Sound Networks IT Support
Sound Networks IT Services
IT Support
Managed IT Services
Cyber Security
AI
Insights
Company

Request free IT audit

This site uses cookies for functionality and analytics Manage Close

The First Hour After a Cyberattack

What to do, and what not to, before your IT provider arrives

What you do in the first hour after a cyberattack matters. It's also the easiest time to make a costly mistake, such as switching off the wrong machine, deleting evidence, or replying from an email account the attacker is already reading. Below is the order to work through, so you're not guessing in the moment. None of it requires technical knowledge.

Before anything else: don't make it worse

Before you touch anything, avoid these:

  • Don't switch the computer off if you can help it. Disconnecting it from the network is safer, as powering down can wipe evidence.
  • Don't delete anything. Leave the ransom note, suspicious email, or alerts exactly as they are.
  • Don't pay a ransom on the spot.
  • Don't use the hacked account to discuss the attack. Switch to phone calls or a different account.

The step by step process

  1. Disconnect affected devices from the network — unplug the cable and turn off Wi-Fi. CISA recommends isolating devices rather than powering them off, unless there's no other way to get them off the network.
  2. Call your IT provider straight away, by phone, not email. Call your cyber insurer next if you have one, as many policies require early involvement.
  3. Leave the evidence alone. Don't wipe or reinstall yet; screenshots help, but keep the originals too.
  4. If money was sent, call your bank immediately and ask them to recall or freeze the transfer. Speed matters most here.
  5. Reset passwords from a clean device and turn on multi-factor authentication, starting with email and admin accounts.
  6. Report it. This can help with recovery and is sometimes a legal requirement.

Where to report it

This depends on where you're based:

  • United Kingdom: the NCSC, and Action Fraud.
  • United States: the FBI's IC3, and CISA.
  • Australia: ReportCyber, or 1300 CYBER1.

If money was wired to a scammer, act fast: the FBI says reporting within 72 hours gives its Recovery Asset Team the best chance, recovering funds in around 70% of timely cases. If customer or staff data was exposed, you may have to notify a regulator and those affected, sometimes within 72 hours, under rules such as GDPR, US state breach laws, or Australia's Notifiable Data Breaches scheme. Check with your lawyer or IT provider early.

Should you pay the ransom?

The NCSC and FBI advises against it. Paying doesn't guarantee your files back, marks you as a payer, and funds further attacks. It's your decision, but make it with law enforcement, your IT team, and your insurer, not alone — and check whether a free decryption tool already exists first.

Prepare before it happens

A single page is enough for most small businesses, covering:

  • Who to call first, and their numbers, kept somewhere reachable without your main systems.
  • Where your backups are, with proof they've been tested.
  • Which accounts and devices matter most.
Watch Guard network security partner
Datto ticketing and management system
Huntress security partner
Dell Technologies and services
Hyper-V routing technologies
BitDefender defending your hardware
Microsoft 365 professional services
3CX VoIP phone systems
Veeam partner
Signable partner
Cyber Essentials Certification
Power Automate automation workflows
GTIA
Watch Guard network security partner
Datto ticketing and management system
Huntress security partner
Dell Technologies and services
Hyper-V routing technologies
BitDefender defending your hardware
Microsoft 365 professional services
3CX VoIP phone systems
Veeam partner
Signable partner
Cyber Essentials Certification
Power Automate automation workflows
GTIA
Need Help?