Your First 60 Minutes After a Cyberattack: An Incident Response Guide for Small Businesses

Author/Publisher: CMIT Solutions Northern Shenandoah Valley
Focus: Incident response plan for small business, small business cybersecurity, and business continuity

September is Business Continuity Month: a useful reminder that disaster preparedness, incident response, risk management, and backup testing cannot remain on the to-do list.

If your business is hit by ransomware, business email compromise, or another cyberattack, the first hour matters. Panic decisions can turn a contained incident into prolonged downtime, lost evidence, denied insurance coverage, or a regulatory problem.

Your objective is not to “fix everything” in 60 minutes. Your objective is to slow the attack, protect evidence, activate the right people, and preserve your recovery options.

This guide is designed for small businesses in Winchester, Frederick County, Clarke County, Martinsburg, Charles Town, and throughout the Eastern Panhandle. It is especially relevant to accounting firms, law firms, schools, churches, agribusinesses, and general SMBs without in-house IT.

Why the First Hour Is So Important

Traditional break-fix thinking: wait until something stops working, then call for help: must be retired immediately during a cyberattack. Every minute can allow an attacker to move laterally, steal data, disable backups, or compromise additional accounts.

Avoid these common panic responses:

  • Do not pay a ransom immediately. Payment does not guarantee decryption, deletion of stolen data, or an end to the attack. Consult your insurer, legal counsel, IT provider, and law enforcement first.
  • Do not wipe or reimage a computer. You may destroy evidence needed for forensics, insurance, and legal obligations.
  • Do not power off systems carelessly. Shutting down can erase valuable evidence in volatile memory. Isolate systems from the network first unless your technical responder directs otherwise.
  • Do not use potentially compromised email to coordinate the response. Use phone calls, in-person conversations, or another trusted channel.
  • Do not let every employee investigate independently. Uncoordinated actions can make containment harder and send attackers a warning.

The first hour is about creating control: not creating a perfect answer.

The First 60 Minutes: A Practical Walkthrough

Minute 0–10: Recognize, Confirm, and Isolate

Look for signs such as encrypted or inaccessible files, unusual file extensions, ransom notes, locked screens, unexpected account activity, or multiple systems behaving abnormally.

Record what you see, including the exact time and any ransom message. Take a photograph or screenshot if it can be done safely.

Then isolate affected systems:

  • Disconnect network cables from affected computers.
  • Remove affected devices from Wi-Fi.
  • Disconnect accessible backup drives, NAS devices, or synchronization systems.
  • If several systems are affected, contact your technical responder about taking a network segment offline.
  • Do not begin restoring backups yet.

If you cannot disconnect a system from the network, powering it down may be necessary to limit further spread. Otherwise, leave it running for responders because memory and other volatile evidence may be lost.

So what? Fast isolation can limit the blast radius and protect the systems your business needs to keep operating.

Minute 10–20: Notify Leadership and Establish Authority

Call the person designated as your incident lead. If that role has not been assigned, the owner or senior operations leader must designate one immediately.

The incident lead should:

  1. Confirm who is making operational decisions.
  2. Establish a trusted communication channel.
  3. Instruct employees not to open suspicious files, connect USB devices, or attempt repairs.
  4. Identify critical business functions that may be affected.
  5. Begin a written incident timeline.

One person should not make every technical, legal, and communications decision. Even a small business needs clear authority.

Minute 20–35: Contain the Incident and Preserve Evidence

Containment is more than disconnecting a laptop. Your technical responder may need to:

  • Disable compromised user accounts.
  • Revoke active sessions and remote access tokens.
  • Disable VPN, remote desktop, or other suspected access paths.
  • Isolate affected servers, cloud workloads, or network segments.
  • Preserve endpoint, firewall, Microsoft 365, authentication, and backup logs.
  • Capture system images or memory from representative devices when feasible.
  • Preserve ransom notes, suspicious files, email headers, and indicators of compromise.

Do not change passwords across the entire organization blindly unless directed. Resetting accounts in the wrong order can lock out legitimate users while leaving an attacker’s persistence in place.

Preserve logs. Logs may show when the attacker entered, which accounts were used, what data was accessed, and whether backups were targeted. That information can determine the scope of the event and support an insurance claim.

Minute 35–50: Call Your Response Contacts

Contact these parties using trusted phone numbers: not links or phone numbers included in suspicious messages:

Contact Why the call matters
IT provider or incident response contact Technical containment, evidence preservation, and recovery planning
Cyber insurance carrier hotline Policy-required reporting, approved vendors, coverage guidance, and claim handling
Legal counsel Privilege, breach analysis, contracts, regulatory duties, and communications
Law enforcement, when appropriate Investigation, threat intelligence, possible decryption guidance, and reporting

Cyber insurance notification timing matters. Many policies require prompt notice and may require you to use approved forensic, legal, or negotiation providers. Waiting too long or hiring outside help without checking the policy can create coverage complications. Read your policy now: before an incident occurs.

The CISA #StopRansomware Guide recommends engaging internal and external response teams, preserving evidence, isolating affected systems, and reporting incidents to appropriate authorities. You can also report cybercrime through the FBI Internet Crime Complaint Center.

Minute 50–60: Begin the Communication Plan

Do not speculate, blame employees, or promise a recovery time you cannot support.

Your initial employee message should state:

  • What is known and what is still being investigated.
  • Which systems employees should stop using.
  • How employees should report suspicious activity.
  • Which communication channel is trusted.
  • Who is authorized to speak externally.

Client, vendor, and public communications should be coordinated with leadership, legal counsel, and your insurer. If personal information, protected health information, financial records, student information, or privileged legal data may be involved, legal counsel should evaluate notification obligations.

Applicable requirements can vary by state, industry, contract, and data type. Refer to CISA’s ransomware guidance and consult counsel regarding Virginia, West Virginia, HIPAA, contractual, or other requirements.

Assign These Roles Before an Incident

Small businesses without in-house IT are often most exposed because nobody has been assigned to lead the response.

Role Primary responsibility Small-team option
Incident lead Makes business decisions and coordinates the response Owner or general manager
Technical contact Isolates systems, preserves evidence, and works with responders MSP, IT consultant, or technically capable employee
Communications lead Manages employee, client, vendor, and public messages Office manager or marketing lead
Legal/compliance contact Evaluates notification, privilege, contracts, and regulatory duties Outside attorney or compliance adviser

One person may wear multiple hats, but every role must have a named primary and backup. Store the assignments offline and in a printed copy.

Containment Do’s and Don’ts

Do

  • Use phone or other trusted out-of-band communication.
  • Write down actions, names, and timestamps.
  • Photograph ransom notes and suspicious screens.
  • Preserve logs and affected devices.
  • Protect offline and immutable backups.
  • Follow your cyber insurance policy.
  • Let qualified responders direct technical changes.

Don’t

  • Don’t negotiate with attackers alone.
  • Don’t wipe, rebuild, or restore systems prematurely.
  • Don’t assume only encrypted computers are affected.
  • Don’t trust email from an account that may be compromised.
  • Don’t reconnect backups until the environment is confirmed clean.
  • Don’t announce unverified facts to customers or employees.

What to Document

Start an incident log with:

  • Date and time the issue was discovered.
  • Person who discovered it.
  • Systems, accounts, locations, and applications affected.
  • Exact error messages or ransom instructions.
  • Actions taken and by whom.
  • People and organizations notified.
  • Evidence collected and where it is stored.
  • Business functions disrupted.
  • Data that may have been accessed, altered, or stolen.

Documentation supports insurance claims, forensic analysis, legal review, regulatory reporting, and future improvements. It also prevents valuable details from disappearing as the first stressful hours become days.

If You Have No IT Provider or Incident Response Plan

Take this bare-minimum path:

  1. Call the business owner or senior leader and appoint an incident lead.
  2. Use a clean phone to coordinate: not business email.
  3. Disconnect affected devices from wired and wireless networks.
  4. Do not wipe or restore systems.
  5. Photograph ransom notes and record timestamps.
  6. Call your cyber insurance carrier, if you have one.
  7. Call a reputable incident response provider or IT professional.
  8. Contact legal counsel.
  9. Report the event to FBI IC3 when appropriate.
  10. Tell employees to stop using affected systems and preserve suspicious messages.

This is not a substitute for a formal plan, but it can prevent money from going down the drain while you assemble qualified help.

Practice the Plan Before You Need It

An untested incident response plan often fails at the breaking point. People discover that the insurance hotline is missing, passwords are stored on an encrypted server, backups were never tested, or nobody knows who can approve shutting down the network.

Run a tabletop exercise at least twice a year and after major technology or staffing changes. Walk through scenarios such as ransomware, a compromised Microsoft 365 account, or a lost laptop containing sensitive data.

Key Success Factors

  • Named incident roles and backups.
  • Current contact information stored offline.
  • Tested backups and documented recovery priorities.
  • A trusted communications method.
  • Cyber insurance requirements understood in advance.
  • Regular employee awareness training.
  • A written after-action review.

The Results: faster decisions, fewer conflicting instructions, better evidence, stronger insurance positioning, and less operational uncertainty.

Your Next Business Continuity Step

A written incident response plan for your small business should connect cybersecurity controls with business continuity. That includes 24/7 monitoring, endpoint protection, backup testing, identity controls, documented escalation procedures, and practical recovery priorities.

Businesses in Winchester, Frederick County, Clarke County, Martinsburg, and Charles Town do not need to build this alone. Whether you operate an accounting firm, law office, school, church, agribusiness, or general SMB, begin by assigning the roles and contacts described above. If you need a local technical partner, CMIT Solutions Northern Shenandoah Valley can help you assess your readiness and build a plan before an incident becomes a breaking point.

Frequently Asked Questions

Should I pay a ransomware demand?

Not immediately. Payment does not guarantee recovery and may create legal, sanctions, insurance, or repeat-attack concerns. Contact your insurer, legal counsel, technical responder, and law enforcement first.

Should I shut down a ransomware-infected computer?

Usually, isolate it from the network first. Shutting it down can destroy volatile evidence. If you cannot disconnect it and the infection is spreading, shutdown may be necessary to limit damage. Follow qualified technical guidance.

How quickly should I notify my cyber insurance carrier?

As soon as possible under the policy’s reporting requirements. Many policies require prompt notice and may require approved vendors or specific procedures.

Should employees use email during an attack?

Assume business email may be compromised until confirmed otherwise. Use phone calls, in-person communication, or another trusted channel.

How often should we test our incident response plan?

At least twice per year, plus after major changes to staff, systems, vendors, insurance coverage, or business operations.

{“@type”:”FAQPage”,”author”:{“name”:”CMIT Solutions Northern Shenandoah Valley”,”@type”:”Organization”},”@context”:”https://schema.org”,”publisher”:{“name”:”CMIT Solutions Northern Shenandoah Valley”,”@type”:”Organization”},”mainEntity”:[{“name”:”Should I pay a ransomware demand?”,”@type”:”Question”,”acceptedAnswer”:{“text”:”Not immediately. Payment does not guarantee recovery and may create legal, sanctions, insurance, or repeat-attack concerns. Contact your insurer, legal counsel, technical responder, and law enforcement first.”,”@type”:”Answer”}},{“name”:”Should I shut down a ransomware-infected computer?”,”@type”:”Question”,”acceptedAnswer”:{“text”:”Usually, isolate it from the network first. Shutting it down can destroy volatile evidence. If you cannot disconnect it and the infection is spreading, shutdown may be necessary to limit damage. Follow qualified technical guidance.”,”@type”:”Answer”}},{“name”:”How quickly should I notify my cyber insurance carrier?”,”@type”:”Question”,”acceptedAnswer”:{“text”:”As soon as possible under the policy’s reporting requirements. Many policies require prompt notice and may require approved vendors or specific procedures.”,”@type”:”Answer”}},{“name”:”Should employees use email during an attack?”,”@type”:”Question”,”acceptedAnswer”:{“text”:”Assume business email may be compromised until confirmed otherwise. Use phone calls, in-person communication, or another trusted channel.”,”@type”:”Answer”}},{“name”:”How often should we test our incident response plan?”,”@type”:”Question”,”acceptedAnswer”:{“text”:”At least twice per year, plus after major changes to staff, systems, vendors, insurance coverage, or business operations.”,”@type”:”Answer”}}]}

Back to Blog

Share:

Related Posts

image not found...!

Cybersecurity Risks Every Small Business Should Address Before 2026

Let’s be honest for a second. When you opened your business this…

Read More
CMIT Solutions Winchester VA team providing HIPAA IT compliance for Virginia medical practices

A Complete HIPAA IT Compliance Guide for Virginia Healthcare Providers

HIPAA IT compliance for Virginia medical practices means meeting the HIPAA Security…

Read More
how-do-deepfake-scams-slip-past-basic-cybersecurity-services

How Do Deepfake Scams Slip Past Basic Cybersecurity Services?

Deepfake scams slip past basic cybersecurity services because those tools scan email…

Read More