What to Do If Your Business Experiences a Cyberattack

You are currently viewing What to Do If Your Business Experiences a Cyberattack
Knowing what to do during the first hour after a cyberattack can help protect your business and speed recovery.

Introduction

Learn what to do after a cyberattack to protect your business, reduce downtime, and recover with confidence.

Most cyberattacks don’t announce themselves.

The attacks that make the evening news often involve flashing warning screens, encrypted files, and demands for payment. While those attacks certainly happen, they aren’t how many cyber incidents begin.

More often, the warning signs are much quieter.

An employee can’t log in. A shared folder suddenly won’t open. A customer calls asking about an invoice your company never sent. Something simply doesn’t seem right.

It’s easy to dismiss these issues as everyday technology frustrations, but they can also be the first signs of a cyberattack.

If that happens, the decisions made during the first hour can make a significant difference in how quickly your business recovers and how much damage is ultimately done.

The good news is that you don’t need to be a cybersecurity expert to respond effectively. Knowing what to do—and just as importantly, what not to do—can help protect your business while your IT provider works to contain the problem and begin recovery.

Your First Instinct May Be Wrong

When something goes wrong with your technology, your first instinct is probably to fix it as quickly as possible. That’s a completely natural reaction.

The problem is that, during a cyberattack, some of the actions that seem most helpful can actually make it more difficult for your IT provider to determine what happened, contain the threat, and recover your systems.

If you suspect your business has experienced a cyberattack, resist the urge to jump into troubleshooting and avoid these common mistakes:

  • Don’t power off the affected computer right away. If possible, disconnect it from the network instead. In some cases, shutting it down can remove valuable information that helps determine how the attack occurred.
  • Don’t delete suspicious emails, files, or ransom messages. They may provide important clues during the investigation.
  • Don’t try random “fixes” you find online. Every cyberattack is different, and well-intentioned troubleshooting can sometimes make recovery more difficult.
  • Don’t pay a ransom immediately. While the pressure can feel overwhelming, that decision should be made only after consulting with your IT provider, your cyber insurance carrier, and, when appropriate, law enforcement.
  • Don’t assume only one device is affected. What appears to be an isolated issue may actually be part of a larger attack.

Instead of reacting, pause, isolate the problem, and call your IT provider. A calm, methodical response is almost always more effective than a rushed one.

Step 1: Isolate the Problem After a Cyberattack

If you believe a computer or device has been compromised, your first priority is to keep the problem from spreading.

If it’s safe to do so, disconnect the affected device from your network by unplugging the network cable or turning off its Wi-Fi connection. This can help prevent malware or ransomware from spreading to other computers, servers, shared files, and network-connected devices.

Notice we said disconnect, not power off. While every situation is different, leaving the device powered on—when it can be safely isolated—may preserve valuable information that helps your IT provider determine what happened and how best to recover your systems. In fact, the Cybersecurity and Infrastructure Security Agency (CISA) recommends isolating affected devices from the network whenever possible before considering a shutdown.

If you’re unsure which device is affected, or you’re concerned about making the wrong move, don’t guess. That’s exactly the time to contact your IT provider for guidance.

The goal isn’t to fix the problem yourself—it’s to prevent it from getting worse until your IT team can take over.

Step 2: Contact Your IT Provider Immediately

Once the affected device has been isolated, your next call should be to your IT provider.

Time matters during a cyberattack. The sooner experienced professionals can begin assessing the situation, the better the chances of containing the threat, protecting your data, and reducing downtime.

If you believe your company’s email system may have been compromised, avoid using email to report the problem. Instead, call your IT provider directly or use another trusted method of communication. If an attacker has gained access to your email account, they may be able to read your messages or interfere with your response efforts.

If your business carries cyber liability insurance, contact your insurance provider as well. Many policies include incident response services and may require prompt notification to ensure your coverage remains in effect.

Remember, your IT provider isn’t just there to fix computers—they’re there to help keep your business running.

Step 3: Preserve the Evidence

Once you’ve contacted your IT provider, resist the urge to start cleaning up the problem.

It’s completely understandable to want to delete suspicious emails, remove unusual files, or restart computers and other devices in hopes that the issue will disappear.. However, those actions can unintentionally remove important clues that help determine how the attack happened, what systems were affected, and whether the threat is still present.

Instead, leave suspicious emails, ransom messages, error screens, and unusual files exactly where they are. If it’s safe to do so, take photos or screenshots of any error messages or ransom notes—but leave the originals untouched so your IT provider can perform a proper investigation.

Even small details that seem unimportant could provide the missing piece needed to understand what happened.

The more information your IT provider has, the better equipped they are to contain the attack, identify its source, and safely restore your systems.

Step 4: Protect Your Accounts and Your Business

Once your IT provider has begun assessing the situation, it’s time to focus on protecting your most important business assets.

If money was sent to a fraudulent account, contact your bank immediately. Acting quickly may improve the chances of stopping or recovering the transfer.

Next, work with your IT provider to secure your business accounts. This may include resetting passwords, enabling multi-factor authentication, or temporarily restricting access to certain systems while the investigation continues. Whenever passwords need to be changed, use a device your IT provider has confirmed is safe to avoid accidentally exposing new credentials to an attacker.

Resist the temptation to rush everyone back to work before your systems have been fully evaluated. While getting back to business is important, restoring operations too quickly can sometimes allow an attacker to regain access or spread the problem further.

The goal isn’t just to restore access—it’s to restore confidence that your systems are secure.

Step 5: Recover After a Cyberattack

Once the immediate threat has been contained, the focus shifts from responding to recovering.

Depending on the type of cyberattack, recovery may involve restoring systems, verifying that malware has been removed, resetting credentials, and carefully returning employees to normal operations. While it can be tempting to get everyone back to work as quickly as possible, rushing the recovery process can leave vulnerabilities behind or allow an attacker to regain access.

Your IT provider should confirm that affected systems are secure before they’re placed back into service. Taking the time to recover the right way can help prevent the same incident from happening again.

Recovery isn’t measured by how quickly your computers turn back on—it’s measured by how confidently your business can move forward.

Cornerstone IT Tip

You can’t always prevent a cyberattack—but you can be prepared for one.

Businesses that recover the fastest aren’t necessarily the ones with the biggest IT budgets. They’re the ones that have a plan, maintain tested backups, know who to call, and work with a trusted IT partner before an emergency occurs.

A little preparation today can save days—or even weeks—of downtime tomorrow.

Hope for the Best. Prepare for the Worst.

No business owner wants to experience a cyberattack. Fortunately, preparing for one doesn’t have to be complicated.

The most effective response plans often fit on a single page. The goal isn’t to create a thick emergency binder that sits on a shelf collecting dust. It’s simply to answer a few important questions before you ever need the answers.

Ask yourself:

  • Who do we call first? Make sure you have your IT provider’s contact information readily available, even if your email system is unavailable.
  • Where are our backups? More importantly, have they been tested to ensure they can be restored when needed?
  • Who needs to be notified? Consider your leadership team, employees, bank, cyber insurance carrier, and any other key contacts.
  • Which systems are most critical to our business? Knowing what needs to be restored first can significantly reduce downtime.
  • How will we communicate if our email isn’t working? Having an alternate communication plan can keep your team informed during an incident.

Taking a little time to answer these questions now can save valuable time, reduce stress, and help your business recover more quickly if the unexpected happens.

Preparation isn’t about expecting the worst—it’s about having the confidence to handle whatever comes next.

Need Help Preparing Your Business?

No business can eliminate every cybersecurity risk, but every business can be better prepared to respond when something unexpected happens.

Whether you’re looking to strengthen your cybersecurity, review your backup strategy, or simply want a second opinion on your current IT environment, Cornerstone IT Professionals is here to help.

Contact us today to learn how we can help keep your business secure, productive, and prepared.

Frequently Asked Questions

What should I do first if I think my business has experienced a cyberattack?

If you believe a computer or device has been compromised, disconnect it from the network if it’s safe to do so, then contact your IT provider immediately. Avoid deleting files, restarting systems, or attempting to fix the issue yourself until it has been properly assessed.


Should I pay the ransom?

Law enforcement, including the FBI, generally advises against paying a ransom because payment doesn’t guarantee you’ll recover your data and may encourage future attacks. Instead, work with your IT provider, cyber insurance carrier, and law enforcement to determine the safest course of action for your business.

How can my business prepare for a cyberattack?

Preparation starts long before an attack occurs. Having a response plan, maintaining tested backups, using strong passwords with multi-factor authentication, and partnering with a trusted IT provider can significantly reduce downtime and improve your ability to recover if the unexpected happens.

The best time to prepare is before you need the plan.