Advanced IT Support • Managed IT Services • Jacksonville, FL

The First Hour: What to Do When You Suspect a Cyberattack

The exact sequence for business owners, in plain English, before panic makes the decisions for you

Maybe it’s a ransom note on a screen. Maybe it’s a vendor calling about an invoice you never sent, files that won’t open, or an employee saying “something weird is happening on my computer.” However it starts, the first hour after discovering a suspected cyberattack matters more than any other. The right moves contain the damage. The wrong moves, most of which feel completely natural in the moment, make everything worse. Here is exactly what to do.

We have walked local businesses through this hour for real, including a ransomware attack that encrypted both of a client’s servers overnight. The businesses that come through these situations well are not the ones with the most technical staff. They are the ones that follow a clear sequence instead of improvising under stress.

This post gives you that sequence. Read it now, while nothing is wrong. It works much better that way.


First: The Three Things Not to Do

Before the steps, the mistakes. These are the instinctive reactions that cause the most damage, and every one of them feels reasonable in the moment.

Do Not Turn Everything Off

The instinct when something is infected is to power it all down. Resist it. Powering off machines destroys evidence that lives in memory, and on encrypted systems it can interrupt processes in ways that make data recovery harder. There is one exception covered in Step 2: disconnecting from the network is right, powering off is usually wrong. Disconnect, don’t shut down.

Do Not Wipe or “Clean” Anything Yet

Running antivirus removal, deleting suspicious files, or reinstalling Windows on an affected machine feels productive. It is also the digital equivalent of mopping a crime scene. Until someone qualified has determined how the attackers got in and what they touched, cleaning machines destroys the information needed to answer those questions, and it does nothing about the entry point. A wiped machine on a still-compromised network just gets compromised again.

Do Not Contact the Attackers or Pay Anything

If there is a ransom note, do not email the address on it, do not open a negotiation, and do not pay. Payment does not guarantee recovery, it marks your business as a payer for future attacks, and depending on who the attackers are, it can create legal exposure. Decisions about ransom involvement are made later, with professionals and often with your insurer and legal counsel involved. Never in hour one, and never by you alone.


The First Hour, Step by Step

Step 1: Write Down What You’re Seeing (5 minutes)

Before touching anything, capture the situation. Take photos of screens with your phone, including any ransom notes or error messages. Note the time you discovered the problem, who discovered it, and what they were doing. Write down which machines and systems seem affected. This takes five minutes and it is enormously valuable to the people who will investigate, to your insurance claim, and to any legal or regulatory process that follows.

Step 2: Disconnect Affected Machines from the Network (10 minutes)

Unplug the network cable from affected computers, or turn off their Wi-Fi. If the situation looks widespread, disconnecting the whole office from the internet at the firewall or modem is a reasonable containment move. The goal is to stop the attack from spreading to more machines and to cut off the attackers’ remote access. Leave the machines powered on. Disconnected but running preserves evidence; powered off destroys it.

Step 3: Call Your IT Provider (Immediately After Step 2)

This is the call that shapes everything after it. Tell them what you documented in Step 1 and what you disconnected in Step 2. A competent provider will take over containment, start investigating the entry point, and tell you exactly what to do next. If you have a managed IT agreement, this call should reach a real person fast. If you cannot reach anyone, that is a serious problem, and worth remembering when the dust settles.

Step 4: Change Critical Passwords from a Clean Device (20 minutes)

Using a device that is not part of the affected network, such as a phone on cellular data, change passwords for your most critical accounts: email, banking, Microsoft 365 admin, payroll. Start with any account that has money or admin authority attached. If multi-factor authentication is not enabled on these accounts, enable it as you go. Do not do this from a potentially compromised computer, or the attackers may capture the new passwords too.

Step 5: Notify Your Insurance Carrier (Before Hour One Ends)

If you carry cyber insurance, call the carrier’s incident hotline early. Most policies require prompt notification, and many will connect you with breach response resources: forensics, legal counsel, and notification services. Waiting to call can jeopardize coverage. If you are not sure whether your general business policy includes cyber coverage, this is also the moment to find out.

Step 6: Control the Story Internally (Ongoing)

Tell employees what they need to know: stop using affected systems, do not talk about the incident outside the company, and route any external questions to one designated person. Speculation travels fast and gets things wrong. If client data may be involved, do not make public statements or client notifications yet. There are legal requirements around breach notification, and getting them wrong creates liability. Those communications happen after the facts are established, usually with counsel involved.


What Happens After the First Hour

Once containment is in place and the right people are engaged, the work shifts to investigation and recovery. How the attackers got in gets identified and closed. Affected systems get assessed. If backups are clean and current, restoration begins, and this is where preparation pays off more than anything else. In the ransomware incident we handled, clean cloud backups turned a potentially devastating attack into a recovery measured in hours.

Recovery timelines vary enormously, and the difference almost always comes down to two things decided long before the attack: whether verified backups existed outside the attackers’ reach, and whether the business had someone to call who knew the environment. Businesses with both are typically operational again in hours or days. Businesses with neither can lose weeks, and some never fully recover.


The One-Page Version to Print

Here is the whole first hour, condensed. Print it, and keep it somewhere that is not on a computer.

Suspected Cyberattack: First Hour

1. Photograph screens, write down what happened and when.
2. Disconnect affected machines from the network. Leave them powered on.
3. Call IT provider: Advanced IT Support, 904-204-6870.
4. From a clean device, change passwords: email, banking, admin, payroll.
5. Call cyber insurance carrier.
6. Brief employees, designate one spokesperson, no external statements yet.
Do not: power off machines, wipe or clean anything, contact or pay attackers.

The best time to think about this sequence is when you do not need it. The same is true of everything that makes the sequence work: the backups, the MFA, the monitoring, and the provider relationship that means Step 3 reaches someone who already knows your environment.