The First Hour After a Cyberattack
What to do, and what not to, before your IT provider arrives
What you do in the first hour after a cyberattack matters. It's also the easiest time to make a costly mistake, such as switching off the wrong machine, deleting evidence, or replying from an email account the attacker is already reading. Below is the order to work through, so you're not guessing in the moment. None of it requires technical knowledge.
Before anything else: don't make it worse
Before you touch anything, avoid these:
- Don't switch the computer off if you can help it. Disconnecting it from the network is safer, as powering down can wipe evidence.
- Don't delete anything. Leave the ransom note, suspicious email, or alerts exactly as they are.
- Don't pay a ransom on the spot.
- Don't use the hacked account to discuss the attack. Switch to phone calls or a different account.
The step by step process
- Disconnect affected devices from the network — unplug the cable and turn off Wi-Fi. CISA recommends isolating devices rather than powering them off, unless there's no other way to get them off the network.
- Call your IT provider straight away, by phone, not email. Call your cyber insurer next if you have one, as many policies require early involvement.
- Leave the evidence alone. Don't wipe or reinstall yet; screenshots help, but keep the originals too.
- If money was sent, call your bank immediately and ask them to recall or freeze the transfer. Speed matters most here.
- Reset passwords from a clean device and turn on multi-factor authentication, starting with email and admin accounts.
- Report it. This can help with recovery and is sometimes a legal requirement.
Where to report it
This depends on where you're based:
- United Kingdom: the NCSC, and Action Fraud.
- United States: the FBI's IC3, and CISA.
- Australia: ReportCyber, or 1300 CYBER1.
If money was wired to a scammer, act fast: the FBI says reporting within 72 hours gives its Recovery Asset Team the best chance, recovering funds in around 70% of timely cases. If customer or staff data was exposed, you may have to notify a regulator and those affected, sometimes within 72 hours, under rules such as GDPR, US state breach laws, or Australia's Notifiable Data Breaches scheme. Check with your lawyer or IT provider early.
Should you pay the ransom?
The NCSC and FBI advises against it. Paying doesn't guarantee your files back, marks you as a payer, and funds further attacks. It's your decision, but make it with law enforcement, your IT team, and your insurer, not alone — and check whether a free decryption tool already exists first.
Prepare before it happens
A single page is enough for most small businesses, covering:
- Who to call first, and their numbers, kept somewhere reachable without your main systems.
- Where your backups are, with proof they've been tested.
- Which accounts and devices matter most.