Skip to main content

How should a business react in the event of a cyber attack?

The first decisions after a cyber attack matter. A clear response helps a business contain the issue, protect evidence and recover with less confusion.

A suspected cyber attack creates pressure quickly. Employees may lose access, customers may ask questions and it may not yet be clear what has happened. The response is easier to manage when the business follows an agreed plan instead of making isolated decisions under pressure.

1. Raise the alarm and use the response plan

Tell the person responsible for managing the incident and contact the organisation that provides your IT or security support. Use a separate communication route if normal email or Microsoft 365 accounts may be affected.

Do not assume the first alert explains the full incident. Record when the issue was noticed, who reported it and which accounts, devices or services appear to be involved.

2. Contain the issue without destroying evidence

The immediate aim is to stop the attacker gaining further access. That may mean isolating an affected device, disabling a compromised account, ending active sign-in sessions or blocking a malicious message.

Avoid wiping devices, deleting messages or making broad changes without advice. Those actions can remove information needed to understand the incident and may make recovery harder.

3. Establish what is known

The response team needs to establish:

  • which users, devices, mailboxes or systems are affected;
  • whether business or personal information may have been accessed;
  • whether the attacker still has access;
  • what work can continue safely; and
  • which decisions need senior approval.

Keep a written timeline of the facts, decisions and actions. It will help the technical investigation, internal communication and any later reporting.

4. Communicate carefully

Employees should receive clear instructions about what they should and should not do. Customers, suppliers, insurers or regulators may also need to be told, depending on the nature of the incident.

Do not speculate. Explain what is known, what action has been taken and when the next update will be provided. Legal, insurance and data-protection advice may be required before external statements are made.

5. Recover in a controlled order

Recovery is not just switching services back on. Accounts may need securing, devices may need checking and data may need restoring from a trusted backup. The order should be based on the business services that matter most and confidence that the attacker has been removed.

6. Learn from the incident

Once the immediate issue is under control, review how the attack happened, which controls worked and where the response became difficult. Turn those findings into named actions with owners and dates.

Continuous Microsoft 365 security monitoring can help suspicious activity reach a security specialist sooner, but every business still needs clear contacts and an incident plan.

Further reading

The National Cyber Security Centre provides current guidance for leaders responding to cyber incidents and reporting routes for UK organisations.

Continue reading

Talk it through

Have a question about what this means for your business?

Tell us what you have in place or what you're trying to decide. We'll explain where we can help and make the next step clear.