What to Do After a Cyber Attack
The immediate first steps for a UK business that suspects it's dealt with a cyber incident, from the first ten minutes through to closing it out.
In the first few minutes
Confirm someone is clearly in charge of the response - even informally - and start a written log immediately, even if it's just timestamped notes. Work out whether the activity is still ongoing (an attacker actively in your systems, ransomware still encrypting files) or whether it's a discrete event that's already happened (a phishing email that was reported before anyone clicked it).
If a device may be compromised, disconnect it from the network rather than switching it off where possible - this can stop the spread while preserving evidence that a shutdown might destroy. Avoid investigating from a device or account that might itself be compromised.
Establish trusted communications
If email or chat systems might be compromised, don't coordinate the response through them - an attacker with mailbox access can see you discussing containment in real time. Use phone calls or a separate, unaffected channel until you're confident your normal systems are clean.
Work out roughly what you're dealing with
In the first hour, you're aiming for a rough classification, not certainty: is this a compromised account, ransomware, a lost device, a data exposure, or payment fraud? Each has a different immediate priority. A compromised email account needs credentials reset and sessions revoked. Ransomware needs containment decisions made fast. Suspected payment fraud needs your bank contacted immediately - recall windows are often very short.
Don't make these common mistakes
Don't negotiate with or pay attackers without specialist, insurer and legal input - this is a decision with legal and financial consequences beyond the immediate technical situation. Don't restore from backup before you're reasonably confident the attacker's access has actually been removed, or you risk reinfecting a clean system. Don't wait until the end of the incident to start thinking about whether personal data was involved - that assessment needs to start early.
When to call in specialist help
Bring in your cyber insurer and, where appropriate, a specialist incident response provider if: you suspect serious criminal activity or financial fraud, you may need forensic evidence, you can't confidently establish scope or root cause, there's a strong suspicion of significant data theft, privileged or admin-level accounts may be compromised, or ransomware is actively spreading. Rushing recovery before you understand what happened is one of the most common ways an incident gets worse rather than better.
After it's contained: don't skip the review
Once things are back to normal, run a short post-incident review: what happened, what worked, what didn't, and what you're changing as a result. This is also the point to complete any outstanding regulatory or insurer notifications and close out your incident log.
If you want a structured way to work through all of this - including the severity classification, the specific playbook for your scenario, and the communications you'll need to send - our Cyber Incident Response Plan & Toolkit is built around exactly this sequence.