Blog · Straitwatch SOC

What a ransomware crew does in the first 24 hours of a hit (and how a 24/7 SOC contains it)

A minute-by-minute map of the first day of a ransomware incident, anchored to the SMB healthcare and defense-sub segments Straitwatch serves and the regulatory clock that starts the moment encryption begins.

Ransomware crews do not improvise. They run playbooks, the same ones your EDR vendor studies when it writes a new signature, the same ones your insurer quotes when it sets your premium. The first 24 hours of a hit are not chaos for the attacker; they are a sequence of decisions your environment has already made for them. The job of a 24/7 SOC is to break that sequence, hour by hour, before the second sunrise.

For SMB healthcare and defense-sub contractor environments the math is even worse, because the clock that matters most is not the one on the wall — it is the regulatory one. The HIPAA breach-notification rule at 45 CFR §164.404 starts running the moment encrypted ePHI crosses the perimeter, and a CMMC L2/3 subcontractor has 72 hours to report a CUI incident to the prime. A SOC that is asleep at hour zero is a SOC that has already lost the difference between "incident" and "reportable incident."

Hours 0–4: the foothold becomes an intrusion

A modern intrusion is almost never a single payload dropped on a single endpoint. The first four hours are the lateral-move window: an initial-access operator hands off to a hands-on-keyboard operator, who enumerates Active Directory, hunts for backup credentials, and stages the encryption tooling in a non-critical subnet before it is moved to a critical one. Anyone who runs an MSSP knows this pattern, because this is exactly when log volume spikes with no corresponding user story.

For a multi-site healthcare practice on a shared EHR, those four signals are the early warning that an attacker is moving toward the segment that holds the patient schedule. For a Tier-2/Tier-3 defense sub, those four signals are the early warning that an attacker is hunting for the CUI enclave that lives behind the perimeter firewall. In both cases, the SOC is in triage at hour two, not escalation at hour twelve.

Hours 4–12: containment, or the door closes

Between hour four and hour twelve the SOC has to decide two things at once: which endpoints to isolate, and which identities to rotate. The wrong move on either is the difference between "containment" and "second wave." A 24/7 SOC — analyst-staffed, not the After-Hours-AI-only queue some vendors run — is the venue where that decision gets made with named, attributable escalation rather than an automated playbook alone.

Hours 12–24: the regulatory clock has already started

By the time the first 24 hours close, the SOC has either contained the blast radius or it has not, and the regulatory clock is already running regardless of which side of that line you are on. HIPAA at §164.404 gives a covered entity up to 60 days to notify affected individuals, but the clock to notify HHS starts the moment the entity confirms the incident, and the clock to notify prominent media kicks in once a single-state breach hits 500 affected individuals. State regimes layer on top: California, Colorado, Connecticut, and Virginia each have their own deadline that may be shorter than the federal one.

For a defense subcontractor the parallel clock is the 72-hour DFARS / CMMC incident-reporting obligation to the prime, and the need to preserve CUI-handling evidence intact during the investigation itself. A SOC that has been asleep for the first 24 hours is going to spend the second 24 hours reconstructing logs rather than preparing the assessor-facing chronology — and that is the gap that loses the next contract.

What a 24/7 SOC actually contains by hour 24

Containment is not "we isolated an endpoint and went home." Containment by sunrise on day two looks like: the same analyst on shift that owns the alert owns the post-incident note; the affected identities are rotated and the old refresh tokens are revoked; the impaired subnet is on a separate routing instance with no path to the EHR or the CUI enclave; the immutable backup has been smoke-tested on a one-host sample; the regulatory clock has been annotated in the case file with what was confirmed and what remains to be confirmed. That is what "named analyst on the call" buys you that an AI-only After-Hours queue does not.

Straitwatch runs that SOC posture against the SMB healthcare and defense-sub segments the mixed buyer profile names — regional healthcare practices with shared EHRs and HIPAA + state privacy on the table, and Tier-2 / Tier-3 primes handling CUI who need assessment-ready artifacts rather than promises. The Compliance tier is the same SLAs, the same artifacts, the same Day-14 audit-ready baseline at a wider framework scope.

Frequently asked questions

What counts as a "breach" under HIPAA for our SOC to report?
Under 45 CFR §164.402, a breach is the unauthorized acquisition, access, use, or disclosure of unsecured ePHI that compromises its privacy or security — with a low probability-of-compromise exception the covered entity must justify in writing. The SOC job is to preserve the post-incident record well enough that the covered entity can run that analysis within the §164.404 notification window, not to make the legal call itself.
How long do we actually have to notify after a ransomware hit?
HIPAA gives a covered entity up to 60 days from the date of discovery to notify affected individuals, but the clock is per-incident and starts the moment the entity confirms the breach. HHS must be notified sooner (within 60 days for breaches affecting fewer than 500; annually for smaller breaches). State regimes layer on top — California, Colorado, Connecticut, and Virginia each have their own windows, and they may be shorter than HIPAA. A 24/7 SOC is what gets the confirmation step right within the first 24 hours.
Does paying the ransom change anything for the audit?
No. Paying the ransom does not reduce, defer, or eliminate a covered entity's HIPAA notification obligation; nor does it undo the §164.404 clock once the breach is confirmed. The 24/7 SOC containment work is what controls how much of that notification runs from a real chronology rather than a post-hoc reconstruction.
Do we need CMMC if we are not yet a defense sub?
If you handle CUI in support of a DoD contract indirectly through a prime or sub — even at the Tier-3 level — CMMC L2 (or a C3PAO-assessed L3, depending on the bid) applies before the next contract goes in front of your quote. The SOC posture that audits cleanly at CMMC L2 is also the SOC posture that runs CMMC L3 well, and the same artifact set is what an SBA-accredited lender or a state regulator will ask for separately.
See pricing
Essentials, Pro, or Defense — pick the tier that matches the framework list you have to answer for and we will show you the artifacts you would already have by Day 14.