# What to do after a cyber attack.

> What to do in the first hour after a cyber attack or data breach: contain, preserve evidence, reset access, notify the right people and recover safely.

Canonical: https://cybersecuritylondon.com/what-to-do-after-a-cyber-attack


By Cyber Security London, published 8 October 2026.

**In short:** After a cyber attack, act quickly but calmly. Disconnect affected devices from the network without switching them off, change passwords from a clean device, write down what you've seen and when, and get expert help. If personal data may be affected, you may need to report it to the ICO within 72 hours.

## What should you do in the first hour?

1. **Contain:** disconnect affected devices from the network and Wi-Fi. Don't switch them off, as that can destroy evidence.
2. **Secure accounts:** from a clean device, change passwords for email, admin and finance accounts, and check multi-factor authentication is on.
3. **Record:** note what happened, when, which systems are affected and who has been told.
4. **Get help:** contact your incident response provider or IT partner. If you have cyber insurance, call your insurer's incident line early, as many policies require it.
5. **Don't pay or negotiate** with attackers before taking expert advice.

## Who do you need to tell?

| Who | When |
| --- | --- |
| Your incident response provider or IT partner | Immediately |
| Your cyber insurer | As early as possible; check your policy |
| The ICO | Within 72 hours of becoming aware of a personal data breach that poses a risk to people |
| Affected individuals | Without undue delay, if the breach is likely to pose a high risk to them |
| Clients and partners | As required by your contracts |

## How common are cyber attacks on UK businesses?

Very. The government's Cyber Security Breaches Survey 2025 found that 43% of UK businesses identified a cyber breach or attack in the previous 12 months, rising to 67% of medium and 74% of large businesses. Phishing was the most common type, experienced by 85% of the businesses that reported a breach or attack.

The same survey found that 53% of medium businesses and 75% of large businesses have a formal incident response plan, so many organisations are still working it out on the day.

## How do you recover safely?

- Find and close the way the attacker got in before restoring anything.
- Restore from backups you have confirmed are clean.
- Monitor closely for signs the attacker is still present.
- Hold a review afterwards and update your incident response plan.

## Frequently asked questions

### Should I switch off a computer that has been hacked?

No. Disconnect it from the network instead. Switching it off can destroy evidence that helps work out what happened.

### Do I have to report a cyber attack to the ICO?

If personal data is involved and the breach poses a risk to people's rights and freedoms, UK GDPR requires you to report it to the ICO within 72 hours of becoming aware of it.

### Should we pay a ransomware demand?

Take expert advice before doing anything. Paying doesn't guarantee recovery of your data and may encourage further attacks.

## Sources

- [Cyber Security Breaches Survey 2025, Department for Science, Innovation and Technology](https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2025/cyber-security-breaches-survey-2025)
- [Personal data breaches, Information Commissioner's Office](https://ico.org.uk/for-organisations/report-a-breach/)
- [Incident management, National Cyber Security Centre](https://www.ncsc.gov.uk/collection/incident-management)

## How we can help

- [Incident Response](https://cybersecuritylondon.com/incident-response)
- [24/7 Monitoring (SOC)](https://cybersecuritylondon.com/managed-soc-monitoring)

## Contact

Email enquiry@cybersecuritylondon.com or use the enquiry form at https://cybersecuritylondon.com/#contact. Cyber Security London, The Leather Market, London Bridge, London.
