Home 9 Business 9 What to do in case of a cyber attack

What to do in case of a cyber attack

Cyberattack? Here’s Exactly What Your Business Should Do in the First Hour

It’s 2pm on a normal Monday.

Your team are busy working, emails are flowing, and everything seems normal. Then suddenly something isn’t right.

Files won’t open. Systems are running strangely. A ransom note appears on screen. Staff start reporting login issues.

If your business experiences a cyberattack, what happens in the next hour can have a huge impact on how quickly you recover, how much the incident costs, and whether valuable data can be protected.

The good news is that you don’t need to be a cybersecurity expert to take the right first steps.

This guide explains exactly what to do, what not to do, and how to minimise damage while help is on the way.


Before Anything Else: Don’t Make Things Worse

When something suspicious happens, it’s natural to react quickly. Unfortunately, some of the most common reactions can make recovery more difficult.

Before touching anything, avoid these mistakes:

  • Don’t immediately switch the affected computer off. If possible, disconnect it from the network instead. Powering down can remove valuable evidence that helps identify how the attack happened.
  • Don’t delete suspicious files, emails or ransom notes. Your IT team may need them during the investigation.
  • Don’t pay a ransom immediately. Payment doesn’t guarantee your files will be returned and may encourage further criminal activity.
  • Don’t use potentially compromised email accounts to discuss the attack. If attackers have access to your mailbox, they may be reading those conversations.

Your First-Hour Cyberattack Response Plan

1. Disconnect Affected Devices From The Network

Your first priority is containment.

If a device appears compromised, disconnect it from the network immediately by:

  • Removing the network cable
  • Disabling Wi-Fi
  • Disconnecting VPN connections

This helps stop malware or ransomware spreading to file servers, backup systems and other devices across your organisation.

Think of it as closing a fire door before a fire spreads throughout a building.

2. Contact Your IT Provider Immediately

Pick up the phone and call your IT support provider straight away.

A cyberattack is rarely the time for email, particularly if email accounts may have been compromised.

An experienced IT team can quickly determine:

  • Whether the attack is still active
  • How many systems have been affected
  • Whether backups remain safe
  • What immediate containment measures are needed
  • Whether legal or regulatory reporting requirements apply

If you have cyber insurance, notify your insurer as soon as possible as well. Many policies require incidents to be reported quickly and may provide access to specialist response teams.

3. Preserve Evidence

One of the biggest mistakes organisations make is trying to fix the problem themselves before the investigation begins.

Avoid:

  • Reinstalling software
  • Deleting files
  • Running multiple clean-up tools
  • Restoring backups prematurely

If safe to do so, take screenshots or photographs of error messages, ransom notes and unusual activity, but leave the original evidence in place.

The more information available, the better chance your IT team has of understanding what happened and preventing it from happening again.

4. If Money Has Been Sent, Call Your Bank Immediately

If attackers have tricked someone into transferring funds through invoice fraud or a compromised email account, speed is critical.

Contact your bank immediately and ask whether the payment can be frozen, recalled or recovered.

The first few hours often provide the best opportunity to stop funds reaching criminal accounts.

5. Change Passwords Using A Trusted Device

If there is any possibility that accounts have been compromised, begin changing passwords from a device you know is unaffected.

Prioritise:

  1. Email accounts
  2. Administrator accounts
  3. Microsoft 365 accounts
  4. Banking platforms
  5. Business-critical applications

Where it isn’t already enabled, switch on Multi-Factor Authentication (MFA) immediately. MFA remains one of the most effective ways to prevent unauthorised access to business accounts.

6. Report The Incident

Reporting cybercrime helps authorities track threats and may be necessary to meet regulatory obligations.

United Kingdom

  • National Cyber Security Centre (NCSC)
  • Action Fraud

United States

  • Internet Crime Complaint Center (IC3)
  • Cybersecurity and Infrastructure Security Agency (CISA)

Australia

  • ReportCyber

If personal data has been exposed, additional reporting requirements may apply depending on where your organisation operates.

 


What If Customer Or Employee Data Has Been Exposed?

A cyberattack isn’t just an IT issue. It can quickly become a legal and reputational challenge too.

Under UK GDPR, organisations must report certain personal data breaches to the Information Commissioner’s Office (ICO) within 72 hours of becoming aware of the incident where there is a risk to individuals’ rights and freedoms.

If customer records, payroll information, HR data or other sensitive information may have been exposed, seek advice from your IT provider and legal advisers immediately.

The earlier you assess the situation, the easier it is to meet notification deadlines and protect those affected.


Should You Pay The Ransom?

This is often the question everyone asks first.

In reality, there is rarely a simple answer.

However, law enforcement agencies and cybersecurity specialists generally advise against paying because:

  • There’s no guarantee your data will be returned
  • Criminals may retain copies of your information
  • Paying can make your organisation a future target
  • The money helps fund further criminal activity

Before making any decision, speak to your IT provider, insurer and relevant authorities.

In some cases, recovery can be achieved through backups or specialist decryption tools without paying attackers at all.


The Best Time To Prepare Is Before An Attack Happens

The organisations that recover fastest are usually not the lucky ones. They’re the prepared ones.

Every business should have a straightforward incident response plan that includes:

  • Who to call first
  • Emergency contact numbers
  • Backup locations and testing records
  • Insurance information
  • Recovery priorities
  • Key systems and accounts

It doesn’t need to be a complex document. A simple one-page plan can save valuable time when every minute counts.


Frequently Asked Questions

What’s the first thing I should do during a cyberattack?

Disconnect affected devices from the network and contact your IT support provider immediately. Containing the issue quickly helps prevent further damage.

Should I switch off a ransomware-infected computer?

Not usually. If possible, disconnect it from the network instead. Powering the device off can remove evidence that may help identify the type of attack and how it entered your systems.

Should I pay the ransom?

Most cybersecurity experts and law enforcement agencies advise against paying. Speak with your IT provider, insurer and legal advisers before making any decision.

What if we’ve transferred money to a scammer?

Contact your bank immediately and ask whether the payment can be frozen or recalled. The sooner you act, the better the chance of recovery.

Who do I report a cyberattack to in the UK?

Businesses should report incidents to the National Cyber Security Centre (NCSC) and Action Fraud. Additional reporting to the ICO may be required if personal data has been compromised.


Need Help Strengthening Your Cyber Defences?

Cyberattacks can happen to organisations of any size, but the businesses that recover quickest are usually the ones that have prepared in advance.

At Bespoke IT Solutions, we help organisations across Hampshire, Surrey, Berkshire and the South East improve their security posture, protect Microsoft 365 environments, implement robust backup solutions and develop practical cyber resilience strategies.

Whether you’re looking to achieve Cyber Essentials certification, strengthen your cybersecurity, improve your backup and disaster recovery plan, or simply gain confidence that your business is protected, our team is here to help.

Speak to Bespoke IT Solutions today for a friendly, no-obligation conversation about protecting your business from modern cyber threats.

Recent Posts

Could a Cyber Criminal Send Emails Pretending to Be You?

Could a Cyber Criminal Send Emails Pretending to Be You?

Could a Cyber Criminal Send Emails Pretending to Be Your Company Today? Imagine one of your customers receives an email from what appears to be your accounts department. The branding looks correct. The signature looks genuine. The email address seems legitimate. The...

How Outsourcing Is Driving Innovation in UK Businesses

How Outsourcing Is Driving Innovation in UK Businesses

Beyond Cost Savings: Outsourcing for Innovation Why UK businesses are turning IT partners into growth drivers The problem For a long time, outsourcing was just about saving money. You handed over IT tasks, reduced costs, and kept things running. But today, that...

How secure is your backup solution?

How secure is your backup solution?

Immutable Backups: The Cyber Insurance Question That Catches Businesses Out Immutable backups are now one of the most important parts of cyber insurance and ransomware protection. However, many businesses are not sure what they are or whether they already have them in...

Small businesses are still targets of cyber attacks.

Small businesses are still targets of cyber attacks.

A ransomware attack on a small business does not happen overnight. Instead, it builds step by step, often starting with simple mistakes that go unnoticed. In fact, many attacks succeed because of small gaps rather than complex hacking. So in this guide, we will walk...

Microsoft 365 Copilot: Why Permissions Matter More Than You Think

Microsoft 365 Copilot: Why Permissions Matter More Than You Think

Microsoft 365 Copilot: Why Permissions Matter More Than You Think If you’re thinking about using Microsoft 365 Copilot, you’re probably excited about what it can do. But here’s the reality most businesses miss. Copilot doesn’t create new risk. It exposes what’s...

Plan for offboarding from day one.

Plan for offboarding from day one.

Offboarding problems don’t start when someone leaves. They start on day one   When someone leaves your business, things can feel rushed and messy. You’re chasing logins, tracking down devices, and trying to work out what they had access to. However, most of these...

Managing the cloud sprawl.

Managing the cloud sprawl.

Cloud Sprawl Management Take control of your cloud, reduce stress, and let your business grow without the chaos. Cloud sprawl management is now one of the biggest challenges facing growing businesses. While cloud systems help you move faster, they can also create...

FortiBleed – Cyber Attack News

FortiBleed – Cyber Attack News

FortiBleed: Why This Cyber Attack Is Different And What You Need To Do Now The problem There’s a new cyber threat making headlines and it’s not what most people expect. FortiBleed is a global campaign targeting Fortinet firewalls and VPN systems. These are the tools...

UK’s Tech Talent Crunch.

UK’s Tech Talent Crunch.

UK Tech Talent Shortage Solutions Why hiring is harder than ever and what you can do about it If you’re struggling to hire IT staff, you’re not alone. Many businesses across the UK are facing the same challenge. UK tech talent shortage solutions are now essential for...

Outsourcing Is Changing – And It’s Becoming a Growth Strategy

Outsourcing Is Changing – And It’s Becoming a Growth Strategy

Strategic IT Outsourcing UK: A Smarter Way to Grow The problem: many UK businesses are under pressure. Costs are rising, skilled IT staff are hard to find, and keeping systems secure is getting harder. The answer: strategic IT outsourcing UK gives you access to expert...