If your business is ever hit, the first hour decides a lot. It is also the easiest hour in which to make things worse: switching off the wrong machine, deleting the evidence, or emailing about the attack from the very inbox the attacker is sitting in. This is the plan for that hour, written so that nobody needs technical knowledge to follow it.
First, the things not to do
Do not power the affected computer off if you can avoid it. Pulling it off the network is better, because shutting it down can wipe evidence in memory that later explains what happened. Do not delete anything: the ransom note, the suspicious email and the alerts are exactly what investigators need, left where they are. Do not pay a ransom in the heat of the moment. And do not discuss the attack from the hacked account. If someone is in your inbox, they are reading your response plans as you type them.
Then, in order
- Get the affected devices off the network. Unplug the network cable and switch off WiFi on anything that looks compromised. This stops the spread to other machines and, importantly, to your backups.
- Phone your IT provider. Phone, not email. If you have cyber insurance, ring them next, because many policies require their incident team to be involved early.
- Leave the evidence alone. No wiping, no reinstalling, no tidying up yet. Screenshots are useful, but keep the originals.
- If money moved, phone your bank immediately. Ask them to recall and freeze the transfer. With payment fraud, the first few hours are worth more than the following week.
- Reset passwords from a clean device. Start with email and anything with admin rights, on a machine you know is unaffected, and switch multi-factor authentication on where it is missing.
- Report it. Open a case with SAPS, because your insurer will want the case number. If personal information about clients or staff was exposed, POPIA requires you to notify the Information Regulator and the people affected as soon as reasonably possible, so get your IT provider or lawyer onto that early rather than late.
The ransom question
If it is ransomware, someone will ask whether you should just pay. Law enforcement agencies around the world advise against it, for practical reasons: payment does not guarantee your files back, it marks you as a business that pays, and it funds the next round of attacks. It is also sometimes unnecessary, because free decryption tools already exist for many ransomware strains. Make that decision with your IT people and your insurer at the table, not alone in the first panicked hour.
The page you write before you need it
All of this is far easier if the decisions were made in advance. You do not need a thick binder. One page covers it for most small businesses: who to phone first and their numbers, kept somewhere reachable when your systems are not; where the backups live, with proof someone has actually restored from them; and which accounts and machines matter most, so you know what to protect first.
Writing that one-pager is part of onboarding on our support plans, along with tested backups and someone to phone who already knows your setup. The worst time to exchange introductions is during the incident.