What should we do in the first hour after a cyber attack?

Skip to main content

Last updated: 3 October 2026

Short answer: isolate affected devices, change passwords from a clean device, call your IT provider, and tell your cyber insurer. Do not wipe anything yet and do not pay a ransom without advice. If personal data may be affected, you may have 72 hours to tell the ICO.

Want this sorted for you?Talk to our Burgess Hill team about cyber security services. Free, friendly and no obligation.
72 hoursto report a notifiable personal data breach to the ICO
First houris when containment makes the biggest difference
1%of UK businesses reported ransomware in the Cyber Security Breaches Survey 2025

What should we do in the first hour after a cyber attack?

  1. Contain itDisconnect affected computers from the network and Wi-Fi, but leave them switched on so evidence is kept.
  2. Call for helpPhone your IT provider, ABCOM or your incident contact, and tell your cyber insurer, since many policies include an emergency helpline.
  3. Change credentials safelyFrom a clean device, reset passwords for affected accounts and admin accounts, and check that MFA is on.
  4. Stop the spreadDisable compromised accounts, block suspicious sign-ins and pause any shared drives that look affected.
  5. Record what you seeWrite down times, messages, ransom notes and screenshots. Do not delete anything.
  6. Protect your backupsCheck your backups are offline or separate and unaffected before restoring anything.

What should we do in the first day?

Who What they do
IT provider Investigate the cause, remove the attacker’s access and restore from clean backups.
Directors or owners Decide who is in charge, approve communications and make the reporting decisions.
Cyber insurer Provide incident response help and tell you what you must do to keep cover.
Data protection lead Judge whether personal data is affected and whether the ICO and individuals must be told.
Staff Be told what happened, what to avoid and who to contact, in plain language.

Do we have to report a cyber attack?

You must report a personal data breach to the ICO within 72 hours of becoming aware of it, unless it is unlikely to result in a risk to people’s rights and freedoms. You should also report cyber crime to the police through the national reporting service, and tell your insurer promptly. Law enforcement and the NCSC discourage paying ransoms, so take advice before you decide.

Prepare before it happens. The businesses that recover fastest have tested backups, MFA on every account, a printed list of emergency contacts and a simple written plan. An hour spent now saves days later.

Can ABCOM help if we have been attacked, or prepare us in advance?

Yes. ABCOM helps Sussex businesses respond to incidents and, more usefully, prepare for them: tested backups, MFA, endpoint protection, monitoring and a short incident plan. Book a free IT review and we will show you where you stand.

Want this looked after for you?

ABCOM has supported Sussex businesses and charities since 1996 and is an NCSC Assured Service Provider – Cyber Advisor (Cyber Essentials). Talk to a real person about your IT.

Also read

How ABCOM can help

Talk to a real person at our Burgess Hill office. We are an NCSC Assured Service Provider and have supported Sussex businesses since 1996.

Scroll to Top
Free 3-minute quiz · No sign-up for your score

Is your team using AI you don’t know about?

Score your Shadow AI risk across policy, data, tools, people and detection, then get the three controls to fix first.

Take the Shadow AI Check10 questions · about 3 minutes