If a cyberattack hits your business, the first hour matters more than any other. It’s also the easiest moment to make an expensive mistake — powering off the wrong machine, deleting the evidence investigators need, or replying from an email account the attacker is already reading. The steps below tell you what to do, in order, so you’re not guessing under pressure. None of them require technical knowledge.

First rule: don’t make it worse

Before you touch anything, avoid these four:

  • Don’t power the affected computer off if you can avoid it. Disconnecting it from the network is better — shutting it down can wipe evidence that helps work out what happened.
  • Don’t delete anything. Leave the ransom note, the suspicious email, and any alerts exactly where they are. That’s what your IT team and investigators will need.
  • Don’t pay a ransom on the spot.
  • Don’t use the compromised email or accounts to discuss the attack. If an attacker is in your inbox, they can read those messages. Switch to phone calls or a clean account.
Cyberattack response for a New York small business

The step-by-step

Work through these in order, from the moment you notice something’s wrong:

  1. Disconnect the affected devices from the network. Unplug the network cable and turn off Wi-Fi on anything that looks affected. This stops the problem spreading to other computers and to your backups. CISA’s guidance is to isolate devices rather than power them off where you can — and only shut a device down if you can’t get it off the network any other way.
  2. Call your IT provider immediately — by phone. Don’t email, in case the attacker is watching your inbox. If you have cyber insurance, call them next; many policies require you to involve their incident team early.
  3. Leave the evidence alone. Don’t wipe, reinstall, or tidy up the affected machines yet. Screenshots of the ransom note or suspicious emails are useful, but keep the originals too.
  4. If money was sent, call your bank immediately. Ask them to recall and freeze the transfer if they can. With wire and bank fraud, acting in the first few hours makes the biggest difference.
  5. Reset passwords from a clean device and turn on MFA. Start with email and any admin accounts, using a device you know isn’t affected.
  6. Report it. It can help you recover, and it’s sometimes legally required.

Where to report it — and the New York legal angle

In the US, report cybercrime to the FBI’s Internet Crime Complaint Center (IC3) and to CISA. If money was wired to a scammer, report it fast and ask IC3 about its Recovery Asset Team — speed is everything with fraudulent transfers.

There’s also a legal dimension for New York businesses. Under New York’s SHIELD Act, a breach exposing private information about New York residents requires you to notify the affected individuals and the state — and if you handle health records, HIPAA adds its own breach-notification duties on top. Miss a notification deadline and the fallout can outlast the attack itself — so loop in your lawyer or IT provider early so you don’t blow a deadline.

Should you pay the ransom?

If it’s ransomware, that’s the big question. Law enforcement generally advises against it: paying doesn’t guarantee you get your files back, it marks you as a business that pays, and the money funds more attacks. It’s ultimately your decision — but one to make with law enforcement, your IT or incident-response team, and your insurer, not alone in the first panicked hour. Sometimes a free decryption tool already exists for the exact strain that hit you, which is one more reason to get experts involved before paying anyone.

The best time to prepare is before it happens

All of this is far easier if you’ve decided some of it in advance. You don’t need a thick binder — just a one-page plan covering: who to call first (IT provider, insurer) and their numbers, kept somewhere reachable without your main systems; where your backups are, and proof they’ve been tested by actually restoring from them; and which accounts and devices matter most, so you know what to protect first. For most small businesses, a single page is enough — and it saves a lot of scrambling if the day ever comes.

Frequently asked questions

What’s the first thing to do in a cyberattack?

Disconnect the affected devices from the network — unplug the cable, turn off Wi-Fi — then call your IT provider by phone. Getting the device off the network stops the spread while you get help.

Should I turn off the computer if I get ransomware?

If you can, disconnect it from the network instead. Shutting it down can wipe evidence stored in memory. Only power off if you can’t isolate it any other way.

Should I pay the ransom?

Law enforcement advises against it — payment doesn’t guarantee recovery and funds more attacks. Make that call with police, your incident-response team, and your insurer, and check whether a free decryption tool already exists first.

We wired money to a scammer. What do we do?

Call your bank immediately and ask them to recall the transfer, then report it to the FBI’s IC3. The faster you act, the better the odds of clawing it back.

Who do I report a cyberattack to in the US?

The FBI’s Internet Crime Complaint Center (IC3) and CISA. Also tell your cyber insurer, and check whether New York’s SHIELD Act or HIPAA require you to notify affected individuals and regulators if personal or health data was exposed.

Prepared by the EB Solution team — managed IT and cybersecurity for businesses across New York. Want a one-page incident plan built for your business before you need it? Let’s put one together.

Watch Our Latest Tech Videos From EB Solution

Call Now