08:47 on a Tuesday. A records clerk on the second floor of a teaching hospital in the South West tries to open a patient's folder and the file will not load. She tries another. Same. Two desks over, a colleague's screen has gone to a plain note demanding payment. Within ninety seconds the same note is on the pharmacy terminal, on the radiology workstation, on the laptop in the matron's office. The encryption is moving faster than anyone in the building can walk. What happens in the next hour decides whether this is a bad week or a closed hospital.
Almost everything written about ransomware picks up after the dust has settled, when there are backups to restore and lessons to number. Nobody rehearses the live hour, the one where the malware is still moving and no one yet knows how far it has reached. And the hospital version carries a cruelty the bank version does not: the obvious move, cutting the network, is the same move that can blank a monitor in theatre while a patient is open on the table.
noticed on the ward
a second department
most of what follows
The first hour, minute by minute
Here is the timeline as it actually runs, not as a plan imagines it. The times are the ones that matter, not the ones that look neat.
T+0, the clerk notices. A file will not open. Her instinct, and almost everyone's, is to reboot the machine. That instinct is wrong, and the reason is forensic: a reboot can flush memory that holds the encryption key and the attacker's live session. The right first act is smaller and harder to think of under pressure. Tell someone. Not the friend at the next desk. The IT duty line, by phone, now.
T+4, the helpdesk gets the call. This is the same hinge a single user faces after clicking a bad link, except multiplied across a building (the individual version is covered in You Clicked the Link: The First 60 Minutes of Phishing Response). The helpdesk's job in these minutes is not to fix anything. It is to size the thing: one machine or twenty, and is it still spreading. A second report from a different department answers that question. It is spreading. That changes the event from a fault to an incident.
T+9, someone has to say the word. A cyber attack on a hospital is a major incident in the same way a building fire is, and someone with the authority must declare it so. In practice this is where Nigerian hospitals lose the most time. The fire procedure has a named person. The cyber procedure, if it exists, often does not, so the duty IT officer hesitates because pulling the network on his own signature feels like a career risk. Decide this on a calm afternoon and write the name down, because at T+9 nobody wants to be the one phoning the Chief Medical Director's mobile to ask permission to take the hospital offline.
The slowest part of the first hour is rarely the malware. It is the silence while everyone waits for someone to be allowed to act.
The network pull, and why a hospital cannot just yank the cable
In a bank, the containment instruction is blunt: isolate the affected segment, pull it now, ask questions later. A hospital cannot reach for that instruction without checking one thing first, and it is the thing that makes healthcare different from every other sector.
Ask what shares the segment you are about to cut. In too many hospitals the answer is everything, because the network was never carved up. The infusion pumps that meter drugs by the millilitre. The patient monitors in the ICU. The theatre's imaging feed. The pneumatic tube that sends blood samples to the lab. If these sit on the same flat network as the records workstations, the disconnect that saves your data can also stop a pump or blank a monitor mid-procedure. So the pull is not one switch thrown by IT. It is a decision made with a clinician in the room, segment by segment: this wing comes off, that one stays up under manual watch until theatre closes the current case. Where the network was segmented in advance, clinical devices on their own VLAN, this whole dilemma shrinks, which is the strongest argument for doing that segmentation while nothing is on fire.
While that call is being made, clinical downtime begins, and it has an order. Theatre and ICU first: confirm every life-supporting device that depends on the network has a manual or standalone fallback, and that staff know which is which. Then emergency, then the wards, then the cold clinics that can simply pause. The point of the order is that you cannot protect everything in the same minute, so protect breathing before you protect billing.
What to preserve before you wipe
By T+30 the temptation in the server room is to start re-imaging machines and get people working again. Resist it for a few more minutes, because the first hour is the only time some evidence exists. Once a machine is wiped, the answers to how they got in and what they took are gone with it, and those answers decide your obligations later.
Three things are worth the wait. Do not power off the first infected machines if you can isolate them instead, by unplugging the network cable rather than the power, since memory holds the live session. Do not delete the ransom note or the email that may have started it. And keep whatever logs you have before they roll over: firewall, domain controller, EMR access logs. Note the time you noticed, who you called, what you switched off. That scribbled record becomes the spine of the report you will owe the Nigeria Data Protection Commission, because a ransomware event that touches patient data is a personal-data breach under the Nigeria Data Protection Act, and the National Health Act treats those records as confidential whether or not they are readable today.
By T+55 the shape of the hour is set. The incident is declared and owned by a named person. The network is coming off in a controlled order with a clinician's hand on it. Theatre and ICU are on known fallbacks. The first machines are isolated, not wiped, and the clock and the call list are written down. None of that has decrypted a single file. What it has done is stop the bleeding and keep the questions answerable, which is the entire job of the first hour.
If you do nothing else before the next one
- Name the declarer now. Write down who is allowed to declare a cyber major incident and authorise the network pull, the same way the fire procedure names a person. The hesitation at T+9 is the most expensive minute of the hour.
- Know what shares the wire. Map which clinical devices sit on the same network as your workstations before an attack forces you to find out. Segmentation done early turns the worst dilemma of the hour into a non-question.
- Isolate, do not power off. Pull the cable, not the plug, on the first infected machines, and leave the ransom note and the logs alone until they are captured. The first hour is the only hour that evidence is still there.
The hour above ends with the hospital still bleeding but in control of the bleed. What comes next, recovery and the harder pay-or-do-not-pay question, is a different decision made in calmer rooms. If your hospital cannot yet say who declares the incident and what shares the clinical network, that is the tabletop exercise to run this quarter, and we can sit through it with your IT and clinical leads together.