The First 24 Hours: What to Do When You Suspect a Cyber Incident

It usually doesn’t announce itself with a ransom note on every screen. More often, it starts small: a vendor calls asking why you changed your bank details. An employee mentions their sent folder is full of emails they never wrote. A file server slows to a crawl on a Tuesday afternoon for no reason anyone can name.

What your business does in the next 24 hours will largely determine whether this becomes a bad day or a defining event. The companies that recover quickly aren’t lucky — they knew what to do before they needed to. The ones that suffer most tend to make the same handful of avoidable mistakes in the first few hours.

Here’s a practical walk-through of that first day, and the missteps to avoid.

Hour Zero: Contain, Don’t Clean

Your instinct will be to fix it — delete the weird files, run an antivirus scan, reboot everything. Resist that instinct.

Disconnect, don’t power off. If a machine looks compromised, unplug it from the network (pull the Ethernet cable, kill the Wi-Fi) but leave it running. Powering down can destroy the evidence in memory that investigators need to determine what happened and what was taken — evidence your insurer and, in some cases, regulators will ask about.

Don’t wipe and reinstall yet. Rebuilding a machine before anyone examines it is like mopping a crime scene. You may feel productive while eliminating the only record of how the attacker got in, which means you can’t be sure you’ve actually shut the door.

Assume the attacker can read your email. If your suspicion involves compromised accounts, coordinate the response by phone or text, not through the email system you suspect is breached. Attackers routinely monitor inboxes and delete or intercept warnings.

Hours 1–4: Sound the Right Alarms

Call your IT provider immediately. Not after the weekend, not after you’ve “looked into it.” Speed matters enormously here: attackers who realize they’ve been spotted either accelerate to do maximum damage or dig in deeper to survive cleanup. If you have a managed IT partner, this is exactly the call they exist for.

Call your cyber insurance carrier’s hotline. Most policies have a 24/7 breach line — and most also have strict notification requirements. Waiting days to report, or hiring outside help the carrier hasn’t approved, can jeopardize your coverage. Your carrier can also bring in a breach coach (an attorney) and forensics team, often at the policy’s expense.

Start a written timeline. Who noticed what, when, and what actions were taken. Do it on paper or on a device you know is clean. This log becomes invaluable for insurers, investigators, and any required notifications later.

Preserve your backups — offline. If backups are connected to the network, an active attacker may target them next. Verify they exist, verify they’re recent, then isolate them.

Hours 4–12: Figure Out the Blast Radius

With professional help engaged, the focus shifts to scope. Which accounts, machines, and data were touched? Was anything taken, or just accessed? Are the attackers still inside?

This is where preparation pays off or its absence bites. Businesses with centralized logging and monitoring can often answer these questions in hours. Businesses without them may never answer definitively — and when you can’t prove what wasn’t accessed, notification laws often force you to assume the worst.

Two decisions typically surface in this window:

  • Whether to pay a ransom (if there is one). Don’t decide this alone or quickly. Your breach coach and insurer have negotiators and know the legal constraints — paying certain sanctioned groups is itself illegal. And remember our earlier post on backups: the ability to restore is what turns this from a negotiation into a cleanup.
  • Whether money is in motion. If the incident involves fraudulent payment instructions or a compromised finance inbox, call your bank immediately — recalls of wire transfers are sometimes possible in the first hours and rarely after that.

Hours 12–24: Communicate Deliberately

Say something to your team — rumor fills any vacuum — but keep it factual and brief: what’s affected, what to do (or not touch), and who’s coordinating. Hold off on customer or public statements until you actually know the scope; walking back an inaccurate reassurance is far worse than a short delay. Ohio, like every state, has breach notification requirements with specific triggers and timelines — that’s a decision to make with counsel, not on adrenaline.

The Uncomfortable Truth

Almost everything above goes faster, cheaper, and calmer if it were decided before the incident: who to call, where the insurance hotline number lives, whether backups are isolated, whether logging exists, who’s authorized to make the call at 6 a.m. on a Saturday. That document is an incident response plan, and for a small business, it can fit on two pages. The businesses we see recover in days instead of weeks all have one.

Know Who to Call

If you read this and realized you don’t know who’d get that first phone call, that’s the gap to close this week, not after something happens.

CMIT Solutions of Dayton South helps local businesses build simple, usable incident response plans — and backs them with 24/7 monitoring so the incident gets spotted at hour zero, not day three. Call us at (937) 518-6590 or request a consultation, and we’ll help you get a plan on paper.

Back to Blog

Share:

Related Posts

When One Tech Isn’t Enough: The Case for Managed IT Services

Over the course of my three-decade career I’ve worked in a wide…

Read More

Securing Trust

I was walking through the Dayton Home and Garden Show when I…

Read More

Is Your Business Prepared for Today’s Cybersecurity Expectations?

For many small and mid-sized businesses in **Dayton and Southwest Ohio**, cybersecurity…

Read More