What to Do in Case of a Cyberattack (Step by Step)

What to do after a cyberattack shown on a laptop being disconnected from the network

Knowing what to do after a cyberattack is the difference between a bad afternoon and a business-ending disaster. When the panic hits, the first hour decides how much you lose, so this is your calm, no-jargon guide to exactly what to do after a cyberattack, step by step. It is written for small business owners, not IT departments, and it covers what to do if your business gets hacked, how to report a cyberattack, and how to get back to work afterward.

What to do after a cyberattack: disconnect the affected device from the network first
What to Do in Case of a Cyberattack (Step by Step) 6

Article Summary: If your business is hit by a cyberattack, the first hour matters. Disconnect the affected devices from the network instead of powering them off, call your IT provider by phone, and leave the evidence in place. If money was wired to a scammer, call your bank right away. This post is the step-by-step plan, plus where to report an attack in the US (including New Jersey), UK, and Australia, when you have to notify customers, and what recovery really costs.

If a cyberattack hits your business, what you do in the first hour really matters.

It’s also the easiest time to make a costly mistake, like turning off the wrong machine, deleting evidence, or replying from an email account the attacker is already reading.

The steps below tell you what to do, in order, so you’re not guessing in the moment. Doing these steps doesn’t require technical knowledge.

Before anything else: don’t make it worse

Responding to a cyberattack starts with the don’ts. Before you touch anything, avoid these dos and don’ts when responding to a cyber incident:

  • Don’t turn the affected computer off, if you can avoid it. Disconnecting it from the network is better, because powering it down can wipe evidence that helps work out what happened.
  • Don’t delete anything. Leave the ransom note, the suspicious email, and any alerts exactly where they are. They’re what your IT team and investigators will need.
  • Don’t pay a ransom on the spot.
  • Don’t use the hacked email or accounts to talk about the attack. If an attacker is in your inbox, they can read those messages. Switch to phone calls or a different account.

What to do after a cyberattack: the step-by-step plan

Think of this as your emergency checklist for cyberattacks. Work through these in order, starting the moment you notice something’s wrong.

  1. Disconnect the affected devices from the network. Unplug the network cable and turn off Wi-Fi on anything that looks affected. This is how to stop an active cyberattack from spreading to other computers and to your backups. CISA’s guidance is to isolate devices rather than power them off where you can, and to shut a device down only if you can’t get it off the network any other way.
  2. Call your IT provider straight away, by phone. Don’t email, in case the attacker is watching your inbox. If you have cyber insurance, call them next, because many policies require you to involve their incident team early.
  3. Leave the evidence alone. Don’t wipe, reinstall, or tidy up the affected machines yet. Screenshots of the ransom note or suspicious emails are useful, but keep the originals too.
  4. If money was sent, call your bank immediately. Ask them to recall the transfer and freeze it if they can. With wire and bank fraud, acting in the first few hours makes the biggest difference.
  5. Reset passwords from a clean device, and turn on multi-factor authentication. Start with email and any admin accounts, and use a device you know isn’t affected.
  6. Report it. That can help you recover, and it’s sometimes legally required. Where to report depends on your country and state, which we cover below.

What to do if your business gets hacked: the first 24 hours, hour by hour

The six steps above are the core of any small business cyberattack response. Here’s what to do after a cyberattack across the first day, so you know what “normal” looks like and can tell whether things are on track.

The first hour: contain it. Get affected devices off the network, get your IT provider on the phone, and stop using any account you think is compromised. Write down what you saw and when. A timeline, even a rough one on paper, is one of the most useful things you can hand to the people helping you.

Hours two to four: work out the scope. Your IT team will be trying to answer three questions: how did they get in, what did they touch, and are they still in? This is where preserved evidence pays off. If you use Microsoft 365 or Google Workspace, sign-in logs and mailbox rules often tell the story. Attackers frequently create hidden forwarding rules so they keep receiving your email even after a password reset, so ask your provider to check for those specifically.

Hours four to twelve: notify the people who need to know now. That means your cyber insurer (if you haven’t already), your bank if any payment details were exposed, and your lawyer if customer or employee data may be involved. Keep your staff informed by phone or in person, and tell them what not to do: no posting about it, no emailing clients about it yet, no “helpful” cleanup.

The rest of day one: start recovery planning. Confirm your backups exist, are intact, and are not connected to the infected systems. Decide which systems matter most to keep the business running, and rebuild those first. Resist the urge to reconnect everything at once; a rushed recovery is the most common way a business gets hit a second time.

How to report a cyberattack (and where)

Reporting is a step people skip when working out what to do after a cyberattack, but it matters. Where you report depends on where you are:

  • United States: file with the FBI’s Internet Crime Complaint Center (IC3), and report to CISA.
  • New Jersey: report the incident to the NJCCIC (New Jersey Cybersecurity and Communications Integration Cell), the state’s central cyber reporting and threat-intelligence hub. If personal data was exposed, New Jersey’s breach notification law also requires you to notify the Division of State Police before you notify affected individuals.
  • United Kingdom: report through the NCSC, and to Action Fraud.
  • Australia: report through ReportCyber, or call the 24/7 hotline on 1300 CYBER1.
What to do after a cyberattack involving wire fraud: call your bank and report to IC3 within 72 hours
What to Do in Case of a Cyberattack (Step by Step) 7

If money was wired to a scammer, report it fast. The FBI says reporting wire fraud to IC3 within 72 hours gives its Recovery Asset Team the best chance of clawing it back, and that team recovers funds in about 70% of the cases reported in time.

Knowing how to report a cyberattack isn’t just about paperwork. A police or IC3 report number is usually the first thing your insurer and your bank will ask for, and it’s what turns “we think we were hacked” into a documented incident that can support a claim or a fraud recovery.

Do I have to notify customers of a data breach?

Often, yes. Part of what to do after a cyberattack is checking your legal duties. If personal data about your customers or staff was exposed, you may be legally required to notify a regulator and the people affected, sometimes within 72 hours.

The rules depend on where you operate, like GDPR in the UK and Europe, state breach-notification laws in the US, and the Notifiable Data Breaches scheme in Australia. Every US state now has its own breach notification law, and they differ on what counts as personal data, how quickly you must act, and who else has to be told.

In New Jersey, for example, the law covers names combined with things like Social Security numbers, driver’s license numbers, or account numbers with access codes. Notice has to go out “in the most expedient time possible and without unreasonable delay,” and law enforcement gets told first. If you handle health information, HIPAA adds its own 60-day breach notification clock on top, and businesses under the Federal Trade Commission’s Safeguards Rule have a separate 30-day reporting duty to the FTC for breaches affecting 500 or more people.

Protecting customer data after a hack also means getting the message right. A clear, honest notice that explains what happened, what you’re doing about it, and what customers should do (change a password, watch their statements) protects trust far better than silence or a vague “security incident” email. Ask your lawyer or IT provider early so you don’t miss a deadline, and don’t send anything until you actually know what was taken. Our guide to which NJ regulations apply to your business walks through the state and federal rules in more detail.

Business ransomware recovery: should you pay?

What to do after a cyberattack with ransomware: business ransomware recovery starts with clean backups, not payment
What to Do in Case of a Cyberattack (Step by Step) 8

If it’s ransomware, the big question about what to do after a cyberattack is whether to pay.

The FBI does not recommend it. Paying doesn’t guarantee you get your files back, it marks you as a business that pays, and the money funds more attacks.

It’s ultimately your decision, but it’s one to make with law enforcement, your IT or incident-response team, and your insurer, not alone in the first panicked hour.

Sometimes a free decryption tool already exists for the exact ransomware that hit you, which is one more reason to get the experts involved before you pay anyone. The No More Ransom project, run by law enforcement and security companies, keeps a library of them.

Real business ransomware recovery almost always comes down to backups. If you have a recent backup that the attacker couldn’t reach, you can rebuild without paying. If your only backup was a drive plugged into the infected server, or a cloud sync that faithfully copied the encrypted files, you’re in a much harder spot. That’s why we push clients toward immutable backups that can’t be altered or deleted, even by an administrator account. For the prevention side, see our ransomware defense plan.

Small business cyber insurance claims: what your insurer expects

If you carry cyber insurance, treat your insurer as part of your incident response team from hour one. Most policies require prompt notice, and many require you to use the insurer’s approved forensics, legal, and recovery vendors. Bringing in your own people first, or waiting a week to call, can put the claim at risk.

Small business cyber insurance claims go more smoothly when you can show three things: a timeline of what happened and when, evidence that you preserved rather than destroyed, and proof that the security controls you described on your application (multi-factor authentication, backups, endpoint protection) were actually in place. If you’re not sure what you promised on your last renewal, read our post on answering cyber insurance questions without voiding your policy.

How much does a data breach cost a small business?

The headline numbers are scary. IBM’s 2025 Cost of a Data Breach report puts the global average at USD 4.44 million, with breaches taking an average of 241 days to identify and contain. Those figures are dominated by large enterprises, though, so they don’t map neatly onto a 20-person firm.

For a small business, the cost of a cyberattack usually shows up in five places: downtime while systems are rebuilt, professional fees for IT recovery, legal advice and forensics, the cost of notifying customers and offering credit monitoring, any ransom or fraudulent transfer that can’t be recovered, and lost customers afterward. The last one is the quiet killer. A week of downtime plus a breach notice can be enough to push a client to a competitor.

That’s why the best answer to “how much does a data breach cost a small business?” is: far less if you’ve prepared. Tested backups turn a multi-week rebuild into a day or two. Multi-factor authentication stops most email account takeovers before they start. And a one-page response plan means you’re acting in the first hour instead of arguing about what to do.

Small business cybersecurity recovery: getting back to normal safely

What to do after a cyberattack: restore from tested backups as part of small business cybersecurity recovery
What to Do in Case of a Cyberattack (Step by Step) 9

Once the cyber incident is contained, what to do after a cyberattack shifts to getting the business running again without reopening the door. Small business cybersecurity recovery usually follows this order:

  1. Confirm the attacker is out. Every compromised account gets a new password and multi-factor authentication. Hidden mailbox rules, unknown admin accounts, and remote-access tools the attacker installed all get removed.
  2. Rebuild, don’t just clean. For anything ransomware touched, a fresh reinstall from a known-good image is safer than trying to remove the malware from a live system.
  3. Restore data from backups you’ve verified. Restore the most important systems first, and scan the restored data before reconnecting it to the network.
  4. Close the hole that let them in. Whether it was a phishing email, an unpatched server, or a weak remote-desktop login, fix the root cause before you call the incident over.
  5. Write down what you learned. A short post-incident review, even a single page, is what turns a bad week into a stronger business.

If you’d rather not build that process yourself, this is exactly what eMDTec’s cybersecurity services and managed IT services are for.

Prepare before you ever need to know what to do after a cyberattack

All of this is far easier if you’ve decided some of it in advance. You don’t need a thick binder, just a simple plan that covers:

  • Who to call first (your IT provider, your insurer) and their numbers, kept somewhere you can reach without your main systems.
  • Where your backups are, and proof they’ve been tested by restoring from them. Our post on simple backup and recovery plans covers what “tested” should mean.
  • Which accounts and devices matter most, so you know what to protect first.
  • Which laws apply to the data you hold, so the notification question is already answered.

A single page covering those is enough for most small businesses, and it’ll save you a lot of scrambling if the day ever comes. If you want a second set of eyes on where you stand today, a security risk assessment is the fastest way to find the gaps before an attacker does.

Frequently Asked Questions

What should a small business do if they are cyber attacked?

Disconnect the affected devices from the network, call your IT provider by phone, preserve the evidence, call your bank if money was sent, reset passwords from a clean device, and report the attack. Then bring in your insurer and, if personal data was involved, your lawyer. The full small business cyberattack response is laid out step by step above.

What’s the first thing to do in a cyberattack?

Disconnect the affected devices from the network, by unplugging the network cable and turning off Wi-Fi, then call your IT provider by phone. Getting the device off the network stops the problem spreading while you get help.

Should I turn off the computer if I get ransomware?

If you can, disconnect it from the network instead of powering it off. Shutting it down can wipe evidence stored in memory that helps work out what happened. Only power a device off if you can’t get it off the network any other way.

Who do I call if my business computer is ransomware encrypted?

Call your IT provider or managed service provider first, by phone, and then your cyber insurer. If you don’t have either, the FBI’s IC3 and, in New Jersey, the NJCCIC can point you to help. eMDTec answers the phone 24/7 at 973-295-5570 for businesses in New Jersey that need urgent help.

How long does it take to recover from a cyberattack?

It depends almost entirely on your backups and your plan. A business with tested, offline or immutable backups and a clear list of who to call can often be working again within a day or two, with cleanup continuing in the background. Without usable backups, rebuilding systems and recreating data can stretch into weeks, and the notification and insurance work adds time on top. That gap is the strongest argument for preparing before anything happens.

Should I pay the ransom?

The FBI does not recommend it. Paying doesn’t guarantee you get your data back, and it funds more attacks. Make that decision with law enforcement, your IT or incident-response team, and your insurer, and check whether a free decryption tool already exists first.

We wired money to a scammer. What do we do?

Call your bank immediately and ask them to recall the transfer. If you’re in the US, report it to the FBI’s IC3 within 72 hours, because reported quickly, their Recovery Asset Team recovers the money in about 70% of cases. In other countries, contact your bank and your national reporting service straight away.

Who do I report a cyberattack to?

In the US, the FBI’s IC3 and CISA, plus your state’s cyber agency (the NJCCIC in New Jersey). In the UK, the NCSC and Action Fraud. In Australia, ReportCyber. Also tell your cyber insurer, and check whether you have a legal duty to notify a regulator if personal data was exposed.

Know what to do after a cyberattack before it happens

Here’s the honest truth: the businesses that come through a cyberattack in one piece are the ones that decided what to do after a cyberattack long before the alarm went off. A tested backup, a phone number for your IT provider, and a one-page plan beat panic every single time.

That’s where we come in. At eMDTec, we help New Jersey businesses build that plan, lock down their backups, and stand ready to pick up the phone the moment something looks wrong, so you always know what to do after a cyberattack. Take a look at our cybersecurity services or reach out through our contact page.

Your next action item: Don’t wait for the worst day to figure out what to do after a cyberattack. Schedule a free consultation and we’ll help you build a response plan that actually works when it counts.

Featured Image Credit

This Article has been Republished with Permission from The Technology Press.