Interested in our Cybersecurity Framework?
Instant Email Domain Score
Interested in a Free Phishing Security Test?
If you're interested in assessing the Phish-prone percentage of your users, contact us to arrange a free simulated phishing attack.
Can Your Organisation Withstand Disruption?
Cyber Essentials Plus: Proven Cyber Security
If your organisation suffers a cyberattack, the actions you take during the first hour can significantly affect the outcome. For London-based organisations with 30-400 users, a prompt, measured response can help contain the incident, preserve critical evidence, and reduce financial and operational disruption. This guide explains what to do immediately, who to contact, and how to meet your reporting obligations in the UK.
Before Anything Else: Avoid Making the Situation Worse
When a cyberattack is discovered, the instinct is often to start “fixing” the problem immediately. Unfortunately, well-intentioned actions can often compromise investigation and recovery efforts.
Before taking any action:
- Do not immediately power off affected devices. If possible, disconnect them from the network instead. Memory data can provide valuable forensic evidence to investigators.
- Do not delete suspicious emails, files, or ransom notes. These may help determine how the compromise occurred.
- Do not pay a ransom without professional advice. Payment does not guarantee data recovery and may encourage further criminal activity.
- Do not use compromised systems to discuss the incident. If attackers have access to your email environment, they may be able to monitor internal communications.
Step-by-Step Response Plan
1. Isolate the Affected Systems
The first priority is containment, so disconnect any affected devices from:
- Wired networks
- Wi-Fi connections
- VPN sessions
- Shared drives and cloud synchronisation where appropriate
This prevents malware, ransomware, or unauthorised access from spreading across your environment.
For organisations with multiple locations or hybrid workers, your IT provider should quickly assess whether additional systems require isolation.
2. Contact Your IT Provider Immediately
Call your managed IT provider or internal IT team directly.
Avoid relying on email if there is any possibility that user accounts or email systems have been compromised.
For organisations with cyber insurance, notify your insurer as soon as possible. Many policies require early involvement of approved incident response specialists.
3. Preserve Evidence
Once systems have been isolated:
- Leave affected devices switched on where safe to do so
- Take photographs or screenshots of any ransom notes or suspicious messages
- Record the time the incident was discovered
- Document unusual behaviour or error messages
Do not reinstall software, reset systems, or begin cleanup activities until your IT provider has assessed the situation.
4. If Money Has Been Transferred, Contact Your Bank Immediately
Business Email Compromise (BEC) and payment diversion fraud remain common threats.
If an employee has transferred funds following a fraudulent email or invoice:
- Contact your bank immediately
- Request an urgent payment recall
- Ask whether the transaction can be frozen or intercepted
Every minute matters. Early reporting offers the greatest chance of recovering funds before they leave the banking system.
5. Reset Critical Passwords from a Clean Device
Once your IT provider confirms it is safe to proceed:
Prioritise:
- Microsoft 365 or Google Workspace accounts
- Administrative accounts
- Finance systems
- CRM platforms
- Remote access solutions
Use a known clean device and enable Multi-Factor Authentication (MFA) wherever possible.
6. Begin Internal Communications
For organisations with 30-400 users, uncertainty can spread quickly during an incident.
Provide staff with:
- Clear instructions on approved communication channels
- Guidance on whether systems should remain offline
- Warnings about additional phishing attempts
- Contact details for reporting suspicious activity
Avoid speculation until facts have been verified.
Reporting a Cyberattack in the UK
For UK organisations, particularly those operating in London and the surrounding areas, cyber incidents should be reported through the appropriate channels.
Report to Action Fraud
Action Fraud is the UK’s national reporting centre for fraud and cybercrime.
Report online or by telephone as soon as possible.
Seek Guidance from the NCSC
The National Cyber Security Centre provides advice, incident guidance, and reporting resources for UK organisations.
Notify the Information Commissioner's Office (ICO) if Required
If personal information relating to employees, customers, service users, or suppliers has been exposed, you may have a legal obligation to report the breach.
Under UK GDPR, organisations must assess whether the breach poses a risk to individuals and, in certain circumstances, notify the ICO within 72 hours.
Early engagement with legal advisers and cyber specialists can help determine reporting requirements.
Should You Pay a Ransom?
For many organisations, ransomware presents the most difficult decision during an incident. Payment may seem like the fastest route to recovery, but there are significant risks:
- No guarantee of receiving a working decryption key
- Potential for repeat attacks
- Funding criminal activity
- Possible regulatory and legal implications
Instead, organisations should work closely with:
- Their IT provider
- Cyber insurers
- Incident response specialists
- Law enforcement agencies
In some cases, decryption tools already exist for specific ransomware variants, making payment unnecessary.
Preparation Is Your Best Defence
The most resilient organisations do not wait until an attack occurs.
The Cyber Security Breaches Survey found that medium-sized organisations continue to experience high levels of cyberattacks, with 67% reporting breaches or attacks in the previous year.
Every organisation should maintain a simple cyber incident response plan covering:
- Who to contact first
- IT provider and insurer contact details
- Backup locations and recovery procedures
- Critical business systems
- Escalation paths for leadership teams
A clear, documented plan can dramatically reduce confusion and downtime during a real-world incident.