|
Getting your Trinity Audio player ready...
|

If your business experiences a cyberattack, the actions you take in the first hour can have a major impact on how quickly you recover. It’s also the point when well-intentioned decisions can accidentally make the situation worse.
Shutting down the wrong computer, deleting important evidence, or communicating through a compromised email account can all complicate recovery.
This step-by-step guide explains what to do immediately after discovering a cyberattack. The process is straightforward, doesn’t require technical expertise, and can help minimize damage while giving your IT team the best chance of resolving the incident quickly.
Cyberattack Response Plan: Protect the Evidence First
Before you start clicking, restarting, or deleting anything, pause and avoid these common mistakes:
- Don’t power off the affected computer unless absolutely necessary. Disconnecting it from the network is usually the safer option because shutting it down may erase valuable evidence that investigators need.
- Don’t delete files, emails, or ransom notes. Leave everything exactly as you found it so your IT provider can determine what happened.
- Don’t rush to pay a ransom. Paying immediately doesn’t guarantee you’ll recover your files and may make your business a future target.
- Don’t communicate using compromised accounts. If an attacker has access to your email, they may also be reading your conversations. Use a phone call or a different, trusted account instead.
Step-by-Step Cyberattack Response Checklist
Follow these steps in order as soon as you suspect something isn’t right.
1. Isolate the Affected Devices
Disconnect impacted computers from your network by unplugging the network cable or disabling Wi-Fi. This helps prevent malware from spreading to additional devices or backup systems.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recommends isolating infected devices rather than immediately shutting them down whenever possible. Their #StopRansomware Guide provides additional best practices for containing ransomware incidents and protecting critical systems.
2. Contact Your IT Provider Immediately
Call your managed IT provider or internal IT team right away.
Avoid sending emails if you suspect your email environment has been compromised. If your business carries cyber insurance, notify your insurance provider as soon as possible since many policies require early involvement from their incident response team.
3. Preserve the Evidence
Resist the urge to clean up the affected systems.
Don’t reinstall software, erase files, or restore devices until your IT professionals have completed their investigation. Taking screenshots of suspicious messages or ransom notes can be helpful, but always leave the original files untouched.
4. Contact Your Bank if Money Was Sent
If fraudulent payments or wire transfers were made, contact your financial institution immediately.
Banks have the greatest chance of recovering funds when they’re notified within the first few hours after the transaction.
5. Change Passwords Using a Trusted Device
Use a clean, unaffected computer or mobile device to reset passwords.
Prioritize:
- Email accounts
- Administrator accounts
- Banking accounts
- Business-critical applications
If multi-factor authentication (MFA) isn’t already enabled, turn it on during this process.
6. Report the Incident
Reporting a cyberattack may improve your chances of recovery and may also be required under applicable laws or regulations.
The appropriate reporting process depends on where your business operates.
Know Where to Report a Cyberattack
Reporting agencies vary by country:
- United States: Submit a report to the FBI’s Internet Crime Complaint Center (IC3) and notify CISA.
- United Kingdom: Report the incident through the National Cyber Security Centre (NCSC) and Action Fraud.
- Australia: Report the incident through ReportCyber or contact the 24/7 CYBER1 hotline.
If money was transferred during the attack, don’t delay reporting it.
According to the FBI, reporting business email compromise or wire fraud to IC3 within 72 hours gives its Recovery Asset Team the best opportunity to recover stolen funds.
If customer or employee personal information was exposed, your organization may also have legal notification requirements.
Depending on your location, this could include:
- GDPR requirements in the UK and Europe
- State data breach notification laws in the United States
- Australia’s Notifiable Data Breaches (NDB) scheme
Consult your legal advisor and IT provider as early as possible to avoid missing important reporting deadlines.
Should You Pay the Ransom?
When ransomware is involved, deciding whether to pay is often the most difficult question.
The FBI advises against paying because there’s no guarantee you’ll regain access to your files. Paying also encourages future attacks and may identify your business as a willing target.
Before making any decision, speak with:
- Your IT provider
- Your cyber insurance carrier
- Law enforcement
- An incident response specialist
In some cases, free decryption tools already exist for certain ransomware variants, making professional guidance especially valuable before any payment is considered.
The Best Cyberattack Response Starts Before One Happens
Recovering from a cyberattack is much easier when you’ve prepared in advance.
A simple incident response plan should include:
- Contact information for your IT provider, cyber insurance carrier, and key decision-makers.
- Details about your backup systems and confirmation that backups have been tested through successful restores.
- A list of your most critical systems, devices, and business accounts so they can be prioritized during recovery.
You don’t need a lengthy disaster recovery manual. Even a single-page cyber incident response plan can help your business react faster, reduce downtime, and make a stressful situation much easier to manage.
To learn how Twintel can help strengthen your cybersecurity and prepare your business for cyber threats, contact us.
Twintel has grown into an expansive, full team of IT services professionals, acting as the outsourced IT department of non-profits, small to mid-size businesses, and enterprise-level corporations in Orange County, across California, and nationally.
Today, it’s the strength and deep expertise of the Twintel team that drives positive outcomes for clients. Each of the support staff, technicians, and engineers works diligently each day to make sure that the companies served have the seamless, secure, and stable IT environments needed to allow them to pursue their organizational objectives.