We use cookies

    We use cookies to enhance your browsing experience, analyse site traffic, and personalise content. By clicking "Accept", you consent to our use of cookies. Learn more

    Hacked? What to Do in the First 24 Hours: A Step-by-Step Guide for UK Businesses
    Back to Blog
    Cybersecurity09 Aug 2026

    Hacked? What to Do in the First 24 Hours: A Step-by-Step Guide for UK Businesses

    9 min read
    Share:

    Nobody plans to read this article. You are here because something has happened: a ransom note on a screen, a supplier asking why your email address just sent them a strange invoice, a login alert from a country nobody works in. The government's latest Cyber Security Breaches Survey found that around 4 in 10 UK businesses identified an attack or breach in the past year, so you are not unusual and you are not the first. What matters now is the order you do things in. The first 24 hours decide whether this is a bad day or a bad quarter.

    The short version

    • Disconnect the affected machine from the network. Do not turn it off.
    • Change passwords and revoke sessions from a clean device, starting with email and admin accounts.
    • Do not pay a ransom and do not delete anything.
    • Check whether personal data is involved. If it is, you have 72 hours to report it to the ICO. That clock is already running.
    • Get help before you start rebuilding. Recovery done in the wrong order destroys the evidence and often re-infects the network.

    Now the same steps in detail, in the order we actually work through them when a client calls us with a live incident.

    Hour zero: contain it without destroying evidence

    Disconnect, do not power off

    Unplug the network cable or turn off the Wi-Fi on any machine you believe is compromised. That stops the attacker moving sideways to other machines and stops data leaving. But leave the machine powered on. Switching it off wipes the memory, and memory is where much of the evidence of what actually happened lives. The one exception: if you can see files being encrypted in front of you, right now, one by one, pull the power. A half-finished encryption run is recoverable more often than a finished one.

    Write down times

    Note what you saw and when, in plain words: "10:14, Sarah noticed the shared drive files had .locked extensions." This feels pointless in the moment. It is the single most useful thing you can hand to whoever investigates, and the ICO will ask for a timeline if personal data is involved.

    Do not wipe, reinstall, or run cleanup tools yet

    The instinct is to make it go away. Resist it. Wiping a machine before anyone has established how the attacker got in means you rebuild with the same open door, and roughly the same result a few weeks later.

    Hour one: lock the doors they came through

    Reset passwords from a clean device

    Use a machine you trust, not the affected one. Start with the accounts that control everything else: Microsoft 365 or Google Workspace admin accounts, then email accounts, then anything financial. If the attacker is watching the compromised machine, changing passwords from it just hands them the new ones.

    Revoke active sessions, not just passwords

    A password change does not log an attacker out of sessions they already have. In Microsoft 365, use "Sign out of all sessions" on the affected accounts. This is the step most people miss, and it is why "we changed all the passwords" is so often followed by "but they are still in."

    Check email rules and forwarding

    The most common small business attack we see is a compromised mailbox. Attackers quietly add inbox rules that forward invoices to themselves or hide replies from real suppliers. Check every affected mailbox for rules and forwarding addresses that nobody recognises, and screenshot them before deleting.

    Need Reliable IT Support for Your Business?

    Our managed IT support services keep your systems secure, monitored, and running efficiently.

    Turn on multi-factor authentication anywhere it is missing

    If MFA was not on the breached account, turn it on now, everywhere. It is the single control that would have prevented most of the incidents we get called into.

    Hours two to twelve: work out what you are dealing with

    Establish the blast radius

    Which accounts, which machines, which data? Be suspicious by default: if a compromised account had access to a folder, assume the folder was read. You are trying to answer two questions: what could they have taken, and is any of it personal data?

    If it is ransomware, do not pay

    The National Cyber Security Centre's guidance is clear, and ours is the same. Payment funds the next attack, offers no guarantee of getting your data back, and marks you as a business that pays. Your recovery route is backups, not the attacker's decryption tool. If your backups turn out to be encrypted too, or last ran months ago, that is exactly the conversation to have with a professional before touching anything else.

    Call your bank and your insurer early

    If money moved or payment details were exposed, call your bank immediately. Banks can sometimes recall payments in the first hours, and almost never after a few days. If you hold cyber insurance, call the insurer's incident line before authorising recovery work. Many policies require it, and some will only pay for approved responders.

    This is the part UK businesses most often get wrong, because it runs on a deadline whether you are ready or not.

    • ICO, within 72 hours. If personal data was, or probably was, exposed and there is a risk to the people involved, UK GDPR requires you to report the breach to the Information Commissioner's Office within 72 hours of becoming aware of it. The 72 hours includes the weekend. You can report with partial information and follow up, and that is far better than a late, complete report.
    • Action Fraud. Report the crime to Action Fraud on 0300 123 2040 or online. You get a crime reference number, which your bank and insurer will both want.
    • The people affected. If the breach puts individuals at high risk, for example exposed passwords or financial details, you must tell them directly, without undue delay.

    Not every incident is reportable. A ransomware attack that encrypted data but demonstrably took none may not need individual notifications. But you need to be able to show your reasoning, which is why the timeline you started at hour zero matters.

    Day one onwards: recover in the right order

    • Find the way in first. A phished password, an unpatched server, a remote access tool nobody knew was installed. Rebuilding before you know is how businesses get hit twice by the same door.
    • Restore from backups onto clean machines, and verify the backups themselves were not reachable from the compromised network. Backups a compromised admin account could delete are not backups, they are a copy the attacker controls.
    • Rotate every credential the attacker could have seen, not just the obviously breached ones. That includes saved browser passwords on affected machines.
    • Watch closely for two to four weeks. Attackers who lose access often try the same trick again while the incident is fresh, betting that everyone is tired.

    What the aftermath should change

    Once you are stable, the honest question is why this worked. The pattern behind most UK small business breaches is boring: a password without MFA, a machine missing updates, no monitoring so the attacker had days instead of minutes. The fixes are equally boring, which is good news, because boring is cheap. MFA everywhere, patching that actually happens, backups that are tested and out of reach, and someone watching the alerts. That is most of Cyber Essentials, the government-backed baseline, and businesses certified to it are dramatically less likely to be back on this page next year.

    If you are reading this mid-incident

    We handle live incidents for London businesses, including ones we have never worked with before. No contract needed: our rate is £50 per hour plus VAT, and we will tell you within the first call whether you actually need us or can finish the job yourself with the steps above. Call 0207 112 4812, or if it can wait until you have contained things, book ad-hoc support here.

    Frequently Asked Questions

    Looking for proactive IT support instead of reactive fixes?

    Speak to our team today and discover how IT-MSP can transform your business technology.

    Certified Engineers Rapid Response 24/7 Support

    Other Articles