First Hour After a Cyberattack: A UK Response Guide

First Hour After a Cyberattack: A UK Response Guide
Cybersecurity Strategy Pillars graphic. Depicts 6-tiers in a pyramid. From the top, the tiers read: Vision, Mission, Objectives, Strategy, Approach, and Tactics.

Interested in our Cybersecurity Framework?

Visit our article on how to organise an effective cybersecurity strategy to download a copy of our framework.

Instant Email Domain Score

By joining forces with Sendmarc, VirtueUK is committed to offering enhanced security measures, ensuring that sensitive data and communications are protected from cyber-attacks. Check your email domain score instantly here.

Interested in a Free Phishing Security Test?

VirtueUK are partners with KnowBe4, the world's largest security awareness training and simulated phishing platform.

If you're interested in assessing the Phish-prone percentage of your users, contact us to arrange a free simulated phishing attack.

Can Your Organisation Withstand Disruption?

Explore how leadership can strengthen resilience and support long-term sustainability.

Cyber Essentials Plus: Proven Cyber Security

Discover why Cyber Essentials Plus certification matters and how it helps organisations strengthen security and build trust.

If your organisation suffers a cyberattack, the actions you take during the first hour can significantly affect the outcome. For London-based organisations with 30-400 users, a prompt, measured response can help contain the incident, preserve critical evidence, and reduce financial and operational disruption. This guide explains what to do immediately, who to contact, and how to meet your reporting obligations in the UK.

Before Anything Else: Avoid Making the Situation Worse

When a cyberattack is discovered, the instinct is often to start “fixing” the problem immediately. Unfortunately, well-intentioned actions can often compromise  investigation and recovery efforts.

Before taking any action:

  • Do not immediately power off affected devices. If possible, disconnect them from the network instead. Memory data can provide valuable forensic evidence to investigators.
  • Do not delete suspicious emails, files, or ransom notes. These may help determine how the compromise occurred.
  • Do not pay a ransom without professional advice. Payment does not guarantee data recovery and may encourage further criminal activity.
  • Do not use compromised systems to discuss the incident. If attackers have access to your email environment, they may be able to monitor internal communications.

The National Cyber Security Centre (NCSC) recommends a measured response focused on containment, evidence preservation, and rapid escalation to your IT support provider.

Step-by-Step Response Plan

1. Isolate the Affected Systems

The first priority is containment, so disconnect any affected devices from:

  • Wired networks
  • Wi-Fi connections
  • VPN sessions
  • Shared drives and cloud synchronisation where appropriate

This prevents malware, ransomware, or unauthorised access from spreading across your environment.

For organisations with multiple locations or hybrid workers, your IT provider should quickly assess whether additional systems require isolation.

2. Contact Your IT Provider Immediately

Call your managed IT provider or internal IT team directly.

Avoid relying on email if there is any possibility that user accounts or email systems have been compromised.

For organisations with cyber insurance, notify your insurer as soon as possible. Many policies require early involvement of approved incident response specialists.

3. Preserve Evidence

Once systems have been isolated:

  • Leave affected devices switched on where safe to do so
  • Take photographs or screenshots of any ransom notes or suspicious messages
  • Record the time the incident was discovered
  • Document unusual behaviour or error messages

Do not reinstall software, reset systems, or begin cleanup activities until your IT provider has assessed the situation.

4. If Money Has Been Transferred, Contact Your Bank Immediately

Business Email Compromise (BEC) and payment diversion fraud remain common threats.

If an employee has transferred funds following a fraudulent email or invoice:

  • Contact your bank immediately
  • Request an urgent payment recall
  • Ask whether the transaction can be frozen or intercepted

Every minute matters. Early reporting offers the greatest chance of recovering funds before they leave the banking system.

5. Reset Critical Passwords from a Clean Device

Once your IT provider confirms it is safe to proceed:

Prioritise:

  1. Microsoft 365 or Google Workspace accounts
  2. Administrative accounts
  3. Finance systems
  4. CRM platforms
  5. Remote access solutions

Use a known clean device and enable Multi-Factor Authentication (MFA) wherever possible.

The NCSC considers MFA one of the most effective security controls for preventing unauthorised account access.

6. Begin Internal Communications

For organisations with 30-400 users, uncertainty can spread quickly during an incident.

Provide staff with:

  • Clear instructions on approved communication channels
  • Guidance on whether systems should remain offline
  • Warnings about additional phishing attempts
  • Contact details for reporting suspicious activity

Avoid speculation until facts have been verified.

Reporting a Cyberattack in the UK

For UK organisations, particularly those operating in London and the surrounding areas, cyber incidents should be reported through the appropriate channels.

Report to Action Fraud

Action Fraud is the UK’s national reporting centre for fraud and cybercrime.

Report online or by telephone as soon as possible.

Seek Guidance from the NCSC

The National Cyber Security Centre provides advice, incident guidance, and reporting resources for UK organisations.

The NCSC also operates the Suspicious Email Reporting Service, helping organisations report phishing campaigns.

Notify the Information Commissioner's Office (ICO) if Required

If personal information relating to employees, customers, service users, or suppliers has been exposed, you may have a legal obligation to report the breach.

Under UK GDPR, organisations must assess whether the breach poses a risk to individuals and, in certain circumstances, notify the ICO within 72 hours.

Early engagement with legal advisers and cyber specialists can help determine reporting requirements.

Should You Pay a Ransom?

For many organisations, ransomware presents the most difficult decision during an incident. Payment may seem like the fastest route to recovery, but there are significant risks:

  • No guarantee of receiving a working decryption key
  • Potential for repeat attacks
  • Funding criminal activity
  • Possible regulatory and legal implications

Instead, organisations should work closely with:

  • Their IT provider
  • Cyber insurers
  • Incident response specialists
  • Law enforcement agencies

In some cases, decryption tools already exist for specific ransomware variants, making payment unnecessary.

Preparation Is Your Best Defence

The most resilient organisations do not wait until an attack occurs.

The Cyber Security Breaches Survey found that medium-sized organisations continue to experience high levels of cyberattacks, with 67% reporting breaches or attacks in the previous year.

Every organisation should maintain a simple cyber incident response plan covering:

  • Who to contact first
  • IT provider and insurer contact details
  • Backup locations and recovery procedures
  • Critical business systems
  • Escalation paths for leadership teams

A clear, documented plan can dramatically reduce confusion and downtime during a real-world incident.