DLC Tech Solutions - IT Support for Small Business
    Back to Blog

    What to Do in the First 24 Hours After a Cyber Incident

    The first 24 hours after a cyber incident decide whether it stays a bad day or becomes a business threatening crisis. Here is a practical, plain English guide.

    16 May 20269 min read

    Nobody wants to think about this. But the businesses that come out of a cyber incident in the best shape are almost always the ones that had a plan, even a rough one, before it happened.

    The first 24 hours matter enormously. The decisions made, and the mistakes made, in that window can determine whether a bad situation becomes a manageable problem or a business threatening crisis.

    This is a practical guide. Not a legal document, not a comprehensive incident response framework, just a clear account of what to do if you think something has gone wrong.

    Step 1: Don't Panic, But Do Act Fast

    The first instinct when something goes wrong is often to try to fix it quietly. Turn the laptop back on. Delete the suspicious email. Hope it resolves itself. Resist that instinct.

    Speed matters, but so does preserving evidence. Do not wipe machines, do not delete files, do not try to "clean up" anything before someone qualified has looked at it. You may need that evidence for your insurer, for regulators, or to understand exactly what happened.

    Step 2: Contain the Damage

    • Disconnect affected devices from the network. Unplug the network cable or disable the Wi-Fi.
    • If you are not sure which devices are affected, err on the side of caution.
    • Change passwords, starting with email and any accounts that might give access to financial systems. Do this from a device you are confident is not compromised.
    • If you use cloud services like Microsoft 365 or Google Workspace, check for unusual sign-in activity and revoke any active sessions you do not recognise.

    Step 3: Call Someone Who Can Help

    If you do not have an IT partner, now is the time to find one. If you do, call them immediately, not after you have spent three hours trying to sort it yourself.

    Incident response is a specialist skill. The right person can assess what has happened, help you contain it, and advise on next steps. They have done this before. You probably haven't.

    Step 4: Consider Your Reporting Obligations

    Under UK GDPR, if personal data has been accessed, lost, or stolen, you may have a legal obligation to report it to the ICO within 72 hours of becoming aware. This is not optional. If you are not sure whether your incident meets the threshold, get legal advice.

    Depending on your sector, there may be other reporting obligations to regulators, to clients, or to your cyber insurer. Your insurer in particular will want to be notified quickly. Some policies have strict notification windows.

    See our guide on breach reporting for staff for what your team should do at the point of discovery.

    Step 5: Communicate Carefully

    Who needs to know? Probably more people than you would initially want to tell, your insurer, potentially the ICO, possibly affected clients. But how you communicate matters.

    Do not rush out a panicked all staff email. Do not post on social media. Get advice on what to say, to whom, and when. Clumsy communication can make a bad situation significantly worse.

    After the Incident

    Once the immediate crisis is managed, the work of understanding what happened begins. How did they get in? What did they access? What needs to change?

    This is also when to document everything. What you noticed, when you noticed it, what you did, and who you spoke to. That record matters for insurance claims, regulatory investigations, and making sure the same thing does not happen again.

    The businesses that recover best treat the incident as a learning experience rather than something to bury. What changed? What was the gap? What would you do differently?

    The Best Time to Prepare Is Now

    If you are reading this without an active incident on your hands, use that luck. Write down (roughly) who you would call, what you would disconnect, where your backups are, and who your insurer is. That is not a full incident response plan, but it is infinitely better than nothing at 11pm when something has gone wrong.

    Want a second pair of eyes on your readiness? Get in touch for a no pressure conversation.

    Stay informed

    Get expert cyber security insights delivered to your inbox.

    Stay Updated

    Subscribe to receive the latest insights on cyber security, compliance, and data protection.