What to Do in the First 24 Hours After a Cyberattack

A calm, step-by-step plan for the moments that matter most before, during, and after an incident.

No one wants to think about what happens if a cyberattack hits their business. But the businesses that recover fastest aren’t necessarily the ones with the biggest security budgets they’re the ones with a plan. Knowing what to do in the first 24 hours can be the difference between a contained, manageable incident and a prolonged, costly crisis.

This post walks through exactly what to do in order if you suspect your business or church has experienced a cyberattack, whether that’s ransomware, a compromised email account, or unauthorized access to your systems.

Step 1: Stay Calm and Don’t Make It Worse 

It’s natural to want to immediately shut everything down, unplug every device, or start deleting things. Resist the urge to act before you understand what’s happening. Panic-driven actions can sometimes destroy evidence that would help you understand and recover from the incident or even make the damage worse.

Take a breath, gather the right people (even if that’s just you and your IT provider), and move through the next steps methodically.

Step 2: Contain the Incident

The priority is to stop the situation from spreading. This typically means:

  • Disconnect affected devices from the internet and your network (unplug the network cable or turn off Wi-Fi) — but don’t power them off completely if possible, as this can destroy useful information.
  • Change passwords for any accounts you believe may be compromised, starting with email and financial accounts — ideally from a different, clean device.
  • Revoke access for any sessions or devices you don’t recognize, if your software allows it.

Step 3: Assess What Happened

Once the immediate spread is contained, start gathering information: what systems or accounts are affected? Is there a ransom note or unusual message? Are customers, congregants, or employees reporting strange emails from your accounts? Has any data been accessed or is anything visibly missing or encrypted?

Write down what you observe and when including timestamps. This record will be valuable for your IT provider, insurance carrier, and any legal or regulatory steps that follow.

Step 4: Notify the Right People

This is where having a list ready in advance (printed or saved somewhere accessible even if your systems are down) pays off. Depending on the situation, this may include:

  • Your IT provider or managed security partner — to begin technical investigation and remediation.
  • Your bank — if financial accounts may be compromised, to freeze transactions or accounts.
  • Your cyber-insurance carrier — many policies require prompt notification and can connect you with response resources.
  • Affected customers, congregants, employees, or partners — if their data may have been exposed, depending on the nature and scope of the incident.
  • Legal counsel — to understand any notification obligations in your area.

Step 5: Begin Recovery From Clea

If systems need to be restored, use backups you’re confident are clean and were not affected by the incident this is exactly why testing your backups regularly matters. Before reconnecting any restored system to your network, verify it’s clean and updated.

If you don’t have confidence in your backups or the scope of the issue, this is the point to lean heavily on professional support rather than attempting recovery alone.

Step 6: Documenr Everything

Keep a running log of what happened, what actions were taken, by whom, and when. This documentation supports insurance claims, helps your IT provider understand the timeline, and becomes the foundation for the most important step: the post-incident review.

After the First 24 Hours

Once the immediate crisis is under control, take time to review: how did this happen, and what changes will prevent it from happening again? Every incident even a near-miss is an opportunity to close a gap before it’s exploited a second time.

The businesses that weather a cyberattack best aren’t the ones it never happens to they’re the ones who had a plan before it did. Even a simple, one-page response plan with key contacts and the steps above can dramatically reduce the chaos, cost, and downtime of an incident.

Build Your Plan Before You Need It

Share this article?

RELATED POSTS

Passwords Are Not Enough: Why Your Business Needs MFA Today

Even a strong password can be stolen. Multi-factor authentication is the simple step that stops attackers anyway.

7 Phishing Red Flags Every Employee Should Know

Your website may look great on a desktop, but how does it perform on a smartphone?

Why Small Businesses and Churches Are the New Favorite Target for Cybercriminals

Your website may look great on a desktop, but how does it perform on a smartphone?
Scroll to Top