Skip to main content Scroll Top

You’ve been hacked. What you do next could save your business.

A cyberattack is not just an IT problem. It is a cash-flow problem, an operations problem, a PR disaster, and a leadership problem. And it is not rare. The UK government says 43% of businesses identified a cyber breach or attack in the last 12 months.

When it happens, speed matters!

What to do during a cyberattack

1. Contain the virus

Do not waste precious time debating. Containment comes first.

If you think ransomware or malware is involved, you need to act immediately.

The National Cyber Security Council (NCSC) says infected laptops, PCs and tablets should be disconnected from the network straight away. To help limit the spread, shut off Wi-Fi, disable network connections and cut internet access.

Don’t delete any data as it can be used as essential evidence to analyse when identifying where the breach came from and how it can be rectified.

2. Get expert help immediately

Most SMEs don’t have the internal IT skills or capacity to handle a serious cyber incident. It’s always best to consult an expert IT provider straight away rather than attempting to diagnose the issue first.

Trying to “see how bad it is” before calling for help is how small incidents turn into expensive issues for your business. The longer you leave your system exposed, the greater the impact on your organisation.

Depending on the nature of the attack, the IT Pros (like us at commited) will manage the entire process and will also implement fixes, including:

  • Using cybersecurity tools and expert knowledge to identify the source of the breach and damage
  • Establish what data and systems have been breached
  • Disable and quarantine compromised accounts
  • Remove unauthorised accounts
  • Enforce password resets, especially for administrators
  • Wipe the infected device/s if malware or ransomware is found and verify clean
  • Run decryption tools if ransomware is found
  • Run the latest anti-virus software, scans and patches
  • Monitor network traffic to identify infections
  • Enact restore and data recovery from a verified clean backup
  • Reconnect devices to update the OS and other software
  • Undertake any further structured remediation

3. Identify if there has been a data breach

If personal data is involved, the clock starts ticking.

The ICO states you need to report a personal data breach within 72 hours of becoming aware of it. This means there is a legal and regulatory obligation to fix this issue and report it swiftly.

4. Carry out damage control

This is where leadership really kicks in. Decide who is leading the response.

Identify which systems matter most. Work out what the business can still operate without.

Keep updates clear and controlled, communicating openly with affected employees, suppliers and partners to maintain trust and reputation.

If the whole thing descends into technical panic, you’re risking your professional reputation alongside your crucial data, so damage control and image protection are essential.

5. Communicate with the right authorities

Managed communication is key. You have legal and compliance obligations to uphold in the event of a cyber attack. Here’s a brief list of the main bodies to contact during a breach.

  • Your cyber insurer
  • The ICO if there is a data breach
  • Legal advisers
  • Key customers or suppliers
  • The fraud police to report the breach

Failing to communicate with the right people in a timely manner not only reduces the rate of recovery, but it also poses compliance issues.

6. Don’t rush recovery; act carefully

It’s natural for any business’s instincts to get everything back online as quickly as possible. This is understandable from an operations perspective, but it’s highly risky.

Recovery should mean restoring critical systems in the right order, checking backups properly, and making sure you are not bringing the same problem back into the environment. These are all tasks your IT partner should undertake in a controlled manner. Rushing can only leave gaps in your defences, which can result in the issue recurring or your systems not being fully protected.

Read more on the NCSC’s recovery guidance, which is built around controlled recovery, not blind reactivation.

7. Learn from your exposures

If the incident revealed weak passwords, poor backups, missing MFA, patching gaps, or a lack of a response plan, those problems existed before the hack, which exposed them.

These are commercial lessons that must be addressed promptly. A cyber incident is expensive enough once, but paying for the same weakness twice is unforgivable.

Take a deep dive into your IT systems, create a comprehensive IT strategy with fail-safes and robust cyber security to prevent a hack from happening again.

Final takeaways

If you have been hacked, the first few hours are critical.

Contain the issue. Escalate it to the professionals. Assess the data risk. Communicate properly. Recover carefully.

The businesses that emerge from these incidents the best are not always the biggest or most technical. They are the ones who respond quickly, calmly and decisively and utilise Cyber Essentials. Often, this type of response earns greater trust and admiration from employees, suppliers and customers when handled well.

Do you have weak IT that could struggle in the event of a hack? Book a no-obligation cyber risk review today and see how our experts at commited can transform your cyber security.

Newsletter

Subscribe for monthly IT advice and a chance to get Co-Op Live tickets.

Follow Us