What to do After a Business Cyber Attack

28 Jul 2026

Ransom attack 1200x800px.jpg

Steps to take after your business suffers a cyber attack

This article provides a step-by-step plan of what to do if your business is hit with a cyber attack plus where to report an attack. What you do in the first hour after an attack matters. It's also the easiest time to make a costly mistake, such as turning off computers, accidentally deleting evidence or using an email account the attacker is already reading. The steps below show you what to do, in order, so you're not guessing in the moment. Completion of these steps does not require any technical knowledge.

Don't make it worse

Before you touch anything, avoid these:

Don't turn the affected computer off, if you can avoid it. Disconnecting it from the network is better. Powering it down can wipe evidence which may help determine what happened.

Don't delete anything. Leave the ransom note, the suspicious email and any alerts exactly where they are. They're what your IT team and investigators will need.

Don't pay a ransom.

Don't use the hacked email or accounts to talk about the attack. If an attacker is in your inbox, they can read those messages. Switch to phone calls or a different account.

The step-by-step

Work through these in order, starting the moment you notice something is wrong.

Step 1. Disconnect the affected devices from the network.

Unplug the network cable and turn off Wi-Fi on any computers that are affected. This stops the problem spreading to other computers and to your backups. Cybersecurity and Infrastructure Security Agency (CISA) recommend isolating devices rather than powering them off where you can and to shut a device down only if you can't get it off the network any other way.

Step 2. Call your IT provider straight away, by phone.

Don't email, in case the attacker is watching your inbox. If you have cyber insurance, call your insurance company next. Many policies require you to involve the insurer's  incident team early.

Step 3. Leave any evidence. Don't wipe, reinstall or tidy up the affected machines. Screenshots of the ransom note or suspicious emails are useful and keep the originals.

Step 4. If money was sent, call your bank immediately.

Ask your bank to recall the transfer if they can. 

Step 5. Reset passwords from a clean device and turn on multi-factor authentication (MFA).

Start with email and any admin accounts and use a device you are confident is not affected.

Step 6. Report it.

This can help you recover and it can be a legal requirement. 

Where to report it

Call the 24/7 hotline on 1300 CYBER1 for urgent assistance.

Report the incident to Australian Signals Directorate (ASD) through the ReportCyber Portal. Australian law mandates that a business entity must submit a formal report within 72 hours of making or becoming aware of a ransomware or cyber extortion payment.

If customer or staff personal data about was exposed you may be legally required to notify a regulator and the individuals affected, possibly within 72 hours. Ask your lawyer or IT provider so you don't miss a deadline.

Should you pay the ransom?

If it's ransomware, the big question is whether to pay. It is not recommended and paying doesn't guarantee your files will be returned, it indicates your business is an organisation that will pay, possibly funding future attacks.

It's ultimately your decision, but it's one to make with legal assistance, your IT or incident-response team and your insurer, not alone in the first panicked hour.

Sometimes a free decryption tool already exists for the exact ransomware that hit you, which is another reason to get the experts involved before you pay anyone.

The best time to prepare is before it happens

All of this is far easier if you have made some decisions in advance. A simple plan is all that's required including:

• Who to call first (your IT provider, your insurer) and their numbers, kept somewhere you can access without your main systems.

• Where are your backups located plus proof they've been tested by restoring from them.

• Which accounts and devices matter most, so you know what to protect first.

A single page with this information is enough for most small businesses and it will save a lot of scrambling if the day ever comes.

Frequently Asked Questions

What's the first thing to do in a cyberattack?

Disconnect the affected devices from the network by unplugging the network cable and turning off Wi-Fi, then call your IT provider by phone. Getting the device off the network stops the problem spreading while you ask for help.

Should I turn off the computer if I get ransomware?

If you can, disconnect it from the network instead of powering it off. Shutting it down can wipe evidence stored in memory that may help work determine what happened. Only power a device off if you can't get it off the network any other way.

Should I pay the ransom?

It is not recommended. Paying doesn't guarantee you get your data back, and it funds more attacks. Make that decision with law enforcement, your IT or incident-response team, and your insurer, and check whether a free decryption tool already exists first.

We transferred money to a scammer. What do we do?

Call your bank immediately and ask them to recall the transfer and report the incident to Australian Signals Directorate (ASD) through the ReportCyber Portal. Australian law mandates that a business entity must submit a formal report within 72 hours of making or becoming aware of a ransomware or cyber extortion payment.

Who do I report a cyberattack to?

Call the 24/7 hotline on 1300 CYBER1 for urgent assistance.

Report the incident to Australian Signals Directorate (ASD) through the ReportCyber Portal. Australian law mandates that a business entity must submit a formal report within 72 hours of making or becoming aware of a ransomware or cyber extortion payment.

Need Help Responding to a Cyber Attack?

When a cyber attack occurs, every minute matters. Knowing who to call and what steps to take can significantly reduce the impact on your business and improve the chances of a successful recovery.

Pact IT Solutions can help contain the threat, assess the extent of the incident, secure affected systems and guide you through the recovery process.

If your business has experienced a cyber attack, or you need assistance developing an incident response plan before one occurs, contact Pact IT Solutions today. Our team is here to help you respond quickly, minimise disruption and get your business back on track. 👉 Need urgent assistance? Contact Pact IT Solutions today.

Article used with permission from The Technology Press.