What Happens After a Cyber Attack? A Step-by-Step Recovery Guide for SMEs

A cyber attack is one of the most stressful things a business can experience. Systems go down. Data is at risk. Customers need answers. And in the middle of the chaos, most business owners are asking the same question: what do we do now?

The good news is that recovery is possible — and the businesses that bounce back fastest aren’t always the ones with the best defences. They’re the ones that had a plan.

This guide walks you through exactly what to do in the immediate aftermath of a cyber incident, so you can act quickly, limit the damage, and come out the other side stronger.

 


 

Step 1: Don’t Panic — But Act Fast

The first minutes after discovering an attack are critical. Your instinct might be to shut everything down immediately, but acting without a plan can make things worse — potentially destroying the forensic evidence you’ll need later.

Stay calm, gather your key people, and move to step two.

 


 

Step 2: Isolate the Affected Systems

The priority is to stop the attack from spreading. Disconnect affected devices from your network — unplug ethernet cables, disable Wi-Fi, and isolate any systems that appear compromised. Do not switch them off entirely unless instructed to do so by a security professional, as this can destroy volatile evidence.

If you use cloud services, check whether any accounts have been accessed or compromised and revoke permissions where necessary.

 


 

Step 3: Notify the Right People

You cannot handle this alone, and you shouldn’t try to. Contact:

  • Your IT provider or managed service provider — they should be your first call. If you don’t have one, now is the time to find a reputable cyber incident response specialist.
  • Your cyber insurance provider — if you have a policy, notify them immediately. Many policies include incident response support.
  • The National Cyber Security Centre (NCSC) — the UK’s national authority on cyber security offers guidance and, for significant incidents, direct support.
  • The Information Commissioner’s Office (ICO) — if personal data has been compromised, you are legally required to report it within 72 hours under UK GDPR.

 


 

Step 4: Assess the Damage

Once the immediate situation is contained, you need to understand what actually happened. Work with your IT team or incident response provider to establish:

  • Which systems and data were affected
  • How the attacker gained access
  • Whether data was stolen, encrypted, or destroyed
  • Whether the attack is ongoing or has been fully contained

This assessment will shape everything that follows — your recovery plan, your communications, and your legal obligations.

 


 

Step 5: Communicate — Carefully and Promptly

Transparency matters, but so does accuracy. Getting your communications wrong can cause unnecessary panic or, worse, legal issues.

Internally, keep your team informed so they know what to do and what not to do — particularly around phishing attempts that may follow an initial breach. Externally, if customers, suppliers, or partners have been affected, notify them promptly with clear, factual information about what happened and what you’re doing about it.

Avoid speculation. Stick to what you know, and update people as the situation develops.

 


 

Step 6: Begin Recovery

With the incident contained and the damage assessed, recovery can begin. This typically involves:

  • Restoring data from backups — this is why regular, tested backups are non-negotiable. If your backups are also compromised, recovery becomes significantly more difficult and expensive.
  • Rebuilding affected systemsrather than cleaning infected machines, it’s often safer to rebuild from scratch using clean images.
  • Resetting credentials — all passwords connected to affected systems and accounts should be reset immediately, with multi-factor authentication (MFA) enforced.
  • Patching vulnerabilities — once you know how the attacker got in, close the door permanently.

 


 

Step 7: Learn and Strengthen

Once the dust has settled, don’t move on too quickly. A post-incident review is one of the most valuable things you can do. Understand what went wrong, what your response got right, and — critically — what gaps it exposed.

Use this as the foundation for strengthening your defences: updated policies, staff training, improved monitoring, and a formal incident response plan for next time.

 


 

The Best Recovery Plan Is One You Never Need

No recovery plan replaces prevention. Cyber Essentials certification, regular patching, multi-factor authentication, and a managed IT provider who monitors your environment proactively are your first and most important lines of defence.

But if the worst does happen, having a clear plan — and the right people around you — makes all the difference.

Disking IT supports SMEs across Hampshire and Surrey with managed cyber security, Cyber Essentials certification, and proactive IT support. If you’d like to review your current security posture or talk through your incident response readiness, get in touch with our team today.

👉 More on disaster recovery: Disaster Recovery Solutions – Disking IT

👉 Want a free cyber security audit? Free Cyber Security Audit | Disking IT

 

 

 

More Posts

Contact us to plan your next stage of IT growth

Perfect Solutions For Your Organisation

Whether you’re enhancing security, gaining deeper insight from your data, or embracing AI, we’ll guide your next move with clarity & confidence.

Read other articles

Latest News & Articles

Cyber Insurance: More than a Checkbox Exercise

Do you buy cyber insurance the same way you buy any other insurance? Fill in a form, tick…

Ransomware Recovery: What Actually Happens in the First 24 Hours

Most businesses only think about ransomware recovery in the abstract, until the morning someone can’t open a file……

5 signs your business has outgrown its current IT support

Outgrowing your IT support is usually a sign business is going well. More staff, more sites, more systems,…

Resources