Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If a cyberattack interrupts your business, activate your incident-response plan, contain affected systems, protect essential services, and coordinate communications. Then preserve evidence, investigate the scope, and restore clean systems in order of business priority. Do not reconnect compromised devices just to get operations moving again.

What to do first when an attack disrupts operations

Use your organization’s approved incident-response plan and involve its incident lead or qualified IT and security support. The #StopRansomware Guide, a multi-agency resource revised October 19, 2023, provides guidance focused on ransomware and data extortion. Other kinds of attacks may require adapted technical, legal, and regulatory responses.

  1. Activate the response plan. Alert the designated incident lead and follow the plan’s escalation and decision-making procedures.
  2. Contain affected systems. Identify systems that appear compromised and isolate them from wired or wireless networks as appropriate. If multiple systems or subnets may be affected, CISA says network-level isolation, such as taking the network offline at the switch level, may be appropriate. Coordinate technical actions through your incident lead or qualified support rather than improvising broad shutdowns.
  3. Protect critical services and people. Identify the business functions affected and any immediate health, safety, customer, or operational risks. Keep leaders responsible for those functions informed.
  4. Coordinate communications and reporting. Use the incident and communications plans to notify the appropriate internal teams, providers, insurers, and other stakeholders. Follow applicable reporting and notification requirements.
  5. Preserve evidence and establish scope. Secure relevant logs and other available artifacts, and investigate whether more systems or earlier activity are involved.
  6. Restore clean systems in priority order. Use offline, encrypted backups and the organization’s critical-service priorities. Keep compromised systems from contaminating clean recovery environments.
  7. Review and update. Record lessons from the incident and revise plans, procedures, and exercises.

Keep a record of systems that appear unaffected; that helps responders avoid spending recovery effort on them while more critical services need attention.

How to contain the attack without making recovery harder

Containment limits further disruption, but the right action depends on the incident and your network. Work from the approved response plan and coordinate with the incident lead, internal IT and security staff, or a qualified provider. Isolate affected devices when appropriate; if the incident appears to span multiple systems or subnets, responders may need to consider isolation at the network level.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

Do not assume that restoring access is the same as containing the threat. A system should not be returned to service until responders have a reason to consider it safe. Keep a clear record of what was isolated, what appears unaffected, and the decisions made during response.

Which systems should you restore first?

Restore according to business impact and dependencies, not convenience or visibility. Use a critical-asset list or business-impact analysis to understand which systems support essential functions, and what those systems rely on. CISA’s guidance for corporate leaders and CEOs recommends identifying systems that support critical functions and testing continuity plans.

Priority question How to use it
Could an outage affect health or safety? Identify services where disruption could create immediate risk to people.
Does the system support revenue or another essential service? Assess how its unavailability affects customers, income, or core operations.
What does the system depend on? Map dependencies so a service is not restored before the infrastructure or systems it needs.
Is the system confirmed clean and safe to reconnect? Do not reconnect a compromised system merely because it is high priority; recovery must not reintroduce the threat.

The order among your organization’s systems depends on its services and dependencies. CISA recommends prioritizing critical assets and restoring safely; your own continuity planning must establish the specific sequence.

Who to involve and what to communicate

Keep senior leadership informed through the plan’s established channels. CISA’s corporate-leader guidance says: “Cyber incident response plans should include not only your security and IT teams, but also senior business leadership and Board members.” Relevant participants may include internal IT, managed or security service providers, cyber insurers, department leaders, legal advisers, and communications staff.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For U.S. organizations, CISA recommends considering a report or request for assistance from CISA, a local FBI field office, FBI IC3, or the U.S. Secret Service, as applicable. The CISA StopRansomware Services page lists no-cost resources and tools. Select contacts according to the incident, your plan, and the service needed.

Share confirmed facts, distinguish what is known from what is still being investigated, and avoid unsupported claims about the attack’s scope or attribution. Notification obligations depend on the data involved, sector, contracts, and applicable law. Follow your plan and obtain appropriate legal advice; U.S. government guidance does not settle requirements for every jurisdiction or organization.

How to preserve evidence and assess the scope

Investigation helps responders determine what was affected, whether the attacker may still have access, and what can be restored safely. Review available detection systems and logs for signs of additional affected systems or earlier compromise. Preserve relevant logs and other artifacts, and consult qualified responders and law enforcement as appropriate.

Some evidence is short-lived: system memory and logs with limited retention can disappear. CISA recommends considering a system image and memory capture of a sample of affected devices if no initial mitigation action appears possible; collect relevant logs and malware samples where available. Coordinate evidence collection with responders so it supports both containment and recovery.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to restore operations safely

Use offline, encrypted backups to restore data and systems according to critical-service priorities. Keep compromised devices and networks separate from clean recovery environments so they do not reintroduce the threat. Confirm that systems are safe to reconnect before returning them to service, and coordinate restoration with the people responsible for incident response and business continuity.

Rank #4
SafeBiz - Wireless Cybersecurity Solution, Next-Gen Firewall, Web Filtering, Phishing/Ransomware/Malicious Website Protection - Wifi6E, 4.3 Gbps, 3000 Sq.Ft Coverage
  • BUSINESS CYBERSECURITY SOLUTION: SafeBiz is an advanced cybersecurity solution that protects your work network and safeguards your Business data and all internet connected devices in your business from cyber threats and hackers. SafeHome blocks phishing, malware, ransomware, online scams and dark web threats.
  • ADVANCED THREAT PREVENTION: SafeBiz includes a Next-Gen Firewall, DNS Security, Web Filtering, Dark Web Protection, Geo-fencing and other AI Powered cybersecurity features protecting your Business and Sensitive Data from internet threats and hackers.
  • BUSINESS DATA & IDENTITY SECURITY: Safeguards your Official and financial data, protecting them from online theft and unauthorized access.
  • EASY SETUP: Connects effortlessly to any existing wireless router or internet connection, setting up in minutes without the need for any changes to your Business internet connection.
  • HIGH SPEED CONNECTIVITY: Supports an aggregate throughput of up-to 4.3 Gbps, maintaining high-speed browsing and streaming performance for up to 128 devices.

An encrypted external drive can be one way to keep a backup offline, but a drive alone does not guarantee recovery. Maintain a sound backup process and test that backups can be used. CISA’s ransomware guidance recommends offline, encrypted backups.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to prepare before another disruption

Plan continuity before an incident, rather than deciding priorities during one. CISA recommends maintaining and exercising incident-response and communications plans, including response and notification procedures, and keeping hard-copy and offline versions available. Plans should clearly assign decision-making and response responsibilities across the chain of command.

  • Identify critical business functions, the systems that support them, and their dependencies.
  • Assign responsibilities across technology, leadership, communications, legal, and business continuity.
  • Connect cyber incident procedures to business contingency and disaster-recovery plans.
  • Run exercises that test roles, communications, and continuity arrangements.
  • Protect and retain logs according to organizational policies and compliance needs.
  • Review plans after exercises and real incidents, then update procedures accordingly.

CISA’s Cyber Essentials Toolkit 6 (November 17, 2020) advises planning and drilling for cyberattacks as for other emergencies. It distinguishes incident response, which focuses on protecting information assets, from disaster recovery, which focuses on business continuity. Both perspectives matter when an attack disrupts operations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Small organizations can consult CISA’s Small and Medium-Sized Business Resources hub for planning and service resources. If you lack in-house response capacity, evaluate outside help based on availability, technical capability, evidence handling, coordination with existing insurance and legal processes, and cost; no particular provider is endorsed here.

After the incident

Document what happened, how decisions were made, which services were restored, and what impeded recovery. Use those lessons to update policies, response and communications plans, continuity procedures, and future exercises. CISA’s Use Logging on Business Systems guidance also addresses response-team responsibilities and log security and retention.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.