2

What to Do in the First 24 Hours After a Cyber Attack

Most business owners assume a cyber attack won’t happen to them — until it does. And when it does, the first 24 hours are critical. How you respond in that window can be the difference between a minor disruption and a catastrophic loss of data, money, and customer trust.

Here’s exactly what to do.

Hour 1 — Don’t panic, but act fast
The moment you suspect something is wrong — systems behaving strangely, files you can’t access, unusual login alerts — stop what you’re doing. Don’t try to fix it yourself and don’t shut everything down immediately. Your first call should be to your IT support provider. If you don’t have one on speed dial, that’s a problem we’ll address at the end of this article.

Hour 2 — Isolate the affected systems
Your IT team should immediately isolate any infected devices from the rest of your network. This means disconnecting from Wi-Fi, unplugging ethernet cables, and preventing the attack from spreading to other machines. Don’t delete anything — evidence matters.

Hour 3-6 — Assess the damage
Once contained, your IT provider will assess what’s been affected. Which systems were compromised? Was any customer data accessed? Are backups intact? This assessment shapes everything that comes next — including whether you have a legal obligation to report the breach.

Hour 6-12 — Report if required
Under UK GDPR, if personal data has been breached you have 72 hours to report it to the Information Commissioner’s Office (ICO). Your IT provider and legal team should guide you through this. Don’t ignore it — the fines for failing to report are significant.

Hour 12-24 — Communicate and recover
If customers or staff have been affected, communicate clearly and honestly. People respect transparency far more than silence. Meanwhile your IT team should be working to restore systems from clean backups and securing the vulnerabilities that allowed the attack in the first place.

The best defence is preparation
The businesses that recover quickest from cyber attacks are the ones that had a plan before it happened — regular backups, monitored systems, and a trusted IT partner on call. At Cloud Guard, we help businesses across Glasgow and the UK put those protections in place before something goes wrong, not after.

If you’re not sure whether your business is properly protected, get in touch today for a free security consultation