
What to Do After a Cyberattack | Small Business Guide
The moment you realize your business has been hit — ransomware on the screen, employees locked out, emails going places they shouldn’t — everything in you wants to fix it immediately. That instinct makes sense. It can also make things significantly worse. According to IBM’s 2024 Cost of a Data Breach Report, organizations that contain a breach quickly save an average of $1 million compared to those that don’t. Speed matters — but the right first move is containment, not remediation. Here’s what to do, in order.
Stop. Don’t Do Anything Yet.
The most common mistake small business owners make in the first minutes of a cyberattack is trying to fix it. They power off the machine. They delete suspicious files. They wipe and reinstall the operating system. All of that feels productive. Most of it is counterproductive.
Powering off an affected machine destroys the volatile memory that forensic investigators use to understand what happened — what was accessed, what was running, how the attacker got in. Deleting files eliminates logs your IT provider and insurance carrier will need. Reinstalling without first taking a forensic image leaves the root cause unknown and potentially still active in your environment.
Before you do anything, take a breath. The attack has already happened. What you do in the next 30 minutes determines how bad the recovery gets.
Contain It First
Containment means stopping the spread without destroying evidence. It’s not complicated, but you need to do it in the right order.
Disconnect affected devices from the network. Pull the ethernet cable or turn off Wi-Fi on any machine showing symptoms. Do not power it off — just isolate it. If the device is a laptop, close the lid but leave it on.
Leave everything else alone. Don’t close programs, don’t move or delete files, don’t try to access anything on the affected machine. If there’s a ransom note or error message on screen, take a photo of it with your phone. Note the time.
Check your other machines. If more than one device is showing signs of trouble, your network may already be compromised across multiple systems. Don’t bring anything new online until you understand the scope.
The goal is simple: stop the damage from reaching the rest of your environment while keeping what you have in a state where it can actually be analyzed.
Who to Call in the First Hour
Three calls. Make them in roughly this order.
Your IT provider or MSP. Call them now. If you have a managed IT provider, this is exactly what you’re paying for. They should be your first point of contact and the ones coordinating everything from here. If you don’t have one, this is the moment where that gap becomes very expensive — you’ll be trying to find emergency help while the clock is running.
Your cyber insurance carrier. If you have a cyber policy, your carrier likely has a breach response team that activates immediately. They often coordinate the forensic investigation, legal counsel, and any required notifications. This matters: making major recovery decisions before looping in your carrier can affect your coverage. Not sure what your policy covers? That’s worth sorting out before something like this happens. (What Colorado businesses should know about cyber insurance)
Legal counsel, if personal data may be involved. Colorado has mandatory breach notification requirements under HB 18-1128. If your business stores personal information about customers or employees — names, Social Security numbers, financial data, health information — and that data may have been accessed, you could be on a legal clock. An attorney can tell you whether you’re required to notify, who, and by when. That’s not a “we’ll figure it out later” call.
One more worth making: the FBI’s Internet Crime Complaint Center at ic3.gov. Reporting your incident won’t undo the damage, but it feeds into federal tracking of cybercrime patterns and is a straightforward thing to do once the immediate crisis is managed.
What Recovery Actually Looks Like
Set honest expectations: recovering from a real incident takes days to weeks, not hours. Here’s the rough sequence.
Forensic assessment first. Before anything goes back online, your IT provider or a forensic specialist needs to understand what happened — how the attacker got in, what was accessed or exfiltrated, and whether anything is still active in your environment. Going back online without this is how businesses get hit twice.
Restore from clean backup — or rebuild. If your backups are current, tested, and stored separately from your main environment, recovery is significantly faster. If your backups are outdated, incomplete, or were also encrypted in the attack, you’re rebuilding from scratch. This is the part where backup discipline pays off or doesn’t. (Are your business backups actually working?)
Reset credentials across the board. Any password stored on or used from an affected system should be treated as compromised. Email, banking, software logins, admin accounts — all of it gets a new password. Multi-factor authentication goes on anything that doesn’t already have it. (Why MFA matters for small business)
Verify before going live. Don’t rush to restore operations until your IT provider confirms the threat is fully removed and your environment is clean. Coming back online too early is how small businesses end up dealing with the same attack twice.
Don’t Waste the Crisis
Once you’re back up, there’s a window — while the experience is still fresh and the business case is obvious — to fix the things that made this possible.
Most incidents trace back to a short list of root causes: no MFA on critical accounts, endpoint protection that wasn’t kept current, backups that were never tested, user accounts with more access than they needed. None of these are complicated fixes. They’re just things that get pushed off until they can’t be anymore. (Endpoint protection for small business, Role-based access controls)
The businesses that recover well from incidents aren’t the ones that got lucky — they’re the ones that used the experience to close gaps they already knew were there. If you’d like an honest look at where your business stands before something like this happens, that’s a conversation worth having. Reach out here.
Frequently Asked Questions
Should I pay the ransom if my business gets hit with ransomware?
The FBI recommends against paying ransoms, and for good reason: there’s no guarantee you’ll get your data back, payment signals to attackers that you’re a viable target, and it may fund further criminal activity. That said, it’s a business decision — one best made with your IT provider, insurance carrier, and legal counsel all in the room. The better answer is having clean backups so payment is never the only option.
How long does it take a small business to recover from a cyberattack?
It depends on the scope and your backup situation. A well-contained incident with current, verified backups can be resolved in a few days. A full ransomware event with no clean backups can take weeks and involve significant rebuild costs. The IBM Cost of a Data Breach Report consistently shows that organizations with incident response plans and tested backups recover faster and at lower cost.
Does my business have to notify customers if we get hacked?
It depends on what data was exposed and where your customers are located. Colorado’s HB 18-1128 requires breach notification when personal information is compromised — there are specific timeframes and requirements. If you operate in multiple states or handle health information, additional laws may apply. Talk to legal counsel early; this isn’t something to figure out after the fact.
What if I don’t have cyber insurance?
You’ll be covering all recovery costs out of pocket: forensic investigation, legal fees, notification costs, potential regulatory fines, and lost business during downtime. That can add up to tens of thousands of dollars for a small business. If you don’t have a policy, it’s worth reviewing what coverage makes sense before an incident happens — not after.
Can I handle a cyberattack recovery without an IT provider?
Technically yes, but it’s not advisable. The forensic assessment, containment verification, and clean restoration all require technical skill that most business owners don’t have — and mistakes at any stage can mean incomplete recovery or re-infection. If you don’t have an IT provider, this is the moment to get one involved even on a one-time basis. It will be significantly less expensive than a botched self-recovery.
What should I do right now if I think my business has been hacked?
Isolate the affected device from your network (disconnect ethernet or Wi-Fi, don’t power off), photograph any error or ransom messages, and call your IT provider immediately. If you don’t have one, call your cyber insurance carrier — they’ll connect you with emergency response resources. Do not delete files or attempt to fix anything before those calls.