Article Summary: A cyberattack can move quickly, and the first few decisions matter. Disconnect affected devices from the network, call your IT provider by phone, preserve the evidence, and contact your bank immediately if money was sent to a scammer. This guide walks through the first steps to take, what not to do, and where to report a cyberattack.
A cyberattack can feel overwhelming, especially when your team is trying to figure out what happened, what is still safe to use, and who to call first.
But the first hour matters. A few quick decisions can help limit the damage, protect important evidence, and give your business a better chance of recovering. The wrong steps, like shutting down the wrong device, deleting a suspicious email, or communicating from a compromised account, can make the situation harder to contain.
In this guide, you’ll learn what to do first if your business is hit by a cyberattack, what mistakes to avoid, when to call your IT provider, how to handle possible wire fraud, where to report the incident, and why having a simple response plan in place before an attack can save time, money, and stress. You do not need to be technical to take the right first steps. You just need to know the order to follow.
First cyberattack response mistakes to avoid
Before you start clicking, deleting, restarting, or trying to clean things up, pause.
The goal in the beginning is not to fix everything immediately. The goal is to stop the issue from spreading and preserve the information your IT team may need to understand what happened.
Avoid these mistakes:
- Do not turn the affected computer off if you can avoid it.
Disconnect it from the network instead. Powering it down can remove evidence that may help your IT team or investigators understand the attack.
- Do not delete anything.
Keep the ransom note, suspicious email, alerts, files, and messages exactly where they are. They may be important later.
- Do not pay a ransom in the moment.
- Do not use a hacked email account to talk about the attack.
If an attacker has access to the inbox, they may be able to read those messages. Use a phone call or a separate trusted account instead.
What to do immediately after a cyberattack
Start here as soon as you notice something is wrong.
- Disconnect affected devices from the network.
Unplug the network cable and turn off Wi-Fi on any device that looks affected. This helps keep the issue from spreading to other computers, servers, or backups. CISA recommends isolating affected devices instead of powering them off when possible. Only shut a device down if you cannot disconnect it from the network any other way. - Call your IT provider by phone.
Do not email from an affected account. If an attacker is watching the inbox, they may see your response in real time. Call your IT provider directly so they can help you contain the issue. If you have cyber insurance, call your insurer next, since many policies require their incident-response team to be involved early. - Leave the evidence in place.
Do not wipe, reinstall, clean up, affected devices yet. Take screenshots of ransom notes, suspicious emails, or unusual alerts if you can, but keep the originals where they are. - If money was sent, call your bank immediately.
If your business wired money to a scammer, contact your bank right away. Ask whether they can recall, stop, or freeze the transfer. With wire fraud, acting quickly matters. - Reset passwords from a clean device.
Use a device you know is not affected. Start with email and administrator accounts, and turn on multi-factor authentication if it is not already enabled. - Report the attack.
Reporting can support recovery and may be required depending on what happened, what data was exposed, and where your business operates.
Where to report a cyberattack
Where you report a cyberattack depends on your location.
- United States: FBI’s Internet Crime Complaint Center, also known as IC3, and CISA
- United Kingdom: NCSC and Action Fraud
- Australia: ReportCyber or the 24/7 hotline at 1300 CYBER1
If money was wired to a scammer, report it quickly. The FBI says reporting wire fraud to IC3 within 72 hours gives its Recovery Asset Team the best chance of helping recover funds. The FBI also says that team recovers funds in about 70% of cases reported in time.
If personal data about customers, employees, or other individuals was exposed, your business may also have a legal duty to notify a regulator or the people affected. In some cases, the deadline may be as short as 72 hours.
The rules depend on where your business operates, including GDPR in the UK and Europe, state breach-notification laws in the US, and the Notifiable Data Breaches scheme in Australia. This is why it is important to involve your lawyer, IT provider, insurer, or incident-response team early. You do not want to miss a reporting deadline while trying to figure everything out on your own.
Should your business pay a ransomware demand?
If the attack involves ransomware, the pressure to pay can feel intense. The FBI does not recommend paying a ransom. Paying does not guarantee that your files will be restored. It can also show attackers that your business is willing to pay and help fund more attacks.
That does not make the decision easy. But it does mean the decision should not be made in the first panicked hour. Before paying anyone, involve law enforcement, your IT provider or incident-response team, and your cyber insurer.
There may also be a free decryption tool available for the type of ransomware that affected your business. That is another reason to get expert help before sending money.
How to prepare before a cyberattack happens
A cyberattack is much easier to handle when your business already knows what to do. You do not need a long, complicated document. For many small businesses, a simple one-page response plan is a strong starting point.
Your plan should include:
- Who to call first
Your IT provider, cyber insurer, attorney, and key internal contacts, with phone numbers stored somewhere accessible even if your systems are down.
- Where your backups are
Not only where backups are stored, but whether they have been tested by restoring data from them.
- Which systems matter most
The accounts, devices, applications, and data your business needs to protect first.
When something goes wrong, your team should not have to guess. A simple plan can reduce confusion, protect evidence, and help your business recover faster.
Conclusion
A cyberattack is stressful, but your response does not have to be chaotic.
The most important thing is to act quickly, in the right order. Disconnect affected devices from the network. Call your IT provider by phone. Leave the evidence in place. Contact your bank immediately if money was sent. Then report the attack and involve the right experts before making major decisions.
The best way to reduce damage is to prepare before something happens. Tested backups, strong account security, clear contact information, and a simple response plan can help your business recover faster and avoid costly mistakes in the first hour.
If you are not sure whether your business is ready for a cyberattack, Atekro can help. Contact us today to review your cybersecurity, backups, and incident response plan so your team knows exactly what to do if something goes wrong.
FAQ
What’s the first thing to do in a cyberattack?
Disconnect affected devices from the network by unplugging the network cable and turning off Wi-Fi. Then call your IT provider by phone. Getting the device off the network helps stop the issue from spreading while you get help.
Should I turn off the computer if I get ransomware?
If possible, disconnect it from the network instead of powering it off. Shutting it down can remove evidence stored in memory that may help your IT team understand what happened. Only power the device off if you cannot disconnect it from the network any other way.
Should I pay the ransom?
The FBI does not recommend paying a ransom. Paying does not guarantee that you will get your data back, and it helps fund more attacks. Make that decision with law enforcement, your IT or incident-response team, and your insurer. Also check whether a free decryption tool already exists before paying.
We wired money to a scammer. What do we do?
Call your bank immediately and ask whether they can recall, stop, or freeze the transfer. If you are in the US, report the fraud to the FBI’s IC3 within 72 hours. The FBI says its Recovery Asset Team has the best chance of helping recover funds when wire fraud is reported quickly.
Who do I report a cyberattack to?
In the US, report to the FBI’s IC3 and CISA. In the UK, report through the NCSC and Action Fraud. In Australia, report through ReportCyber. You should also contact your cyber insurer and check whether you have a legal duty to notify a regulator if personal data was exposed.
Love This Article? Share It!
A password manager can streamline your security by storing all your credentials in one encrypted vault, simplifying logins with a single master password. Discover implementation tips for enhancing your digital security.
Ransomware attacks are on the rise, threatening businesses of all sizes. Discover how to defend your business with practical tips on preventing attacks and maintaining resilience.
Gain clarity as an accountant on the FTC Safeguards Rule and its implications for your business's data security. Discover effective strategies to ensure your company meets regulatory standards.
Discover six actionable tech tips to enhance your accounting firm's efficiency and security. From cloud adoption to cybersecurity, stay ahead of the curve.
Discover why Multi-Factor Authentication (MFA) is essential for securing your Microsoft 365 account against cyber threats. With simple setup options safeguard your data effectively.
As a business owner, it's difficult to determine which cybersecurity solutions are essential for your small business. Find the right solutions by considering three primary factors: effectiveness, user impact, price.
Learn about the primary and hidden costs of a ransomware attack that can devastate your business and why proactive cybersecurity measures are essential for safeguarding your company's future.
STAY IN THE LOOP
Subscribe to our free newsletter.


