Hacked

The first hour after discovering a cyberattack is the one that decides how the rest of the story goes. It’s also the hour where panicked, well-meaning people make things worse, shutting down the wrong machine, wiping the one file that would have explained everything, or firing off an email from an account the attacker is quietly reading over their shoulder.

None of what follows requires a computer science degree. It just requires knowing the order of operations before you need them, which is precisely why five minutes now beats fifty minutes of guessing later.

First, Some Things Not to Do

Before you touch a single button, resist the urge to do any of the following:

  • Don’t switch the machine off. Pulling it off the network is usually the safer move,  cutting the power can destroy the digital fingerprints that later explain exactly what happened and how.
  • Don’t clean anything up. That ransom note, that dodgy email, that pop-up alert, leave them exactly where they are. Your IT team and any investigators will want to see them untouched.
  • Don’t rush to pay a ransom. Whatever’s being demanded, it can wait until you’ve spoken to people who deal with this for a living.
  • Don’t discuss the incident over a compromised account. If someone’s inside your inbox, they can read every word you type about catching them. Pick up the phone or use a separate account instead.

The Response Plan, Step by Step

Follow these in sequence from the moment something feels off.

1. Pull the affected devices off the network. Unplug the cable, switch off the Wi-Fi, and isolate anything that looks compromised. This stops whatever’s happening from spreading sideways into other machines or, worse, your backups. Cybersecurity agencies like the US’s CISA generally recommend isolating a device, powering it completely, and only shutting it off entirely if there’s no other way to disconnect it.

2. Phone your IT provider, don’t email them. If the attacker has inbox access, an email tips them off that you’re onto them. If you carry cyber insurance, call your insurer straight after, since many policies require their incident response team to be looped in early. This is the moment where already having a dependable IT support arrangement in place turns a chaotic hour into a controlled one.

3. Preserve the scene. Resist the urge to reinstall software, wipe drives, or “tidy up.” Screenshots of the ransom note or the phishing email are handy, but always keep the originals as well.

4. If funds went out the door, ring your bank immediately. Ask them to recall or freeze the transfer. With wire fraud especially, the first few hours are worth more than everything that follows.

5. Change your passwords from a device you trust, and switch on multi-factor authentication. Start with email and anything with admin access, and do it from a machine you’re confident hasn’t been touched.

6. Report the incident. Beyond being the right thing to do, it can genuinely help your recovery, and in some cases, it’s a legal requirement, not a suggestion.

Who to Report It To

Where you report depends on where your business operates:

United States — Lodge a report with the FBI’s Internet Crime Complaint Center (IC3) and notify CISA.

United Kingdom — Go through the National Cyber Security Centre (NCSC) and Action Fraud.

Australia — Report through ReportCyber, or ring the 24/7 hotline on 1300 CYBER1.

If a payment was wired to a scammer, speed matters enormously. The FBI notes that reporting wire fraud to IC3 within 72 hours gives its Recovery Asset Team the best shot at intercepting the funds, and when businesses report within that window, roughly 70 per cent of cases see some money clawed back.

There’s a second clock running too. If customer or staff data was exposed, you may be legally obligated to notify a regulator and the affected individuals, often within 72 hours. Exactly what applies depends on your jurisdiction, GDPR across the UK and Europe, a patchwork of state breach notification laws in the US, or the Notifiable Data Breaches scheme here in Australia. Loop your lawyer or IT provider in early so a deadline doesn’t slip past unnoticed.

Should You Actually Pay?

If ransomware is involved, this is the question everyone eventually asks.

The FBI’s official position is a firm no. Paying doesn’t guarantee you’ll see your files again, it marks your business out as one willing to pay, and it directly bankrolls the next attack on someone else.

That said, the final call is yours to make, but it shouldn’t be made solo, in a state of panic, an hour after discovering the breach. Bring in law enforcement, your incident response team, and your insurer before deciding anything. It’s also worth knowing that a free decryption tool sometimes already exists for the specific strain of ransomware involved, which is one more reason to get the experts talking before any money changes hands.

The Real Trick Is Preparing Before It Happens

Everything above gets dramatically easier if some of it was decided in advance. You don’t need a lengthy playbook, just a single page covering:

  • Who to call first, your IT provider and your insurer, along with their numbers, stored somewhere you can reach even if your main systems are down
  • Where your backups live, and confirmation they’ve actually been tested by restoring from them, not just assumed to work
  • Which accounts and devices matter most, so there’s no debate in the moment about what to protect first.

That one page is often all a small business needs, and it saves an enormous amount of scrambling if the day ever comes. Putting it together is exactly the sort of groundwork a genuinely proactive managed IT services provider should already be handling for you, long before you ever need to open it.

Conclusion

A cyberattack can happen without warning, so having a clear incident response plan in place before an incident occurs is essential. Knowing who to contact and what steps to take in those critical first minutes can significantly reduce disruption and help your business recover more quickly.

If you’re looking to strengthen your cyber resilience, explore our cybersecurity services or get in touch with us. Our team can help you develop an incident response plan tailored to your business so you’re prepared before an incident happens.

FAQs:

1. What’s the very first thing I should do after spotting a cyberattack?

Disconnect the affected device from the network rather than switching it off, then contact your IT provider by phone so you’re not tipping off an attacker who may be reading your email.

2. Should I turn off an infected computer straight away?

Generally no, disconnecting it from the network is safer, since powering down can erase evidence needed to understand how the attack happened.

3. Is it ever a good idea to pay a ransom?

The FBI advises against it, since payment doesn’t guarantee recovery and funds further attacks. Any decision should involve law enforcement and your insurer, not be made alone.

4. How quickly do I need to report a cyberattack?

As soon as possible. For wire fraud, reporting to the FBI’s IC3 within 72 hours significantly improves the odds of recovering stolen funds.

5. Do I have to tell customers if their data was exposed?

Often, yes. Depending on your location, laws like GDPR or Australia’s Notifiable Data Breaches scheme may require notifying both a regulator and affected individuals within a set timeframe.

6. What should a small business have ready before an attack happens?

A one-page plan listing who to call, where backups are stored and tested, and which accounts and devices are the highest priority to protect.

7. Can my bank help if money was already transferred to a scammer?

Yes, if you act fast. Contact your bank immediately and ask them to recall or freeze the transfer; the first few hours offer the best chance of success.

Original Source: https://www.elevate.au/2026/08/30/what-to-do-in-case-of-a-cyberattack-step-by-step/

By Jack