What to Do in Case of a Cyberattack (Step by Step)

hacker typing on a laptop lego style

The first hour after a cyberattack matters. Quick action can limit the damage, protect your backups, and give investigators a better chance of finding out what happened.

It is also an easy time to make a costly mistake. You might turn off the wrong computer, delete useful evidence, or send an email through an account the attacker can still read.

You do not need deep technical knowledge to take the first steps. You need a clear order of action and the right phone numbers.

This guide explains what to do during the first hour. It also covers where to report an attack in the United States, United Kingdom, and Australia.

What Not to Do After a Cyberattack

Pause before you start trying to fix the problem. A rushed action may destroy evidence or warn the attacker that you have found them.

Do Not Turn Off the Affected Computer

Disconnect the computer from the network instead, if you can. Unplug its network cable and turn off its Wi-Fi.

Turning off a computer can remove evidence stored in its memory. That evidence may help your IT provider or an investigator learn how the attack happened.

CISA advises businesses to isolate affected devices when possible. Shut down a device only when you cannot disconnect it from the network in another way.

Do Not Delete or Clean Up Anything

Leave ransom notes, strange emails, alerts, and unusual files where they are. Do not delete them or move them to the trash.

Do not wipe the computer or reinstall its software. Your IT or incident response team may need the original evidence.

You can take screenshots of what you see. Keep the original message or alert in place as well.

Do Not Pay a Ransom Right Away

A ransom note often creates fear and urgency. Do not let that pressure force a quick payment.

Paying does not ensure that you will get your files back. A free decryption tool may also exist for the type of ransomware involved.

Speak with law enforcement, your IT or incident response team, and your cyber insurer before making a decision.

Do Not Discuss the Attack Through a Hacked Account

An attacker inside your email account may be reading new messages. They may learn what your team knows and how it plans to respond.

Use phone calls or a separate, trusted account to discuss the incident. Do not use the affected email system until your response team says it is safe.

What to Do During the First Hour

Work through these steps in order. Stay calm, keep notes, and avoid making changes that your response team has not approved.

1. Disconnect Affected Devices From the Network

Start with any computer, server, or other device that shows signs of an attack. Signs may include a ransom note, locked files, strange alerts, or activity you did not start.

Unplug the network cable. Then turn off Wi-Fi on the device. This can stop the attack from reaching other computers or connected backups.

Do not power off the device if you can isolate it another way. If you cannot disconnect it from the network, shutting it down may be the only option.

Focus on the devices that appear affected. Your IT team can help decide whether other systems must also be isolated.

2. Call Your IT Provider by Phone

Call your IT provider or incident response team as soon as the affected devices are isolated.

Use the phone. Do not rely on company email because the attacker may have access to it.

Tell the provider what you saw, when you noticed it, and which devices appear affected. Explain what actions you have already taken.

If your business has cyber insurance, call the insurer next. Many policies require the insurer’s incident team to become involved early.

Follow the process in your policy. Starting work without the insurer’s approval may create problems with covered costs or approved vendors.

3. Protect the Evidence

Leave the affected devices and messages alone. Do not wipe, reset, reinstall, or tidy them.

Take clear photos or screenshots of ransom notes, suspicious emails, and alerts. Record the time you first saw the problem.

Write down who noticed the incident and what they were doing at the time. Keep a simple record of every action your team takes.

This information can help your IT provider, insurer, and investigators understand the attack. It may also support any report your business must make.

4. Call Your Bank if Money Was Sent

If your business sent money to a scammer, call the bank at once. Ask the bank to recall the transfer and freeze the funds if possible.

Do not wait for a full technical review. The first few hours can make the biggest difference in wire and bank fraud cases.

Give the bank the payment date, amount, receiving account, and any messages linked to the transfer. Keep a record of the person you spoke with and the case number.

If you are in the United States, report the fraud to the FBI’s Internet Crime Complaint Center, or IC3, as soon as possible.

5. Reset Key Passwords From a Clean Device

Use a device that you know is not affected. Do not reset passwords from a computer that may contain malware or be under the attacker’s control.

Start with email and administrator accounts. These accounts often provide access to other systems and password reset messages.

Create new, unique passwords. Turn on multi-factor authentication where it is not already active.

Work with your IT team before changing many accounts at once. Password changes can affect evidence, active sessions, and the wider response plan.

6. Report the Attack

Reporting may help with recovery. It may also be required by law, your insurer, or a contract.

The right reporting service depends on where your business operates. You may need to contact more than one group.

Where to Report a Cyberattack

United States

File a report with the FBI’s Internet Crime Complaint Center, known as IC3. You can also report the incident to CISA.

Fast reporting is vital when money has been wired to a scammer. The FBI says reporting wire fraud to IC3 within 72 hours gives its Recovery Asset Team the best chance to recover the funds.

The team recovers money in about 70 percent of cases reported in time.

United Kingdom

Report the attack through the National Cyber Security Centre. You should also report it to Action Fraud.

Keep the reference numbers from each report. Your insurer, lawyer, or other advisers may need them.

Australia

Report the incident through ReportCyber. You can also call the 24-hour hotline at 1300 CYBER1.

Contact your bank at once if the attack involved a payment or transfer. Do not wait until you complete the online report.

When Personal Data Is Exposed

A cyberattack may expose information about your staff, customers, or other people. If that happens, your business may have a legal duty to report the breach.

Some rules require notice to a regulator and the affected people. Certain deadlines can be as short as 72 hours.

The rules depend on where you operate. They may include GDPR requirements in the United Kingdom and Europe, state breach laws in the United States, or the Notifiable Data Breaches scheme in Australia.

Speak with your lawyer, IT provider, and insurer early. They can help you find which rules apply and avoid a missed deadline.

Do not make a public statement or contact affected people until you have clear advice. The facts may change as the investigation continues.

Should Your Business Pay a Ransom?

The FBI does not recommend paying a ransom. Payment does not promise a working key or the return of your data.

A payment may also show attackers that your business is willing to pay. The money can help fund more attacks.

Still, the final choice belongs to the business. It should not be made by one person during the panic of the first hour.

Discuss the choice with law enforcement, your IT or incident response team, your insurer, and your legal adviser. Check whether a free decryption tool exists for the exact ransomware strain.

Your team must also consider whether the payment itself could create legal or insurance concerns. Get expert advice before sending money or speaking with the attacker.

Prepare Before an Attack Happens

A short plan can save valuable time. Most small businesses do not need a thick response binder. A clear one-page guide is a strong start.

Keep an Offline Contact List

List the phone numbers for your IT provider, cyber insurer, bank, lawyer, and key leaders.

Keep the list somewhere you can reach without your normal systems. A printed copy may help if company files and email are not available.

Make it clear who should call each contact. Review the numbers on a regular schedule.

Know Where Your Backups Are

Record where backups are stored and who can reach them. Make sure an attack on your main network cannot also destroy every backup.

Test the backups by restoring data from them. A backup is only useful if your team can recover the files when needed.

Keep proof of the latest test. Note what was restored, how long it took, and whether any problems appeared.

Identify Your Most Important Systems

List the accounts, computers, devices, and data that matter most to the business.

Email and administrator accounts may need early protection. Finance systems, client data, and key business apps may also need priority.

This list helps your team decide what to isolate, protect, and restore first.

Practice the First-Hour Plan

Walk through the plan with your staff. Make sure they know how to disconnect a computer from Wi-Fi and where to find the contact list.

The exercise does not need to be complex. A short practice session can reveal missing phone numbers, unclear roles, or backups that no one knows how to reach.

Update the plan whenever your providers, systems, or key staff change.

Frequently Asked Questions

What Is the First Thing to Do During a Cyberattack?

Disconnect affected devices from the network. Unplug their network cables and turn off Wi-Fi. Then call your IT provider by phone.

Isolation can help stop the attack from spreading while you get expert help.

Should I Turn Off a Computer With Ransomware?

Disconnect it from the network instead, if possible. Turning it off can remove evidence stored in memory.

Power it off only if you cannot isolate it from the network in another way.

Should I Pay the Ransom?

The FBI does not recommend paying. Payment does not ensure that you will recover your data, and it funds further attacks.

Make the decision with law enforcement, your response team, your insurer, and your lawyer. Check for a free decryption tool first.

What Should I Do After Sending Money to a Scammer?

Call your bank right away. Ask it to recall the transfer and freeze the funds if possible.

In the United States, report the fraud to IC3 within 72 hours. Fast reports give the FBI’s Recovery Asset Team the best chance to help.

Who Should Receive a Cyberattack Report?

In the United States, report to IC3 and CISA. In the United Kingdom, use the NCSC reporting service and Action Fraud. In Australia, use ReportCyber or call 1300 CYBER1.

Also contact your cyber insurer. Ask for legal advice if personal data may have been exposed.

Create Your First-Hour Response Plan

The first steps are simple. Isolate affected devices. Call your IT provider by phone. Protect the evidence. Contact your bank at once if money was sent. Reset key passwords from a clean device, then make the required reports.

Write those steps and your key phone numbers on one page. Store it outside your main systems. That small amount of preparation can prevent delay and costly mistakes when every minute matters.

Related articles

You may also be interested in

Cookie policy
We use our own and third party cookies to allow us to understand how the site is used and to support our marketing campaigns.

Headline

Never Miss A Story

Get our Weekly recap with the latest news, articles and resources.

Headline

Never Miss A Story

Get our Weekly recap with the latest news, articles and resources.
Cookie policy
We use our own and third party cookies to allow us to understand how the site is used and to support our marketing campaigns.

Hot daily news right into your inbox.