The First Hour of a Breach: What to Do, and What Not to Touch

Picture of Ikram Massabini

Ikram Massabini

August 8, 2026

The First Hour of a Breach_ What to Do, and What Not to Touch

Most of the damage a business suffers in a cyber incident is decided before anyone qualified has looked at it. Not because the attack is unusually sophisticated, but because the first person to notice something wrong starts trying to fix it.

That instinct is understandable and almost always counterproductive. Powering down the wrong machine destroys evidence. Deleting the ransom note removes the one artifact that identifies which strain you are dealing with. Emailing the team about the incident, from an account the attacker is currently reading, tells them how much you know and how fast you are moving.

None of what follows requires technical skill. It requires knowing the order in advance, because the moment you need it is the worst possible time to work it out.

Four things to leave alone

Before any action, there are a few reflexes to suppress.

Avoid powering off the affected computer. Cutting its network connection contains the incident just as well and preserves evidence that lives only in memory. CISA’s guidance is to isolate rather than shut down, reserving a hard power-off for cases where nothing else will sever the connection.

Do not delete anything. The ransom note, the suspicious email, the alerts your security tools fired: leave all of it where it is. That material is what your IT team and any investigator will work from.

Do not decide about a ransom in the first panicked hour. And do not discuss the incident using the compromised accounts. If someone is in your inbox, they are reading those messages.

The order to work in

Once you have stopped making it worse, the sequence is straightforward.

  1. Isolate first. Pull the ethernet cable, disable the wireless adapter, and do it on every device that looks involved. Cutting network access is what keeps the problem from spreading to your other machines and, critically, to your backups.
  2. Call your IT provider by phone, not email. If you carry cyber insurance, call the carrier next. Many policies require their incident response team from the beginning, and waiting can complicate the claim.
  3. Preserve the scene. No wiping, no reinstalling, no tidying up. Screenshots are useful, but they supplement the originals rather than replace them.
  4. If money moved, call the bank immediately and ask them to recall and freeze the transfer. With wire fraud, the window is measured in hours.
  5. Reset passwords from a device you are confident is clean, starting with email and administrator accounts, and turn on multi-factor authentication wherever it is missing.
  6. Report it, which is sometimes a legal obligation rather than a choice.

Where to report, and why the clock matters

In the United States, file with the FBI’s Internet Crime Complaint Center and report to CISA. Businesses operating in the UK report through the NCSC and Action Fraud; in Australia, through ReportCyber.

Speed is not a formality here. The FBI’s Recovery Asset Team recovers funds in roughly 70 percent of wire fraud cases reported to IC3 within 72 hours. Past that window, the odds drop sharply.

A second clock runs if customer or employee data was exposed. Depending on what was taken, notification duties may attach, to a regulator and to the individuals themselves, on timelines that can be as short as 72 hours. New York businesses carry state breach notification obligations on top of any federal or industry rules. Ask your attorney or IT provider early rather than discovering a missed deadline afterward.

The ransom question

If it is ransomware, this is the decision everyone fixates on. The FBI does not recommend paying. Payment does not guarantee recovery, it marks your business as one that pays, and it funds the next round of attacks.

It remains your call, but it is one to make alongside law enforcement, your incident response team, and your insurer. It is also worth checking whether a free decryption tool already exists for the variant that hit you, because for a number of strains one does.

The version of this that actually helps

Everything above is easier if some of it was decided in advance, and a usable plan is shorter than most people expect. One page covering who to call first and their phone numbers, stored somewhere reachable without your main systems. Where your backups live, and evidence that someone has actually restored from them. Which accounts and devices matter most.

That is enough for most small and mid-sized businesses, and it converts a chaotic morning into a sequence of phone calls.

If you would rather not improvise

MVP Network Consulting helps businesses throughout Buffalo and Western New York build that one-page plan and, when it comes to it, work the response. If your team would be guessing right now, that is worth fixing. Get in touch and we will put the plan together with you.