top of page
Search

What to Do After a Cyberattack

When a cyberattack hits, panic is the enemy. You don't need a committee meeting, and you definitely don't need your IT team randomly rebooting servers in a panic. You need a rigid, practiced checklist. The mistakes made in the first 60 minutes of a ransomware event often cost more than the attack itself. If you suspect a breach, ransomware deployment, or unauthorized access, this is the sequence of events you need to follow.

Unplug network cables after a Cyberattack
Unplug, Don't Reboot after a Cyberattack

1. Disconnect, Do Not Reboot


The instinct is always to turn it off and back on again. Don't! Pull the network cables instead. Turn off the Wi-Fi. Isolate the infected machines, storage arrays, and virtualization hosts from the rest of the network and the internet. Rebooting destroys volatile forensic evidence stored in RAM. Worse, many ransomware variants are designed to execute their destructive payloads or delete volume shadow copies during the boot sequence because they expect you to reboot. For virtual servers, disconnect the network adapter in the hypervisor, which is the physical equivalent of yanking the network. Leave it powered on.


2. Call Your Breach Counsel (Lawyer)


Don't call your PR firm first. Call your breach counsel. You want the entire incident response and forensic investigation directed by legal counsel to establish attorney-client privilege. If you skip this step, the forensic report detailing exactly how your security failed will be fully discoverable when a client sues you for losing their data.


3. Notify Your Cyber Insurance Carrier


Your cyber insurance policy isn't just a payout. Start the process of contacting your insurer's pre-approved Incident Response (IR) firm. Experts such as digital forensic investigators, breach attorneys, and extortion negotiators are available to contain and recover from a cyberattack. Most policies feature a 24/7 hotline to activate these specialized services and mitigate financial or operational damage. Call the hotline. They will assign an IR team to your case. If you go rogue and hire your own forensics firm without the insurance carrier's prior written approval, you risk voiding your coverage.


4. Preserve Evidence (Stop the IT Guys from "Fixing" It)


Your internal IT team or Managed Service Provider will want to start "getting things back up" or restoring from backups immediately to get the business running. Stop them! You need the IR firm to figure out exactly how the attackers got in so you can close the door. If you restore servers from yesterday's backup without patching the vulnerability or finding the compromised account, you are just giving the attackers fresh, clean servers to encrypt again tomorrow.


5. Quarantine and Verify Backups


Ensure your backup repositories are completely offline and immutable. Do not connect them to the compromised network to check them. It is very possible the attackers have been in your network for weeks and they have already tried to find and corrupt your backups. You need the IR firm to verify the integrity of the backup sets in a sterile environment before you even think about hitting the restore button. Ideally, you have been testing restores as part of your Disaster Recovery Plan.


6. Execute Password Resets

Eventually, you will need to force a global password reset for all administrative and user accounts. The attacker may have installed a keylogger, so resetting passwords from a compromised machine is useless since they will be able to capture the new passwords. Resets must happen from a verified clean, isolated device that has never touched the compromised network. The IR team can help with this.


7. Communicate Carefully


You won't be just losing money in this attack. Your customer's trust and company image are at stake. Do not lie to your staff or your clients, but absolutely do not speculate. Use approved holding statements vetted by your breach counsel. Control the narrative by sticking strictly to verified facts.

Say something like: "We are experiencing a network disruption and are investigating the root cause with outside security experts".

Inform all employees and vendors that if they are asked by anyone if they know what is going on, that they should not say anything and direct the inquiry to the appropriate PR person.


Final Thoughts

A disaster recovery plan is a practiced, methodical response designed to limit damage and legal liability. 255 IT Consulting helps businesses build real incident response and disaster recovery plans long before the fire starts, so when the worst happens, you know exactly what to do.


 
 
bottom of page