
What Every Small Business Should Do After a Cyberattack: A Step-by-Step Guide
For a small business, a cyberattack can be overwhelming. Whether it's ransomware, a phishing scam, a compromised email account, or a data breach, the actions you take in the first hour can significantly impact how much damage is done.
The good news is that you don't need to be a cybersecurity expert to take the right first steps. Having a simple response plan can help your small business contain the threat, protect sensitive data, and recover more quickly.
First Things First: Don't Make the Situation Worse
When a cyberattack is detected, your first instinct may be to start clicking, deleting, or shutting things down. Resist that urge.
If your small business experiences a cyberattack, avoid these common mistakes:
- Don't turn off affected computers unless absolutely necessary. Disconnecting them from the network is often a better first step.
- Don't delete suspicious emails, ransom notes, or warning messages. They may contain evidence your IT provider needs.
- Don't immediately pay a ransom demand. There may be other recovery options available.
- Don't discuss the incident through potentially compromised email accounts. Use phone calls or another trusted communication method.
Step-by-Step: How Small Businesses Should Respond to a Cyberattack
Step 1: Isolate Affected Devices Immediately
If a computer or server appears compromised:
- Disconnect the network cable.
- Turn off Wi-Fi access.
- Remove the device from the network.
For a small business, isolating infected devices quickly can help prevent malware or ransomware from spreading to other computers, servers, and backups.
Step 2: Call Your IT Provider
If your small business works with a managed IT provider or cybersecurity partner, call them immediately.
Avoid using email if there's any chance your mailbox has been compromised.
If your small business has cyber liability insurance, contact your insurer as soon as possible. Many policies require prompt notification and may provide access to cybersecurity specialists.
Step 3: Preserve Evidence
Do not:
- Reinstall Windows
- Delete files
- Erase logs
- Wipe hard drives
Take screenshots if needed, but leave the original evidence intact. Your IT provider may need this information to determine how the attack occurred and what systems were affected.
Step 4: Contact Your Bank if Money Was Involved
If your small business:
- Sent a wire transfer to a scammer
- Paid a fraudulent invoice
- Discovered unauthorized transactions
Contact your bank immediately.
The faster your bank is notified, the better the chance of stopping or recovering the funds.
Step 5: Change Critical Passwords
Using a clean, unaffected device:
- Change email passwords
- Reset administrator credentials
- Update financial account passwords
- Enable Multi-Factor Authentication (MFA)
For a small business, securing email accounts should be a top priority because compromised email is often used to launch additional attacks.
Step 6: Report the Incident
Depending on where your small business operates, you may need to report the attack to the appropriate authorities.
In the United States, this may include:
- The FBI Internet Crime Complaint Center (IC3)
- CISA (Cybersecurity & Infrastructure Security Agency)
You may also have legal notification obligations if customer or employee data was exposed.
Should Your Small Business Pay the Ransom?
This is one of the most difficult questions business owners face after a ransomware attack.
In many cases, paying the ransom does not guarantee:
- Your files will be recovered
- Systems will be restored
- Data won't be leaked
Additionally, paying encourages future criminal activity.
A small business should consult with:
- Its IT provider
- Cyber insurance company
- Legal counsel
- Law enforcement
before making any decision regarding ransom payments.
How Small Businesses Can Prepare Before an Attack Happens
The best time to prepare for a cyberattack is before one occurs.
Every small business should have a simple cyber incident response plan that includes:
Emergency Contact Information
Maintain an offline list containing important phone numbers for:
- Your IT provider
- Cyber insurance company
- Key vendors
- Banking institutions
Reliable Backups
Ensure your critical business data is backed up regularly and tested. A backup is only valuable if it can actually be restored when needed.
Critical System Inventory
Document:
- Key computers and servers
- Microsoft 365 accounts
- Financial systems
- Customer databases
- Business applications
Knowing what is most important helps your small business prioritize recovery efforts.
Why Small Businesses Need a Cyberattack Response Plan
Many small business owners assume cybercriminals only target large corporations. Unfortunately, the opposite is often true.
Small businesses are frequently targeted because attackers believe they have:
- Fewer security controls
- Smaller IT teams
- Limited cybersecurity resources
Having a simple response plan can dramatically reduce downtime, financial losses, and business disruption when an incident occurs.
Protect Your Small Business Before It's Too Late
A cyberattack can happen to any small business, regardless of size or industry. The key is being prepared and knowing exactly what to do when every minute counts.
By acting quickly, preserving evidence, involving your IT provider, and following a clear response plan, your small business can minimize damage and recover faster.
If you'd like help creating a cyber incident response plan, strengthening your cybersecurity defenses, or ensuring your backups are ready when you need them most, contact us today. We're here to help keep your small business protected before, during, and after a cyberattack.
About the author
Don is a technically sophisticated and business-savvy professional with a career reflecting strong leadership qualifications coupled with a vision dedicated to the success of small businesses. His skills include the deployment of IT technologies including custom desktops, small networks, and hardware/software solutions all with a focus on the management of security and efficiency to promote growth.
After graduation from the University of Missouri-Columbia, Don spent over 20 years developing and honing his management skills in the small business community in and around the Columbia area.
Coupled with the passion and skills in IT technology, he looks to assist businesses to become highly productive and more profitable with the right IT solutions.