TL;DR: Disconnect affected devices from the network instead of powering them off. Call your IT provider and your insurer by phone, not email. Leave the ransom note and suspicious messages exactly where they are. If money was wired, call the bank immediately and report it to IC3 the same day. Then reset passwords from a clean device. The first hour decides how much of this you get back.
If you’re reading this because something is happening right now, start with the next section and come back to the rest later. Knowing what to do in a cyberattack matters most in the first hour, and this post runs in the order you’ll need it.
Here’s what trips people up. The instinct in the first ten minutes is to shut everything down and start emailing people about it. Both of those instincts make things worse. Powering off a machine destroys evidence sitting in memory. Emailing about the attack tells an intruder who’s still in your inbox that you’ve spotted them.
None of this requires technical skill. It requires doing things in the right order, and knowing which two or three moves are hard to undo.
What Should You Do First in a Cyberattack?
Disconnect the affected device from the network. Unplug the ethernet cable and turn off Wi-Fi. Then call your IT provider. Getting the machine off the network stops the spread, and leaving it powered on preserves evidence in memory that shows what happened and how far it reached.
If several machines or whole sections of your network look affected, CISA’s ransomware guidance is to take the network offline at the switch level rather than chasing individual devices.
Powering down is the last resort, not the first move. CISA is direct about the tradeoff: shut a device off only when you can’t get it off the network any other way, and understand that doing so wipes the artifacts stored in volatile memory that investigators use to reconstruct the attack.
If you don’t have someone to call, that’s the gap to close today rather than during an incident. Round-the-clock response is one of the things managed IT services in Louisville exist to provide.
Four Things Not to Do
These are the expensive mistakes, and all four happen in the first fifteen minutes.
- Don’t power everything off if you can isolate instead. You lose the record of what the attacker did.
- Don’t delete anything. The ransom note, the suspicious email, the odd alert in your dashboard. Screenshot them if you like, but leave the originals in place.
- Don’t discuss the attack on the compromised email system. This is the one people underestimate. CISA points out that attackers monitor a victim’s activity to see whether they’ve been noticed, and tipping them off can push them to move sideways through your network or deploy everywhere at once before you get systems offline. Switch to phone calls or a completely separate account.
- Don’t decide about a ransom in the first hour. That decision has inputs you don’t have yet.
The Step-by-Step Response
Work through these in order, starting the moment something looks wrong.
- Isolate the affected devices. Off the network, still powered on where possible.
- Call your IT provider by phone. Not email, not Teams, not Slack if any of those run through the compromised environment.
- Call your insurance carrier before you engage anyone else. Many cyber insurance policies route incident response through their own approved panel, and bringing in an outside firm first can affect how a claim gets handled. Check what your policy actually requires before you make that call.
- Preserve the evidence. No wiping, no reinstalling, no tidying up.
- If money moved, call the bank right now. This step jumps the queue. See the next section.
- Reset passwords from a clean device and confirm MFA is on. Start with email and administrator accounts. Use a machine you’re confident isn’t affected.
- Report it. Details below.
What If Money Was Already Wired?
Call your bank immediately and ask them to recall the transfer. Then file with the FBI’s Internet Crime Complaint Center the same day. The FBI’s Recovery Asset Team can trigger a freeze process with the receiving bank, but only if it hears about the transfer while the money is still sitting there. Hours matter far more than days.
One correction worth making, because it’s repeated a lot. You’ll see claims that the FBI recovers funds in roughly 70% of cases reported in time. That figure comes from an earlier reporting year. The 2025 IC3 report shows the Recovery Asset Team handled around 3,900 incidents involving $1.16 billion in attempted theft and froze $679 million, a success rate closer to 58%.
That’s still a coin flip worth taking, and the lower number makes the point better than the higher one did. Recovery isn’t automatic. It depends almost entirely on how fast the bank and the FBI find out.
On timing: the formal reporting window for the freeze process is 72 hours after the transfer. Investigators who work these cases tell victims to report within 48 hours, and same-day when possible. That gap isn’t bureaucratic caution. It’s roughly how long stolen money stays in one account.
Who Do You Report a Cyberattack To?
In the US, file a report with the FBI’s Internet Crime Complaint Center at ic3.gov and report to CISA. Tell your cyber insurance carrier. If personal information about customers or employees was exposed, notification obligations may apply, and that’s a question for your attorney rather than something to work out from a blog post.
That last part deserves a sentence more. Kentucky has a breach notification statute, KRS 365.732, and the Kentucky Consumer Data Protection Act took effect on January 1, 2026. Whether either applies to a given incident depends on facts this post can’t see, including what data was involved, whether it was encrypted, and which federal rules already cover your industry.
None of that is legal advice. The practical takeaway is that the call to a lawyer belongs early in the response, not after everything else is handled.
Should You Pay the Ransom?
The FBI and CISA don’t recommend it. Paying doesn’t guarantee you get your data back, it marks your business as one that pays, and the money funds the next attack. It’s still your decision, but it’s one to make with law enforcement, your incident response team, and your insurer, not alone in a panic.
A few facts that help frame it. Sophos research this year found 48% of organizations with encrypted data paid the ransom. It also found the average recovery cost, excluding any ransom, ran about $1.7 million and climbed 11% year over year. The ransom is usually not the biggest line item. Downtime is.
Worth checking before anyone pays anything: a free decryption tool may already exist for the specific ransomware strain that hit you. The No More Ransom project maintains a public library of them. Your incident response team will know to look. Someone acting alone at 2am probably won’t.
The One-Page Plan to Write Before You Need It
Everything above gets easier if a few decisions are already made. You don’t need a binder. One page covers it.
- Who to call, with phone numbers, stored somewhere you can reach without your main systems. A printed card in a drawer beats a contact list inside the email account that just got locked.
- Where your backups live, and proof someone has restored from them. Untested backups are a theory. Data backup and recovery only counts once you’ve watched a restore work.
- Which accounts and systems matter most, so nobody has to prioritize under pressure.
This is where smaller businesses lose ground. That same Sophos research found only 34% of small organizations stopped attacks before encryption or extortion, well behind larger companies. The difference isn’t usually better technology. It’s having decided things in advance. For businesses with nobody in a security leadership seat, a virtual Chief Security Officer is one way to get the plan written and kept current.
The Moves That Are Hard to Undo
Three things to hold onto. Isolate rather than shut down, because evidence in memory disappears the moment you power off. Get off the compromised email system before you say a word about the incident. And if money moved, treat it as a same-day problem, not a tomorrow problem.
Most of what determines the outcome happens before anyone technical arrives. That’s the part you control. If you want the upstream version of this story, our post on how these attacks usually start shows how little it costs an attacker to get in.
If you’re not sure who your business would call at 6am on a Saturday, that’s worth sorting out while nothing is on fire. Schedule an intro call and we’ll walk through what your response plan should cover.
Frequently Asked Questions
What’s the first thing to do in a cyberattack?
Disconnect the affected device from the network by unplugging the ethernet cable and turning off Wi-Fi, then call your IT provider by phone. Getting the machine off the network stops the problem spreading to other computers and to your backups while you wait for help.
Should I turn off the computer if I get ransomware?
If you can disconnect it from the network instead, do that. Powering a device down wipes evidence stored in memory that helps investigators work out what happened and how far the attacker got. CISA’s guidance is to power off only when you can’t get the device off the network any other way.
We wired money to a scammer. What do we do?
Call your bank immediately and ask them to recall the transfer and freeze it if they can. Then file with the FBI’s IC3 the same day. The FBI’s Recovery Asset Team can ask the receiving bank to freeze funds, and in 2025 it froze $679 million of the $1.16 billion in attempted theft it worked on. Speed is the main variable.
Who do I report a cyberattack to in the US?
File with the FBI’s Internet Crime Complaint Center at ic3.gov and report to CISA. Notify your cyber insurance carrier. If customer or employee personal information may have been exposed, talk to your attorney early about whether notification obligations apply to your situation.
Should we pay the ransom?
The FBI and CISA don’t recommend it, since paying doesn’t guarantee you get data back and it funds further attacks. If you’re weighing it, do that with law enforcement, your incident response team, and your insurer rather than alone. Check first whether a free decryption tool already exists for that ransomware strain.
Would You Know Who to Call?
Most businesses find out what their incident response plan was in the middle of an incident. A short conversation now is a much cheaper way to find out. Get in touch and we’ll help you build the one-page plan, test your backups, and make sure someone answers the phone when it matters.
