RUEN
Home/Materials/Cyberattack response
Cybersecurity and continuity

What to do in the first hours after a cyberattack: action plan

The first hours after an attack decide whether you lose a day or a week. We break down a step-by-step response plan and what to prepare in advance so the team does not waste time.

Updated: June 28, 2026 · Author: Evgeny Telenkov · ≈ 7 min read

The first hours: step by step

  1. Isolate. Disconnect infected systems from the network to stop the spread. Do not shut machines down blindly — it can destroy evidence.
  2. Assemble the response team. Pre-assigned roles: who leads, who handles IT, who handles communications.
  3. Assess the scope. What is affected, which processes are down, whether there is a data breach.
  4. Activate the continuity plan. Switch critical processes to backup options (see BCP).
  5. Communications. Agreed messages for customers, partners and staff; notify the regulator if required.
  6. Recovery. Bring systems back from isolated backups by priority (see DRP).
  7. Post-incident review. Causes, lessons, fixes — so it does not happen again.
What not to do: do not pay extortionists on emotion (no guarantees, it encourages attacks), do not "sweep" the incident under the rug without root-cause analysis, and do not stay silent where notification is mandatory. Why concealment is costly — in "Why companies hide cyberattacks".

What to prepare in advance

  • Response team roles and contacts (on paper / in a messenger, available offline).
  • Isolated backups and a tested recovery procedure.
  • Communication templates for customers and partners.
  • A ransomware-scenario drill.

FAQ

What is the very first thing to do in an attack?

Isolate infected systems from the network to stop the spread, and assemble the pre-assigned response team. Do not shut machines down blindly — you can destroy evidence.

Should you pay extortionists for decryption?

Usually no: payment does not guarantee recovery and encourages new attacks. Rely on isolated backups and a recovery plan.

Do you have to report an attack?

For certain organisations and data, notifying the regulator is required by law. Even when silence is formally allowed, root-cause analysis matters more than concealment.

Is your team ready for the first hour of a crisis

Plans are tested by scenarios, not by reading. The assessment shows the gaps, the corporate format works them through with your team on your processes.

Evgeny Telenkov
Evgeny Telenkov
Director, business continuity practice · PhD in Economics · Academic Director & Chief Examiner
Risk Manager of the Year in Russia 2020 (RusRisk). Built business continuity from scratch at Nornickel, more than 20 plans; led risk functions at Beeline, Rosneft and EY. Chief risk officer of a 20 billion dollar petrochemical megaproject. Deputy chair of Rosstandart technical committee 010 "Risk management", co-author of six national standards. Author of the ERGP and SAFE programmes.