What to Do in the First 24 Hours After a Cyberattack

A cyberattack doesn’t wait for business hours, and neither should your response.

Whether it’s ransomware locking your files, suspicious account activity, or systems suddenly going offline, the first 24 hours after a cyberattack are often the most important.

The decisions made during this period can determine whether your business experiences a temporary disruption or a prolonged crisis involving data loss, financial damage, regulatory issues, and reputational harm.

Unfortunately, many organizations are unprepared. Studies consistently show that a large percentage of businesses lack a documented cyberattack response plan, leaving employees and leadership scrambling when an incident occurs.

The good news is that a clear, structured response can significantly reduce the impact of an attack.

Knowing what to do, and what not to do, in the first 24 hours can make the difference between a contained incident and a catastrophic breach.

Why the First 24 Hours Matter

Cybercriminals move quickly. Some ransomware variants can encrypt entire networks in less than an hour. Once systems are compromised, every minute matters.

At the same time, legal and regulatory obligations may begin immediately. Canadian businesses subject to the Personal Information Protection and Electronic Documents Act (PIPEDA) must assess whether a breach creates a real risk of significant harm and determine whether notification requirements apply.

The first 24 hours are also critical for preserving evidence. Improper actions can overwrite logs, destroy forensic information, and make it more difficult to determine what happened.

Perhaps most importantly, customer trust depends on how organizations respond.

Businesses that act quickly, communicate clearly, and demonstrate control of the situation are often better positioned to preserve relationships and recover more effectively.

Hour 0–1: Detect, Confirm, and Contain

Recognize the Signs of an Attack

Cyberattacks can present themselves in many ways. Common warning signs include:

  • Files suddenly becoming inaccessible or encrypted
  • Ransom notes appearing on devices
  • Unusual login activity
  • Unexpected system outages
  • Strange network behaviour or unauthorized software installations

Even if you’re uncertain whether an attack is occurring, unusual activity should always be treated seriously.

Don’t Panic- But Act Immediately

It’s natural to feel overwhelmed when a cyber incident occurs. However, acting impulsively can make the situation worse.

Avoid immediately wiping devices, reinstalling systems, or deleting suspicious files. These actions can destroy valuable evidence that cybersecurity professionals need to understand the scope of the attack and determine the appropriate recovery steps.

Isolate Affected Systems

Containment is essential.

Disconnect compromised devices from the network by unplugging Ethernet cables or disabling Wi-Fi connections. Doing so can help prevent malware from spreading to additional systems.

However, avoid powering devices off unless directed by cybersecurity professionals. Important forensic evidence may exist in a system’s active memory and could be lost during shutdown.

Activate Your Incident Response Team

Notify the appropriate individuals immediately, including:

  • Internal IT personnel
  • Leadership teams
  • Department managers
  • Your managed IT provider or cybersecurity partner

Having the right people involved early helps ensure decisions are made quickly and consistently.

Hour 1–4: Assess and Document

Identify the Scope of the Attack

Begin determining the extent of the incident:

  • Which systems have been affected?
  • What data may be involved?
  • Is the attack still active?
  • Are backups accessible?

The answers to these questions will shape your recovery strategy.

Preserve Evidence

Documentation is critical during a cyber incident.

Capture screenshots of error messages and ransom notes. Save system logs where possible. Record timestamps and document actions taken by employees and IT staff.

Also, avoid logging into accounts that may be compromised, as doing so can alter evidence and complicate investigations.

Determine the Type of Attack

Not all cyber incidents are the same.

You may be dealing with:

Understanding the nature of the attack helps determine containment and recovery priorities.

Engage Cybersecurity Experts

Most small and mid-sized businesses do not have in-house forensic capabilities.

This is where a trusted IT partner becomes invaluable. Experienced cybersecurity professionals can rapidly assess the incident, coordinate containment efforts, preserve evidence, and guide recovery activities while minimizing further business disruption.

Hour 4–12: Notify and Communicate

Communicate Internally

Employees need clear instructions.

Explain what is happening and provide guidance on what they should and should not do. For example:

  • Do not click suspicious emails or links.
  • Do not attempt unauthorized troubleshooting.
  • Do not discuss the incident publicly or on social media.

Clear communication reduces confusion and prevents accidental mistakes that could worsen the situation.

Address Legal and Regulatory Obligations

Cyber incidents often involve legal considerations.

Under PIPEDA, organizations may be required to report breaches involving a real risk of significant harm to affected individuals and the Office of the Privacy Commissioner of Canada.

Engaging legal counsel early can help organizations understand their obligations and ensure notifications are handled appropriately.

Notify Your Insurance Provider

If your business has cyber insurance, contact your insurer immediately.

Many policies require prompt notification and may specify approved incident response procedures or vendors. Delays can complicate claims and potentially affect coverage.

Prepare External Communications

Customers, partners, and vendors may need information about the incident.

Transparency matters. Clear, honest communication demonstrates professionalism and helps maintain trust during uncertain situations.

A carefully prepared message is far more effective than rushed or incomplete communication.

Hour 12–24: Contain, Eradicate, and Begin Recovery

Eliminate the Threat

Once the attack has been assessed, efforts can shift toward remediation.

This may include:

  • Removing malicious software
  • Closing exploited vulnerabilities
  • Resetting compromised credentials
  • Applying security patches
  • Restricting unauthorized access

The objective is to eliminate active threats and stabilize the environment.

Begin Restoring from Backups

Backups play a critical role in recovery.

However, backups should never be restored immediately without verification. They must first be confirmed as clean and uncompromised to avoid reinfecting systems.

Reliable backup and disaster recovery planning significantly reduce downtime and help businesses return to normal operations more quickly.

Monitor for Re-Entry

Cybercriminals frequently attempt to maintain access.

Backdoors, stolen credentials, and hidden malware can allow attackers to re-enter systems even after initial remediation efforts.

Continuous monitoring is essential in the days and weeks following an incident.

Document Everything

Maintain a detailed record of:

  • Systems affected
  • Actions taken
  • Communication timelines
  • Recovery activities
  • Decisions made throughout the incident

This documentation supports insurance claims, regulatory requirements, legal obligations, and future security improvements.

What NOT to Do in the First 24 Hours

Certain mistakes can significantly increase the impact of a cyberattack.

Avoid:

  • Paying a ransom without expert guidance
  • Hiding the incident from leadership or stakeholders
  • Trying to manage everything without cybersecurity expertise
  • Deleting suspicious files or evidence
  • Assuming the incident is over simply because systems appear functional

Careful, deliberate action is always more effective than reactive decision-making.

The Best Time to Prepare Is Before an Attack

Organizations that recover most effectively typically have one thing in common: they prepared before the incident occurred.

A strong cyberattack response plan should include:

  • Documented response procedures
  • Clearly defined roles and responsibilities
  • Reliable, regularly tested backups
  • Continuous monitoring and managed IT support
  • Appropriate cyber insurance coverage

Preparation transforms chaos into a structured, manageable response.

Why Response I.T. Is Your Incident Response Partner

For more than 20 years, Response I.T. has helped organizations throughout Kingston and across Canada protect their operations and recover from technology disruptions.

Our team provides proactive managed IT services, network security solutions, disaster recovery planning, and rapid-response support designed specifically for small and mid-sized businesses.

We help organizations prepare for incidents, respond effectively when they occur, and recover with confidence, because a cyberattack should never define your business.

Don’t Wait Until an Incident Happens to Create a Cyberattack Response Plan

The first 24 hours after a cyberattack are critical. Every decision matters, and preparation remains your strongest defense.

Whether your organization is currently facing a cyber incident or wants to ensure it is ready before one occurs, Response I.T. can help.

Contact Response I.T. today and build a cyberattack response plan that protects your business before the unexpected happens.