Almost every piece of cyber security advice is about prevention. Strong passwords, software updates and staff training are all aimed at stopping an incident.
Far less is written about the hour after you realise something has happened. That hour contains decisions that can be difficult to reverse, and they are often made by people under pressure who have never rehearsed them.
Only a quarter of UK businesses have a formal incident response plan. Among micro businesses the figure is 21%, and 45% of businesses have none of the incident-response measures measured by the government's Cyber Security Breaches Survey 2025/2026. For many owners, the first hour will otherwise be improvised.
Here is what to do, and what to avoid.
First, a correction about timing
“The first hour” means the first hour after you become aware of the incident. It is not necessarily the first hour of the attack.
M-Trends 2026 reports a global median dwell time of 14 days across Mandiant's 2025 investigations, up from 11 days. That is useful context, not a clock for your incident: some attacks are detected much sooner and others persist far longer.
The practical point is that you may be discovering activity that has already been under way. Your job is to limit further harm without destroying the information responders need to understand what happened.
Do not power everything off automatically
The instinct is to shut every affected machine down. It feels decisive, but it can erase temporary evidence held in memory and make the incident harder to investigate.
That does not mean a shutdown is never appropriate. The NCSC's immediate-activities guidance says the choice between disconnecting and shutting down depends on the incident. Safety, rapidly spreading ransomware, operational technology and essential services can change the decision.
If it is safe and practical, isolate an affected device from wired, wireless and mobile networks, avoid clicking around, and get specialist advice. Do not wipe, reset or rebuild it simply to make the warning disappear.
This is worth discussing with your team in advance because the right response may be different from their first instinct.
Put one person in charge
Name one incident lead with authority to coordinate decisions, stop payments, isolate systems and pause normal work when needed. Name a deputy too, because incidents rarely happen at a convenient time.
The first-hour role is narrow: protect people and essential services, coordinate containment, start the right calls and make sure somebody records what happens. The incident lead does not need to be the technical investigator.
Avoid a committee issuing conflicting instructions. Agree who owns each action and when the next update will happen.
Start the important calls early
Use contact details you already trust, not details supplied in a suspicious message.
- IT support or an incident-response specialist: explain what you can confirm, what appears affected and what actions have already been taken.
- Your cyber insurer: notify it promptly if you have cover. A policy may provide an incident-response team or require approval before outside costs are incurred.
- Your bank or payment provider: call immediately if email, payment instructions, banking credentials or money may be involved.
These calls can happen in parallel. Do not wait until the end of an internal investigation before checking policy conditions or trying to stop a payment.
The government survey found that 47% of businesses reported some form of cyber cover, only 10% held a specific cyber policy, and 22% did not know whether they were insured. Find out what you have before an incident, including the notification number and any conditions attached to the response.
Stop suspicious money movements
If an email account may be compromised, pause unusual or high-risk outgoing payments until the account and instructions have been checked through a trusted route.
An attacker inside a mailbox may wait for a genuine invoice, then alter the bank details or send a convincing change request from the real account. The supplier, amount and email history can all look correct.
Change passwords and review active sessions from a device you have good reason to trust, following advice from your provider or responder. Do not use the machine you believe may be compromised to secure the rest of the business.
Keep one time-stamped incident record
Record what was seen, when it was seen, who made each decision and what happened after each action. Include:
- affected devices, accounts, services and locations;
- alerts, messages, filenames, addresses and other indicators;
- screenshots or original messages preserved without unnecessary alteration;
- suspected effects on staff, customers, suppliers, money and data;
- calls to insurers, advisers, authorities and regulators; and
- confirmed facts separately from assumptions.
It can feel like a distraction, but the timeline will help technical responders, the insurer and any regulator. Memory rarely preserves the order of events after a stressful week.
Understand the ICO's 72-hour rule
Not every cyber incident is a reportable personal data breach.
First establish whether personal data may have been lost, changed, destroyed, disclosed, accessed without authority or made unavailable. Then assess the likely risk to people's rights and freedoms.
The ICO's current breach guidance says a notifiable breach must be reported without undue delay and, where feasible, within 72 hours of becoming aware of it. The clock does not wait for a completed investigation. If every detail is not yet known, information can be supplied in phases.
If the threshold is unclear, get privacy or legal advice quickly and document the decision. The ICO's small-business guidance is under review following the Data (Use and Access) Act, so check the live guidance rather than relying on an old printed checklist.
Control what is communicated
Agree who updates staff, who contacts affected customers or suppliers, and who speaks publicly. Everyone else should avoid speculation, including on social media.
Use a communication channel you have reason to trust if normal email or messaging might be visible to an attacker. Keep updates factual: what you know, what you do not yet know, what people should do and when the next update will arrive.
Use the correct reporting routes
If a business, charity or organisation in England, Wales or Northern Ireland is suffering a live cyber attack, Report Fraud says to call 0300 123 2040 immediately. In Scotland, contact Police Scotland on 101.
Significant incidents can also be reported through the NCSC incident service. An NCSC report does not replace separate police, ICO, insurer, contractual or sector-regulator duties.
Suspicious emails, calls, text messages, social-media accounts and websites can be submitted through Report Fraud's suspicious-report route when no money has been lost and you have not responded.
What not to do
Do not wipe and rebuild immediately. Restoring service before establishing and closing the route in can recreate the same exposure.
Do not make a ransom-payment decision on the spot. Contact your insurer and obtain specialist legal and incident-response advice before deciding what to do.
Do not investigate casually on an affected system. Logging in, running tools or deleting files can overwrite evidence and alert the attacker.
Do not assume it is over because the screen looks normal. Recovery and resolution are separate jobs.
Recovery is not the same as resolution
Getting back to trading is recovery. Resolution means understanding how the incident happened, what the attacker reached, whether access remains and what must change.
The government's survey found that businesses experiencing cyber crime reported a median of three incidents in a year and a mean of nineteen. Those figures do not prove that every repeated incident used the same route, but they are a strong reason not to stop at restoring service.
For prevention steps that complement this response plan, read how cyber attacks often start and add its separate-channel verification rule to staff guidance.
After containment:
- establish the route in with evidence rather than assumption;
- rotate affected credentials and revoke sessions from trusted systems;
- patch or reconfigure the weakness;
- restore only from backups you have checked; and
- record what changed, who owns it and how the fix will be reviewed.
Put the plan on one page now
The plan that gets used is usually not a thick document. Put these items on one page:
- the incident lead and deputy;
- trusted numbers for IT support, the insurer and the bank;
- the first containment rule and who may authorise it;
- where the incident record will be kept if normal systems are unavailable;
- who handles staff, customer and public communications;
- the reporting and regulatory prompts; and
- the recovery checks required before normal service resumes.
Walk through the page with the people named on it. Print a copy or keep it somewhere that does not depend on the network you may be trying to recover.
The first hour should not be spent inventing authority, looking for telephone numbers or debating who is allowed to act. Make those decisions while everything is calm.