If a cyberattack ever hits your business, what you do in the first hour matters more than almost anything that comes after.
It’s also the easiest hour to make a costly mistake — turning off the wrong machine, deleting the evidence, or replying to “IT support” from an email account the attacker’s already sitting inside of.
The steps below tell you exactly what to do, in order, so you’re not guessing while your heart’s racing. None of it requires technical know-how. It just requires knowing the order ahead of time — which is the whole point of reading this now, before you ever need it.
Before anything else: don’t make it worse
Before you touch a single thing, avoid these:
- Don’t turn the affected computer off, if you can help it. Disconnecting it from the network is the better move — powering it down can wipe evidence that helps figure out what actually happened.
- Don’t delete anything. Leave the ransom note, the suspicious email, and any alerts exactly where they are. That’s what your IT team and any investigators will need.
- Don’t pay a ransom on the spot.
- Don’t use the hacked email or account to talk about the attack. If an attacker’s in your inbox, they can read those messages too. Switch to phone calls or a different account entirely.
The step-by-step
Work through these in order, starting the moment you notice something’s wrong.
- Disconnect the affected devices from the network. Unplug the network cable and turn off Wi-Fi on anything that looks affected. This stops the problem from spreading to other computers and to your backups. CISA’s guidance is to isolate devices rather than power them off wherever you can, and only shut one down if there’s no other way to get it off the network.
- Call your IT provider straight away — by phone. Don’t email, in case the attacker’s watching your inbox. If you have cyber insurance, call them next; a lot of policies require you to loop in their incident team early.
- Leave the evidence alone. Don’t wipe, reinstall, or tidy up the affected machines yet. Screenshots of the ransom note or suspicious emails are useful, but hang onto the originals too.
- If money was sent, call your bank immediately. Ask them to recall the transfer and freeze it if they can. With wire and bank fraud, the first few hours make the biggest difference to whether you ever see that money again.
- Reset passwords from a clean device, and turn on multi-factor authentication. Start with email and any admin accounts, and use a device you know isn’t compromised.
- Report it. It can help with recovery, and in some cases it’s legally required. Where you report depends on where you’re located.
Where to report it
- United States: File with the FBI’s Internet Crime Complaint Center (IC3), and report to CISA.
- United Kingdom: Report through the NCSC, and to Action Fraud.
- Australia: Report through ReportCyber, or call the 24/7 hotline at 1300 CYBER1.
If money was wired to a scammer, report it fast — the FBI says reporting wire fraud to IC3 within 72 hours gives its Recovery Asset Team the best shot at clawing it back, and that team recovers funds in roughly 70% of cases reported in time.
If personal data about your customers or staff was exposed, you may be legally required to notify a regulator and the people affected — sometimes within 72 hours. The exact rules depend on where you operate: GDPR in the UK and Europe, state breach-notification laws across the US, and the Notifiable Data Breaches scheme in Australia. Loop in your lawyer or IT provider early so you don’t miss a deadline you didn’t know existed.
Should you pay the ransom?
If it’s ransomware, this is the big question. The FBI does not recommend paying. It doesn’t guarantee you get your files back, it marks you as a business that pays (which invites more attacks), and the money funds the next round of attacks against someone else.
It’s ultimately your call, but it’s a decision to make alongside law enforcement, your IT or incident-response team, and your insurer — not alone, in the first panicked hour. Sometimes a free decryption tool already exists for the exact ransomware that hit you, which is one more reason to get the experts on the phone before you send anyone a dime.
The best time to prepare is before it happens
All of this is a lot easier if some of it’s already decided in advance. You don’t need a thick binder — just a simple plan covering:
- Who to call first (IT provider, insurer) and their numbers, kept somewhere you can reach even without your main systems.
- Where your backups are, and proof they’ve actually been tested by restoring from them.
- Which accounts and devices matter most, so you know what to protect first.
A single page covering those three things is enough for most small businesses — and it’ll save a lot of scrambling if the day ever comes.
Frequently Asked Questions
What’s the first thing to do in a cyberattack?
Disconnect the affected devices from the network — unplug the cable, turn off Wi-Fi — then call your IT provider by phone. Getting the device off the network stops the problem spreading while you get help on the way.
Should I turn off the computer if I get ransomware?
If you can, disconnect it from the network instead of powering it off. Shutting it down can wipe evidence stored in memory that helps figure out what happened. Only power a device off if there’s genuinely no other way to get it off the network.
Should I pay the ransom?
The FBI doesn’t recommend it. Paying doesn’t guarantee you get your data back, and it funds more attacks. Make that call together with law enforcement, your IT or incident-response team, and your insurer — and check whether a free decryption tool already exists first.
We wired money to a scammer. What do we do?
Call your bank immediately and ask them to recall the transfer. In the US, report it to the FBI’s IC3 within 72 hours — reported that quickly, their Recovery Asset Team recovers the money in about 70% of cases. Elsewhere, contact your bank and your national reporting service right away.
Who do I report a cyberattack to?
In the US: the FBI’s IC3 and CISA. In the UK: the NCSC and Action Fraud. In Australia: ReportCyber. Also tell your cyber insurer, and check whether you’re legally required to notify a regulator if personal data was exposed.
Graham’s Take
Most of the businesses I’ve helped after an attack didn’t have a plan — they had a scramble. The ones that came through it in the best shape were the ones who already knew who to call and where their backups actually lived. That’s worth having in writing before you ever need it, and it’s part of what we walk through in a free checkup.


