The ransom note on the screen, the customer who says your emails are sending scams, the login that suddenly does not work: the moment you realize you have been attacked is disorienting, and the temptation is to panic or to freeze. But the first hour often shapes how bad the whole thing gets. You do not need to be a security expert to handle it well, you need a short, calm plan you can follow when your heart is pounding. Here is that plan. Keep it somewhere you can find it when you need it.
First, contain, without destroying evidence
Your first job is to stop the spread. Disconnect affected devices from the network, unplug the network cable, turn off the Wi-Fi, so malware or an intruder cannot reach the rest of your systems. But resist the urge to wipe or rebuild anything yet, and be careful about simply powering machines off, because that can destroy evidence that helps you understand what happened and prove it later. Isolate, do not erase. If in doubt, disconnect but leave it on.
Call the right people, in the right order
- Your IT support or security provider first, the people who can actually assess and respond. If you have a plan, this is where it kicks in.
- Your cyber insurer, if you have coverage. Many policies require you to notify them early and will provide expert help, and acting on your own first can even affect a claim.
- Legal advice, especially if personal data may be involved, since you may have reporting duties.
- Law enforcement as appropriate, and in Canada you can report to the Canadian Anti-Fraud Centre and the Canadian Centre for Cyber Security.
Do not do these things
A few instincts make it worse. Do not pay a ransom on the spot, that is a decision for after you understand your options and have expert advice, not a panic reaction. Do not try to quietly clean it up and move on as if nothing happened, hidden compromises come back. Do not broadcast details publicly before you understand the situation. And do not lie to yourself about the scope, assume the attacker saw more than you hope until you know otherwise.
Then move to the plan
Once the immediate bleeding is stopped and the right people are engaged, you shift from the frantic first hour to the structured response: understanding what happened, recovering cleanly from backups, meeting any breach-notification obligations, and communicating honestly with anyone affected. The businesses that come through an attack with the least damage are rarely the ones that were never hit, they are the ones who stayed calm, contained it fast, and called for help early. An hour of clear thinking, prepared in advance, is your best defence.