What to Do After a Cyber Attack: A First-Hours Playbook for Small Businesses
The first hours after a cyber attack decide how bad it gets. This playbook walks you through five stages — contain, assess, report, recover and learn — in plain English. Keep it somewhere you can reach even if your systems are down, so that when something goes wrong your team acts calmly instead of panicking or making things worse.
Some links on this page are affiliate links: if you sign up or buy through them, Dacros may earn a commission, at no extra cost to you. We only recommend tools we use and rate. Full disclosure.
Before you do anything, stay calm
The moment you realise you have been attacked — files encrypted, an account taken over, money gone, a strange message on screen — the instinct is to panic or to start clicking things to “fix” it. Resist that. Panic is what makes a bad incident worse.
This playbook breaks the response into five stages: contain, assess, report, recover and learn. You will not do them all perfectly under pressure, and that is fine. The goal is to move deliberately, protect what you still have, and avoid the mistakes that turn a contained problem into a disaster.
A quick note on preparation: this playbook is far more useful if you have read it before you need it, and if you keep a printed or offline copy along with your key contacts. When systems are down, a plan trapped inside those systems is no help at all.
Stage 1: Contain — stop the bleeding
Your first job is to limit the damage, not to investigate or repair. Think of it like a burst pipe: turn off the water first, mop up later.
- Disconnect affected devices from the network. Unplug the network cable or turn off Wi-Fi on the machine involved. Do this rather than shutting it down, if you can — powering off can destroy evidence that helps work out what happened.
- Do not switch everything off in a blind panic. Isolating the affected device is usually better than yanking power from the whole office, which can corrupt data and lose useful traces.
- Change critical passwords from a clean device. If an account has been compromised, reset its password from a device you trust is unaffected, and turn on multi-factor authentication if it is not already on. A password manager such as Proton Pass makes it much easier to reset many logins quickly and store the new ones safely.
- Call your IT support immediately. Your managed IT provider should lead containment. The sooner they are involved, the more they can protect.
If money has already moved — a fraudulent payment, a drained account — phone your bank straight away. Speed matters; some transfers can be stopped or recalled if you act fast.
Stage 2: Assess — understand what happened
Once the immediate spread is stopped, take stock. You are trying to answer three questions: what got in, what did it reach, and what data or money is involved?
- What type of incident is it? Ransomware, a hacked email account, a scam invoice, stolen login details, or a lost laptop are all handled differently.
- What systems and data are affected? List what the attacker could have reached. Pay particular attention to anything containing personal data about customers or staff, because that affects your legal duties.
- Is it still ongoing? Some attacks are a single event; others involve an intruder still moving around your systems. If in doubt, assume they may still have access until your IT team confirms otherwise.
Your first job is to limit the damage, not to investigate or repair. Think of it like a burst pipe: turn off the water first, mop up later.
Write down a timeline as you go: when you noticed, what you saw, what you did and when. This rough log is invaluable later for reporting, for insurance, and for learning. Note the times — you will not remember them accurately once the adrenaline fades.
Stage 3: Report — meet your obligations
Several organisations may need to hear from you, and some have deadlines.
- The ICO. If personal data has been breached and it is likely to put people at risk, you must report it to the Information Commissioner’s Office within 72 hours of becoming aware. Not every attack triggers this, but do not sit on it — the clock starts when you become aware, not when you finish investigating. Our article on how to report a data breach to the ICO walks through the judgement call.
- Action Fraud and the NCSC. Report cyber crime and fraud to Action Fraud, the UK’s national reporting centre. The National Cyber Security Centre (NCSC) also provides guidance and can be notified of significant incidents.
- Your bank. For any financial fraud, notify them immediately.
- Your insurer. If you have cyber insurance, tell them early — many policies require prompt notification and can provide specialist help.
- Affected people. If a breach is likely to be a high risk to individuals, you may also need to tell those individuals directly, in clear language, so they can protect themselves.
Keep your reporting factual. You do not need every answer before you report; regulators expect an initial report followed by updates as you learn more.
Stage 4: Recover — get back to work safely
Now you rebuild, carefully. The temptation is to rush back to normal, but restoring onto a system the attacker still controls just hands it all back to them.
- Confirm the threat is removed. Your IT team should be satisfied that any malware is gone and any intruder access is cut off before you reconnect.
- Restore from clean backups. This is where good backups earn their keep. Restore data from a backup taken before the attack, and verify the files open properly. If you are unsure your backups would cope, our guide to 3-2-1 backups and disaster recovery is worth a read once the dust settles.
- Reset credentials broadly. Assume passwords touched by the incident are compromised and change them. Turn on multi-factor authentication everywhere it is available — see our explainer on multi-factor authentication.
- Bring systems back in a sensible order. Restore the most important functions first, and watch closely for any sign the problem returns.
Do not pay a ransom without taking advice. There is no guarantee it works, it may be funding further crime, and being able to restore from your own backups is a far stronger position.
Stage 5: Learn — close the gap
Once you are trading again, hold a short, blame-free review while it is fresh. The point is not to find someone to punish; it is to stop it happening again.
- How did they get in? A phishing email, a weak or reused password, out-of-date software, or a missing safeguard?
- What worked and what did not? Were your backups usable? Did people know who to call? Was this playbook to hand?
- What are the one or two changes that would have stopped it? Focus on a small number of high-impact fixes rather than a long wish list nobody completes.
Many attacks succeed through the same handful of gaps: no multi-factor authentication, weak passwords, poor backups, and staff who were never shown what a scam looks like. Working towards the government-backed Cyber Essentials scheme is a practical way to close the most common ones, and it reassures customers too.
Get help before and after
The businesses that come through a cyber attack best are usually the ones that prepared: tested backups, multi-factor authentication switched on, and a plan people had actually read. If you are in the middle of an incident now and need support, or you would rather never be in this position, contact DACROS. You can also explore our cyber-security services to see how we help Yorkshire small businesses stay resilient.
Print this playbook. Add your key phone numbers. Keep it somewhere you can reach even with the power off. That five minutes of preparation is the cheapest insurance you will ever buy.
Frequently asked questions
Should we pay a ransom if we are hit by ransomware?
UK law enforcement and the NCSC advise against paying. There is no guarantee you get your data back, you may be funding further crime, and paying marks you as a business that pays. It is much better to be in a position where you can restore from clean, tested backups. Report the incident to Action Fraud and the NCSC, and take specialist advice before making any decision.
Do I have to tell the ICO about every cyber attack?
No. You must report a personal data breach to the ICO only if it is likely to pose a risk to people's rights and freedoms, and you must do so within 72 hours of becoming aware. Not every attack involves personal data, and not every breach is reportable. Our separate article on reporting a data breach to the ICO explains how to judge this.
Who should I call first after a cyber attack?
Your IT support or managed IT provider, so containment can start immediately. In parallel, notify a senior decision-maker in the business. If money has been taken or there is fraud, contact your bank straight away and report to Action Fraud. Having these numbers written down somewhere offline means you are not hunting for them mid-crisis.
How do we stop the same attack happening again?
After recovery, hold a short review: how did they get in, what did we miss, and what one or two changes would have stopped it? Common fixes are turning on multi-factor authentication, improving backups, and staff phishing awareness. Working towards Cyber Essentials is a practical way to close the most common gaps.
Dacros — led by Jordan Gilbert
Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.
Related guides
The backup password on the laptop you're backing up
Recovery controls fail in a way audits miss: the control quietly depends on the very thing it is meant to recover you from. We found five in our own systems in a week — here's the one question that finds them, and a two-hour fix.
Read → GuideIT and Cyber Security for Charities and Non-Profits in the UK
A plain-English guide to IT and cyber security for UK charities: protecting donor and beneficiary data, controlling volunteer access, and Cyber Essentials on a tight budget.
Read → GuideIT & Cyber Security for Solicitors and Law Firms: A Plain-English Guide
A practical guide to IT security for UK law firms: client confidentiality, SRA-aligned controls, secure email and documents, DMARC, backups and staying compliant.
Read →Want this handled for you?
Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.