
What to Do in Case of a Cyberattack (Step by Step)
The first hour after a cyberattack matters. Quick action can limit the damage, protect your backups, and give investigators a better chance of finding out what happened. It is also an easy time to make a costly mistake. You might turn off the wrong computer, delete useful evidence, or send an email through an account the attacker can still read. You do not need deep technical knowledge to take the first steps. You need a clear order of action and the right phone numbers. This guide explains what to do during the first hour. It also covers where to report an attack in the United States, United Kingdom, and Australia. What Not to Do After a Cyberattack Pause before you start trying to fix the problem. A rushed action may destroy evidence or warn the attacker that you have found them. Do Not Turn Off the Affected Computer Disconnect the computer from the network instead, if you can. Unplug its network cable and turn off its Wi-Fi. Turning off a computer can remove evidence stored in its memory. That evidence may help your IT provider or an investigator learn how the attack happened. CISA advises businesses to isolate affected devices when possible. Shut down a device only when you cannot disconnect it from the network in another way. Do Not Delete or Clean Up Anything Leave ransom notes, strange emails, alerts, and unusual files where they are. Do not delete them or move them to the trash. Do not wipe the computer or reinstall its software. Your IT or incident response team may need the original evidence. You can take screenshots of what you see. Keep the original message or alert in place as well. Do Not Pay a Ransom Right Away A ransom note often creates fear and urgency.




