Last updated: 3 October 2026
Short answer: isolate affected devices, change passwords from a clean device, call your IT provider, and tell your cyber insurer. Do not wipe anything yet and do not pay a ransom without advice. If personal data may be affected, you may have 72 hours to tell the ICO.
What should we do in the first hour after a cyber attack?
- Contain itDisconnect affected computers from the network and Wi-Fi, but leave them switched on so evidence is kept.
- Call for helpPhone your IT provider, ABCOM or your incident contact, and tell your cyber insurer, since many policies include an emergency helpline.
- Change credentials safelyFrom a clean device, reset passwords for affected accounts and admin accounts, and check that MFA is on.
- Stop the spreadDisable compromised accounts, block suspicious sign-ins and pause any shared drives that look affected.
- Record what you seeWrite down times, messages, ransom notes and screenshots. Do not delete anything.
- Protect your backupsCheck your backups are offline or separate and unaffected before restoring anything.
What should we do in the first day?
| Who | What they do |
|---|---|
| IT provider | Investigate the cause, remove the attacker’s access and restore from clean backups. |
| Directors or owners | Decide who is in charge, approve communications and make the reporting decisions. |
| Cyber insurer | Provide incident response help and tell you what you must do to keep cover. |
| Data protection lead | Judge whether personal data is affected and whether the ICO and individuals must be told. |
| Staff | Be told what happened, what to avoid and who to contact, in plain language. |
Do we have to report a cyber attack?
You must report a personal data breach to the ICO within 72 hours of becoming aware of it, unless it is unlikely to result in a risk to people’s rights and freedoms. You should also report cyber crime to the police through the national reporting service, and tell your insurer promptly. Law enforcement and the NCSC discourage paying ransoms, so take advice before you decide.
Can ABCOM help if we have been attacked, or prepare us in advance?
Yes. ABCOM helps Sussex businesses respond to incidents and, more usefully, prepare for them: tested backups, MFA, endpoint protection, monitoring and a short incident plan. Book a free IT review and we will show you where you stand.
Sources and further reading
Want this looked after for you?
ABCOM has supported Sussex businesses and charities since 1996 and is an NCSC Assured Service Provider – Cyber Advisor (Cyber Essentials). Talk to a real person about your IT.
Also read
How ABCOM can help
Talk to a real person at our Burgess Hill office. We are an NCSC Assured Service Provider and have supported Sussex businesses since 1996.