument that tooling without a rehearsed decision process just gets you a faster, better-documented version of the same outcome.
Related reading
Detection Engineering
Alert volume is not a security metric
Why the number of alerts a platform generates tells you almost nothing about whether your organisation is actually safer.
Elena Marsh · 2 Jun 2026
Compliance
DORA is a resilience test, not a compliance checkbox
What actually changes operationally for UK-serving financial firms under DORA, beyond the paperwork.
Merrow Research Team · 14 May 2026