15 August 2026
What to Do in Case of a Cyberattack (Step by Step)
By Jack Wetson-Catt
Photo by GuerrillaBuzz on Unsplash
If a cyberattack hits your business, what you do in the first hour matters more than almost anything you do afterwards.
It's also the easiest time to make a costly mistake: turning off the wrong machine, deleting the evidence, or replying from an email account the attacker is already reading. Here at Atema, this is the guidance we give clients the moment something's gone wrong, not a theoretical checklist. It doesn't require any technical knowledge to follow, just a clear order to work through.
Before anything else, don't make it worse
Before you touch anything, avoid these:
- Don't switch the affected computer off if you can avoid it. Disconnecting it from the network, by unplugging the cable and turning off Wi-Fi, is safer, because powering a device down can wipe evidence that helps work out what actually happened. NCSC guidance is to get the device off wired and wireless networks first, and only escalate to disabling your wider network if the problem is clearly spreading.
- Don't delete anything. Leave the ransom note, the suspicious email, and any alerts exactly where they are. Your IT provider needs them to work out what happened.
- Don't pay a ransom on the spot.
- Don't use the affected email account or system to talk about the attack. If someone's already in your inbox, they can read those messages, and they can use that same access to send emails that look like they're genuinely from you, the trick we cover in our guide to stopping scammers sending email in your company's name. Switch to phone calls, or a different account entirely.
The step by step
Work through these in order, starting the moment you notice something's wrong.
- Disconnect the affected devices from the network. Unplug the network cable and turn off Wi-Fi on anything that looks affected. This stops the problem spreading to other computers and to your backups.
- Call your IT provider straight away, by phone. Don't email, in case the attacker is watching your inbox. If you have cyber insurance, call them next, since many policies require you to involve their incident response team early.
- Leave the evidence alone. Don't wipe, reinstall, or tidy up the affected machines yet. Screenshots of the ransom note or suspicious emails are useful, but keep the originals too.
- If money was sent, call your bank immediately. Ask them to recall the transfer and freeze it if they can. With bank transfer fraud, acting in the first few hours makes the biggest difference to whether it can be clawed back.
- Reset passwords from a clean device, and turn on multi-factor authentication. Start with email and any admin accounts, using a device you know isn't affected.
- Report it. Reporting can help with recovery, and it's sometimes a legal requirement. Where to report depends on what happened.
Where to report it
For UK businesses, there are two places to report a cyberattack, and they're not the same thing:
- The National Cyber Security Centre, for the cyber incident itself. The NCSC triages reports and can offer direct support for serious incidents.
- Report Fraud, the UK's national fraud and cybercrime reporting service (the successor to Action Fraud), for the crime. If your business is currently in the middle of a live cyberattack, their line is answered 24 hours a day on 0300 123 2040.
If money was wired to a scammer, report it fast, both to your bank and to Report Fraud. The sooner it's reported, the better the chance of a bank being able to intervene.
If personal data about your customers or staff was exposed, such as names, emails, or financial details, you may have a legal duty to notify a regulator and the people affected. Under UK GDPR, if a breach is likely to put people at risk, organisations generally need to notify the Information Commissioner's Office within 72 hours of becoming aware of it, and that clock runs over weekends too. Ask your lawyer or IT provider early so you don't miss the deadline.
Should you pay the ransom?
If it's ransomware, the big question is whether to pay.
The NCSC does not encourage, endorse, or condone paying ransoms. Paying doesn't guarantee you get your files back, it marks you as a business that pays, and the money funds more attacks against other businesses.
It's ultimately your decision, but it's one to make with your IT or incident response provider, your insurer, and potentially law enforcement, not alone in the first panicked hour. Sometimes a free decryption tool already exists for the exact ransomware that hit you, which is one more reason to get the experts involved before paying anyone.
The best time to prepare is before it happens
All of this is far easier if some of it has been decided in advance. You don't need a thick binder, just a simple plan that covers:
- Who to call first (your IT provider, your insurer), and their numbers kept somewhere you can reach without your main systems.
- Where your backups are, and proof they've been tested by actually restoring from them. A backup nobody has ever restored from is a guess, not a plan.
- Which accounts and devices matter most, so you know what to protect first.
A single page covering those three points is enough for most small and mid-sized businesses, and it saves a lot of scrambling if the day ever comes. This is exactly the kind of incident readiness our cyber security work builds in for clients as standard, rather than something worked out for the first time mid-incident. If you'd like us to look at where your business currently stands, book a call with our team and we'll take it from there.
Frequently Asked Questions
What's the first thing to do in a cyberattack?
Disconnect the affected devices from the network, by unplugging the network cable and turning off Wi-Fi, then call your IT provider by phone. Getting the device off the network stops the problem spreading while you get help.
Should I turn off the computer if I get ransomware?
If you can, disconnect it from the network instead of powering it off. Shutting it down can wipe evidence that helps work out what happened. Only power a device off if you can't get it off the network any other way.
Should I pay the ransom?
The NCSC does not encourage, endorse, or condone paying ransoms. Paying doesn't guarantee you get your data back, and it funds more attacks. Make that decision with your IT or incident response provider and your insurer, and check whether a free decryption tool already exists first.
We wired money to a scammer. What do we do?
Call your bank immediately and ask them to recall the transfer. Then report it to Report Fraud, the UK's national fraud and cybercrime reporting service, either online or by calling 0300 123 2040, which is staffed 24 hours a day for businesses currently experiencing a live attack.
Who do I report a cyberattack to?
In the UK, report the incident itself to the National Cyber Security Centre, and the crime to Report Fraud. Also tell your cyber insurer, and check whether you have a legal duty to notify the Information Commissioner's Office if personal data was exposed.
Written by
Jack Wetson-CattJack co-founded Atema in 2017 and leads the team day to day, bringing years of IT experience across telecoms, finance and legal to how Atema supports its own clients.
