Skip to content
Merrow

Incident Response

The first 90 minutes of a ransomware event

Tomás Reyes · 22 Apr 2026

A breakdown of the decisions that determine containment scope, drawn from anonymised patterns across Merrow's retainer caseload.

Almost every ransomware engagement we've run shares the same pattern in its first 90 minutes: a narrow window where containment scope is still genuinely a choice, followed by a much longer period where the team is managing consequences of decisions already made.

The single highest-leverage decision in that window is usually the least technical one — who has the authority to isolate a segment without waiting for a change-approval process built for a calmer day. Firms with a pre-agreed incident authority structure consistently contain faster than firms with excellent tooling and no such structure.

None of this is an argument against good detection tooling. It's an argument that tooling without a rehearsed decision process just gets you a faster, better-documented version of the same outcome.