Blog

Hit by Cyberattack

What to Do After a Cyberattack: A Step-by-Step Guide for Businesses

September 21, 20265 min read

Here is what really helps in a cyberattack: knowing in advance what to do. The businesses that navigate these situations best are almost never the ones with the most sophisticated defenses. They are the ones who had a plan, knew who to call, and did not lose critical minutes to panic and confusion.

This guide gives you that framework.

The First Thing to Do: Stay Calm and Do Not Make It Worse

The instinct during a cyberattack is to act immediately. That instinct, without guidance, often makes things worse. Deleting files, shutting everything down without a plan, or restoring systems before the threat is contained can all extend the damage rather than limit it.

The first action is not a technical one. It is to pause, notify the right people, and start the response process in order.

Step 1: Isolate, Don't Shut Down

If systems are actively compromised, the priority is to disconnect infected devices from the network, not necessarily to shut them down completely. Isolation stops the spread. An unplanned full shutdown can destroy forensic evidence needed to understand what happened and complicate recovery.

Disconnect affected devices from Wi-Fi and network cables. If a device appears to be actively spreading something, powering it off may be warranted, but do so with awareness that this choice exists rather than as an automatic reaction.

Step 2: Call Your IT Provider Immediately

This is the call that changes the trajectory of what happens next. If you are an Info Advantage client, this is also where the Info Advantage support line connects you to a human being within seconds, someone who knows your environment and begins coordinating the response from that first call.

Do not try to investigate or remediate on your own before making this call. The response team needs to assess the situation before changes are made.

Step 3: Identify What You Are Dealing With

The response team will work to determine what type of incident is occurring. Ransomware, a phishing-based credential theft, an unauthorized access event, and a data exfiltration attempt all require different response approaches. The assessment drives the next steps rather than a generic script.

What you can help with at this stage: describing what you noticed first, when you noticed it, and which systems or users appear to be affected.

Step 4: Notify Stakeholders Appropriately

Depending on what has occurred and what data may be involved, notifications may be required. According to the FTC's cybersecurity guidance for small businesses, businesses should have an incident response plan that includes knowing who to notify and when, including potentially affected customers, insurance providers, and in some cases regulatory bodies.

Not every incident requires external notification, but knowing the thresholds in advance means this decision does not get made under maximum stress without any preparation.

Step 5: Contain and Begin Remediation

Once the scope of the incident is understood, the response team moves to contain it, removing the attacker's access, identifying how they got in, and beginning the process of cleaning affected systems. This is technical work that happens in coordination with your IT provider.

What the business needs to do during this phase: support the response team with access and information, communicate internally with staff about what is happening, and avoid restoring systems before you get the all-clear.

Step 6: Restore From Clean Backups Only

CISA's incident response guidance is direct on this point: restore systems only after the threat has been fully removed and clean backups are confirmed. Restoring too early can reintroduce the attacker. Your IT provider will verify backup integrity before reconnecting systems.

This is one of the clearest illustrations of why tested backups matter so much before anything happens. The backup that was verified during a routine test is the backup you can trust during recovery. The one that was never tested is a source of uncertainty at exactly the wrong moment.

Step 7: Conduct a Post-Incident Review

Once systems are restored and operations are stable, the most important conversation is the one about what happened and what changes. How did the attacker get in? What would have caught it earlier? What protections need to be added or changed?

This review is not about assigning blame. It is about making sure the same path cannot be used again, which is the lasting outcome of a well-handled incident.

What Having an IT Partner Changes About This Process

The difference between a business that navigates a cyberattack well and one that does not often comes down to whether a human response started in the first minutes rather than the first hours. At Info Advantage, a live human answers within seconds, knows the environment, and begins coordinating immediately. The calm, step-by-step response starts with that first call, and it runs all the way through post-incident review and the changes that come out of it.

Preparation is what calm looks like in a crisis.

Schedule a call with Info Advantage and find out what your incident response plan looks like, before you need it.

Frequently Asked Questions

Should we shut everything down immediately if we think we are under attack? Not necessarily. Isolation of affected devices from the network is often more appropriate than a full shutdown, which can destroy forensic evidence. Your IT provider should guide this decision from the first call.

What if we do not have an IT provider when an attack happens? Contact CISA's 24/7 reporting line or the FBI's Internet Crime Complaint Center (IC3) for federal resources. Having a provider in place before an incident makes an enormous difference in response time and coordination.

How do we know if customer data was exposed? The post-incident investigation determines scope, which is why containing and investigating before restoring is critical. Your IT provider and potentially legal counsel can help assess notification obligations.

Can we restore from backup immediately? Only after the threat has been fully removed and backups are verified as clean. Restoring too early is one of the most common mistakes in cyberattack response and can reintroduce the attacker.

How long does recovery typically take? It depends on the type and scope of the incident, the quality of backups, and how quickly the threat was contained. Businesses with tested recovery plans and clean backups recover far faster than those without. Ransomware recovery without a good plan can take weeks or longer.

Back to Blog

We Can Help

Call us at (585) 257-2898 or fill out the form below.

Enroll in Our Email Course

Learn How a No-Nonsense IT Strategy Benefits Your Company:
  • Strategies to allocate your IT budget efficiently

  • Enhance cybersecurity defenses on a budget

  • Ensure your technology investments continue to serve your business as it grows