What to Do After a Cyber Attack

12th March 2026

Cyber crime costs businesses billions of dollars every single year. A recent study revealed that a cyber attack occurs every 39 seconds, meaning the threat to your data is constant and very real.

Knowing what to do immediately after a cyber attack can mean the difference between a minor operational hiccup and a complete business shutdown. Quick, decisive action stops hackers in their tracks, protects your sensitive information, and saves your company from severe financial loss.

In this guide, we break down exactly what you need to know and the precise steps you must take to secure your business, recover your data, and protect your team.

What is a Cyber Attack?

A cyber attack is when hackers deliberately try to gain unauthorised access to your computer systems, networks, or digital devices. Their goal is usually to steal, change, or destroy sensitive data. In some cases, they may hold your data hostage and demand a ransom.

Here are the most common types of cyber attacks businesses face:

  • Phishing: Hackers send fake emails that look like they come from trusted sources. They try to trick you into clicking malicious links or giving away passwords.

  • Malware: Malicious software, like viruses or spyware, designed to damage or access your network without permission.

  • Ransomware: A type of malware that locks your files and systems until you pay a ransom to regain access.

  • Insider Threats: Sometimes the danger comes from within. Employees or contractors might accidentally or intentionally leak sensitive company information.

Understanding these threats is the first step to protecting your business and keeping your digital workspace safe.

How Do I Know if My Business Has Been Hacked?

Hackers usually want to remain hidden for as long as possible. However, they almost always leave a trail. Recognising the early warning signs helps you stop an attack before it causes catastrophic damage.

Look out for these common signs of a cyber attack:

  • Unusual login activity: You might notice logins from strange locations or multiple failed login attempts on an employee account.

  • Extremely slow systems: Malware often runs heavily in the background. If your computers or internet suddenly slow down to a crawl, investigate immediately.

  • Locked files: If you suddenly cannot open everyday files, or if file names have strange extensions, you might be facing a ransomware attack.

  • Missing funds: Unexplained transfers or missing money from business bank accounts is a major red flag.

  • Altered passwords: Employees reporting that their passwords no longer work suggests someone has hijacked their accounts.

If you spot any of these indicators, assume your system is compromised and move immediately to containment.

What Should I Do Immediately After a Cyber Attack?

Time is your most valuable asset during a breach. You need to stop the spread of the attack to protect your remaining healthy systems.

Take these step by step actions right away:

Disconnect affected devices from the network
Do not turn the computers off. Instead, unplug the ethernet cables and turn off the Wi-Fi. Disconnecting stops the infection from spreading to other servers and devices while preserving critical evidence for forensic investigators.

Change passwords immediately
Have all employees change their passwords on a clean, uninfected device. Focus first on administrator accounts, email accounts, and financial portals. Use complex, unique passwords for every single login.

Inform your IT and security team
Contact your internal IT department or your external managed service provider. They need to mobilise immediately to contain the threat and secure your infrastructure. Notify upper management so they can start making critical business decisions.

Document all details of the attack
Write down exactly what happened, when it happened, and who discovered it. Note down any unusual screen messages or ransom notes. Take photos of the infected computer screens with a smartphone. This documentation proves crucial for both law enforcement and your cyber insurance provider.

How Can I Assess the Damage After a Cyber Attack?

Once you contain the immediate threat, you must figure out exactly what the hackers touched. This assessment guides your entire recovery strategy.

Follow this checklist to evaluate the impact:

  • Identify compromised devices: Make a list of every computer, phone, and server that showed signs of infection.

  • Locate affected data: Determine what files the hackers accessed. Did they touch customer credit card numbers, employee social security numbers, or proprietary business plans?

  • Check system functionality: Find out which business operations are currently offline. Can you process orders? Can your team send emails?

  • Prioritise critical systems: Decide which systems you absolutely need to get the business running again. Focus your recovery efforts on bringing these vital operations back online first.

Thorough assessment prevents you from accidentally bringing infected systems back online during the recovery phase.

Who Should I Notify After a Cyber Attack?

Communication is critical during a crisis. Hiding a breach almost always makes the situation worse and can lead to severe legal consequences.

You need to notify both internal and external parties:

  • Internal teams: Keep your employees informed. Tell them what happened, what systems are down, and what they need to do (like changing passwords). Clear communication prevents panic and stops rumors from spreading.

  • Customers and clients: If hackers accessed customer data, you must tell them. Explain what data was compromised and what steps you are taking to protect them. Transparency builds trust.

  • Law enforcement: Report the crime to local authorities or federal agencies like the FBI. They can offer guidance and might be tracking the specific hacking group responsible.

How Do I Safely Recover My Systems After a Cyber Attack?

Recovery takes time and precision. Rushing this process often leads to reinfection. Work closely with your IT professionals to rebuild your network securely.

Take these steps to safely restore operations:

  • Clean the infected machines: Your IT team must thoroughly scrub the affected devices. This often means completely wiping the hard drives and reinstalling the operating systems from scratch.

  • Scan for malware: Before reconnecting any device to the network, run deep antivirus and anti-malware scans. Ensure no hidden threats remain.

  • Restore data from clean backups: Pull your files from secure, offline backups. Verify that the backup files themselves were not infected before restoring them to your main network.

  • Update all software: Hackers usually exploit known vulnerabilities in outdated software. Apply every available security patch to your operating systems, applications, and network hardware.

  • Upgrade firewalls and security tools: Take this opportunity to strengthen your defenses. Install advanced endpoint protection and configure your firewalls to block suspicious incoming traffic.

How Can I Prevent Future Cyber Attacks?

Experiencing an attack highlights the gaps in your security. Use this hard learned lesson to fortify your business against the next threat.

Implement these vital prevention strategies:

  • Regular employee training: Human error causes the vast majority of security breaches. Train your team regularly on how to spot phishing emails, social engineering tricks, and suspicious links.

  • Multi-factor authentication (MFA): Require MFA for all accounts. This adds an extra layer of security by requiring a code from a mobile device along with a password.

  • Strong password policies: Enforce the use of password managers. Require employees to use long, complex passwords and prevent them from reusing passwords across different sites.

  • Secure, isolated backups: Back up your data daily. Keep a copy of your backups completely disconnected from your main network so ransomware cannot reach it.

  • Endpoint detection and response (EDR): Invest in advanced security software that actively monitors your network for strange behavior, rather than just scanning for known viruses.

What Daily Habits Can Employees Follow to Stay Safe?

Your employees are your first line of defense. By building simple security habits into their daily routine, they can drastically reduce your company’s risk profile.

Encourage your team to practice these daily habits:

  • Scrutinize emails: Always check the sender’s actual email address, not just the display name. Never click links or download attachments from unknown or unexpected senders.

  • Protect sensitive data: Never share passwords via email or instant messenger. Do not leave sensitive documents sitting openly on desks or visible on unlocked screens.

  • Keep devices updated: Promptly install software updates when prompted by the IT department. These updates contain critical security patches.

  • Use secure networks: Avoid accessing company data over public Wi-Fi networks at coffee shops or airports. Always use a virtual private network (VPN) when working remotely.

  • Speak up quickly: Report any strange computer behavior or suspicious emails to the IT department immediately. A fast report can stop a massive breach.

Conclusion

A cyber attack can be stressful, but staying calm and following a clear plan makes all the difference. Remember the key steps: detect the threat, act quickly to contain it, assess the damage, recover your systems safely, and put measures in place to prevent future attacks.

Fast, decisive action can minimise financial loss, protect your valuable data, and strengthen your overall security.

Don’t wait for a cyber attack to catch your business off guard. Protect your company today. Contact Gray IT for professional cyber attack response, complete data recovery, and employee cyber security training.