A suspected cyber attack creates pressure quickly. Employees may lose access, customers may ask questions and it may not yet be clear what has happened. The response is easier to manage when the business follows an agreed plan instead of making isolated decisions under pressure.
1. Raise the alarm and use the response plan
Tell the person responsible for managing the incident and contact the organisation that provides your IT or security support. Use a separate communication route if normal email or Microsoft 365 accounts may be affected.
Do not assume the first alert explains the full incident. Record when the issue was noticed, who reported it and which accounts, devices or services appear to be involved.
2. Contain the issue without destroying evidence
The immediate aim is to stop the attacker gaining further access. That may mean isolating an affected device, disabling a compromised account, ending active sign-in sessions or blocking a malicious message.
Avoid wiping devices, deleting messages or making broad changes without advice. Those actions can remove information needed to understand the incident and may make recovery harder.
3. Establish what is known
The response team needs to establish:
- which users, devices, mailboxes or systems are affected;
- whether business or personal information may have been accessed;
- whether the attacker still has access;
- what work can continue safely; and
- which decisions need senior approval.
Keep a written timeline of the facts, decisions and actions. It will help the technical investigation, internal communication and any later reporting.
4. Communicate carefully
Employees should receive clear instructions about what they should and should not do. Customers, suppliers, insurers or regulators may also need to be told, depending on the nature of the incident.
Do not speculate. Explain what is known, what action has been taken and when the next update will be provided. Legal, insurance and data-protection advice may be required before external statements are made.
5. Recover in a controlled order
Recovery is not just switching services back on. Accounts may need securing, devices may need checking and data may need restoring from a trusted backup. The order should be based on the business services that matter most and confidence that the attacker has been removed.
6. Learn from the incident
Once the immediate issue is under control, review how the attack happened, which controls worked and where the response became difficult. Turn those findings into named actions with owners and dates.
Continuous Microsoft 365 security monitoring can help suspicious activity reach a security specialist sooner, but every business still needs clear contacts and an incident plan.
Further reading
The National Cyber Security Centre provides current guidance for leaders responding to cyber incidents and reporting routes for UK organisations.


