If a cyberattack hits your business, the first hour matters more than any other. It’s also the easiest moment to make an expensive mistake — powering off the wrong machine, deleting the evidence investigators need, or replying from an email account the attacker is already reading. The steps below tell you what to do, in order, so you’re not guessing under pressure. None of them require technical knowledge.
Before you touch anything, avoid these four:

Work through these in order, from the moment you notice something’s wrong:
In the US, report cybercrime to the FBI’s Internet Crime Complaint Center (IC3) and to CISA. If money was wired to a scammer, report it fast and ask IC3 about its Recovery Asset Team — speed is everything with fraudulent transfers.
There’s also a legal dimension for New York businesses. Under New York’s SHIELD Act, a breach exposing private information about New York residents requires you to notify the affected individuals and the state — and if you handle health records, HIPAA adds its own breach-notification duties on top. Miss a notification deadline and the fallout can outlast the attack itself — so loop in your lawyer or IT provider early so you don’t blow a deadline.
If it’s ransomware, that’s the big question. Law enforcement generally advises against it: paying doesn’t guarantee you get your files back, it marks you as a business that pays, and the money funds more attacks. It’s ultimately your decision — but one to make with law enforcement, your IT or incident-response team, and your insurer, not alone in the first panicked hour. Sometimes a free decryption tool already exists for the exact strain that hit you, which is one more reason to get experts involved before paying anyone.
All of this is far easier if you’ve decided some of it in advance. You don’t need a thick binder — just a one-page plan covering: who to call first (IT provider, insurer) and their numbers, kept somewhere reachable without your main systems; where your backups are, and proof they’ve been tested by actually restoring from them; and which accounts and devices matter most, so you know what to protect first. For most small businesses, a single page is enough — and it saves a lot of scrambling if the day ever comes.
Disconnect the affected devices from the network — unplug the cable, turn off Wi-Fi — then call your IT provider by phone. Getting the device off the network stops the spread while you get help.
If you can, disconnect it from the network instead. Shutting it down can wipe evidence stored in memory. Only power off if you can’t isolate it any other way.
Law enforcement advises against it — payment doesn’t guarantee recovery and funds more attacks. Make that call with police, your incident-response team, and your insurer, and check whether a free decryption tool already exists first.
Call your bank immediately and ask them to recall the transfer, then report it to the FBI’s IC3. The faster you act, the better the odds of clawing it back.
The FBI’s Internet Crime Complaint Center (IC3) and CISA. Also tell your cyber insurer, and check whether New York’s SHIELD Act or HIPAA require you to notify affected individuals and regulators if personal or health data was exposed.
Prepared by the EB Solution team — managed IT and cybersecurity for businesses across New York. Want a one-page incident plan built for your business before you need it? Let’s put one together.