If a cyberattack hits your business, what you do in the first hour matters more than almost anything that follows. It’s also the easiest time to make a costly mistake: powering off the wrong machine, deleting evidence, or replying from an email account the attacker is already reading.
None of the steps below require technical knowledge. They just require doing them in order, so you’re not guessing in the moment.
Before Anything Else, Don’t Make It Worse
A few instincts that feel helpful actually aren’t. Don’t turn the affected computer off if you can avoid it; disconnecting it from the network is better, because powering down can wipe evidence in memory that helps figure out what happened. Don’t delete anything: leave the ransom note, the suspicious email, and any alerts exactly where they are. Don’t pay a ransom on the spot. And don’t use the hacked email or account to discuss the attack; if an attacker is in your inbox, they can read those messages too. Switch to phone calls or a separate account.
The Steps, in Order
Disconnect the affected devices from the network. Unplug the network cable and turn off WiFi on anything that looks affected. This stops the problem from spreading to other machines and to your backups. CISA’s guidance is to isolate rather than power down where possible, and shut a device off only if there’s no other way to get it off the network.
Call your IT provider immediately, by phone, not email, in case the attacker is watching your inbox. If you have cyber insurance, call them next; many policies require involving their incident response team early, and skipping that step can complicate a claim later.
Leave the evidence alone. Don’t wipe or reinstall anything yet. Screenshots of the ransom note or suspicious emails are useful, but keep the originals too.
If money was sent, call your bank immediately and ask them to recall and freeze the transfer if possible. With wire and bank fraud, acting in the first few hours makes the biggest difference in whether it’s recoverable.
Reset passwords from a clean device you know isn’t affected, and turn on MFA if it isn’t already, starting with email and any admin accounts.
Report it. Reporting can help with recovery and is sometimes legally required, depending on what was exposed and where you operate.
Where to Report It
In the US, that’s the FBI’s Internet Crime Complaint Center (IC3) and CISA. In the UK, the NCSC and Action Fraud. In Australia, ReportCyber or the 24/7 hotline.
If money was wired to a scammer, speed matters specifically: the FBI says reporting wire fraud to IC3 within 72 hours gives its Recovery Asset Team the best shot at clawing it back, and that team recovers funds in roughly 70% of cases reported in time.
If personal data about customers or staff was exposed, you may be legally required to notify a regulator and the people affected, sometimes within a specific window. Requirements vary by where you operate: GDPR in the UK and Europe, state breach notification laws in the US, similar schemes elsewhere. Loop in your lawyer or IT provider early so a deadline doesn’t get missed.
Should You Pay a Ransom
If it’s ransomware, this is the question everyone eventually asks. The FBI doesn’t recommend paying. It doesn’t guarantee you get your files back, it marks you as a business willing to pay, and the money funds the next attack.
It’s ultimately your decision, but it’s one to make with law enforcement, your IT or incident response team, and your insurer, not alone in the first panicked hour. Sometimes a free decryption tool already exists for the exact strain that hit you, which is one more reason to get the right people involved before paying anyone.
The Best Time to Prepare Is Before It Happens
All of this is far easier if some of it’s been decided in advance. You don’t need a thick binder, just one page covering who to call first and their numbers, kept somewhere reachable without your main systems, where your backups are and proof they’ve actually been tested, and which accounts and devices matter most so you know what to protect first.
That single page saves a lot of scrambling if the day ever comes. If you don’t have one yet, that’s a straightforward thing to put together, and worth doing before you need it rather than during.