---
title: "What to Do in the First Hour After a Cyber Attack: A Guide for SMEs"
description: What to do in the first hour after a cyber attack. A cyber incident response guide for SMEs, from the first phone call to the 72-hour ICO deadline.
---

[Noble IT Blog](https://noble-it.co.uk/blog)

# [What to Do in the First Hour After a Cyber Attack: A Guide for SMEs](https://noble-it.co.uk/blog/cyber-incident-response-smes-first-hour)

 Written by [Adam Nichols](https://noble-it.co.uk/blog/author/adam-nichols) | Oct 05, 2026

In the first hour after a cyber attack, call your IT partner and disconnect affected devices from the network without switching them off. Then start a written log of everything that happens, because every decision after this one depends on it.

Most small businesses will be making it up as they go. According to the government's[Cyber Security Breaches Survey 2025/2026](https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026), only 25% of UK businesses have a formal incident response plan, and 45% have none of the basic measures in place, such as named roles or guidance on who to notify. One charity summed up its approach to the researchers in five words: it would "probably play it by ear".

This guide is the plan for the first 60 minutes, written for the Office Manager or director who ends up holding it.

## What should you do first if your business is hit by a cyber attack?

The first thing to do is call your IT partner or incident response contact, before you touch anything else.

Every instinct says to start fixing things. Resist it. Deleting files or restoring from backup can wipe out evidence of how the attacker got in, and let them back in afterwards. Your IT partner needs to see the systems as they are.

If a business, charity or organisation is suffering a live attack in progress,[Report Fraud](https://www.reportfraud.police.uk/) (which replaced Action Fraud) asks you to call 0300 123 2040 immediately. In Scotland, call Police Scotland on 101.

## Should you turn off your computer after a cyber attack?

No, in most cases you should disconnect an affected computer from the network but leave it switched on.

Unplug the network cable and turn off Wi-Fi. That stops the attack spreading to other machines and cuts the attacker's connection. Powering down, by contrast, can destroy information held in memory that investigators need. The NCSC's guidance on[the first hours of an attack](https://www.ncsc.gov.uk/collection/what-to-do-when-cyber-attacks-disrupt-your-organisation/recovering/immediate-activities) describes this as a trade-off, which is exactly why the call to your IT partner comes first. If ransomware is actively encrypting files and you can't reach anyone, shutting down to stop it is the lesser evil.

## Who do you need to tell in the first hour?

In the first hour, tell your IT partner and your directors, then check what your cyber insurer needs from you.

- Directors or owners. 81% of UK businesses say this is what they'd do. It's the easy one.
- Your cyber insurer. Many policies include an incident helpline, and some require you to call before appointing anyone. Only 51% of insured businesses say they'd tell their insurer. Check your policy now, not during the attack.
- Your bank, straight away, if payment details or banking logins may be involved.
- Your team. Tell them not to log in or open email until you give the all-clear.

Two other deadlines start ticking. If personal data may have been affected, UK GDPR requires you to[report it to the ICO](https://ico.org.uk/for-organisations/report-a-breach/) within 72 hours of becoming aware, where the breach poses a risk to people. And fraud or cyber crime should be reported to Report Fraud.

## Should you pay a ransomware demand?

The NCSC and UK law enforcement advise against paying a ransom, because payment doesn't guarantee you'll get your data back and marks you out as a business that pays.

Don't reply to the attackers or open negotiations in the first hour either. That decision belongs to your directors, your insurer and your incident responders together. It helps to have made it in advance. 49% of UK businesses have a policy not to pay ransomware demands, and 24% don't know what their policy is.

## How do you keep the business running during a cyber attack?

You keep running by switching to the backup ways of working set out in your business continuity plan, and by communicating through channels the attacker can't see.

Assume your email is compromised until you're told otherwise. Move incident conversations to phone calls or a separate messaging group on personal phones. Then work out what the business needs to keep going today. Can staff take orders by phone? Can invoices wait a day? Who needs to be told their delivery may be late?

This is where a business continuity plan earns its keep. If you don't have one, our[disaster recovery and business continuity](https://noble-it.co.uk/services/disaster-recovery-and-business-continuity) service will help you build one before you need it.

## What should you write down during a cyber attack?

Write down what happened, when, who noticed and every action taken since, with times against each entry.

Use paper or a device that isn't connected to your network. Screenshots of ransom notes or strange messages help too, taken on a phone if necessary. The NCSC recommends keeping one central record of what's been found and decided. Your insurer will ask for it, and so might the ICO.

## How can SMEs prepare for a cyber incident before it happens?

SMEs prepare by writing a short incident response plan and practising it with the team at least once a year. Keep a printed copy, because your network may be down when you need it.

A good cyber incident response for SMEs doesn't need a 50-page document. One page covering who to call, who decides, who talks to clients and where the backups are will do more than a manual nobody reads. Then test it. The NCSC's free[Exercise in a Box](https://www.ncsc.gov.uk/section/exercise-in-a-box/overview) walks your team through realistic scenarios, including ransomware and phishing.

Testing pays off. One large business in the survey ran its test as a Dungeons & Dragons-style tabletop game and came away with questions nobody had thought to ask. Another admitted its untested plan "keeps me awake at night".

## Right. Let's talk.

For Noble IT clients, the first call in that first hour is to us. Our 24/7[cyber security](https://noble-it.co.uk/services/cyber-security) monitoring often spots an attack before anyone in the office does, and we already know your systems. You carry on with your day, or as close to it as possible.

Don't know who you'd call right now? Not sure your backups would survive an attack? A[360 Review](https://noble-it.co.uk/book-360-review) will give you a clear answer. No obligations.

[Book Your 360 Review](https://noble-it.co.uk/book-360-review)

*Statistics and quotes: Cyber Security Breaches Survey 2025/2026, Department for Science, Innovation and Technology and the Home Office, published 30 April 2026.*

[View full post](https://noble-it.co.uk/blog/cyber-incident-response-smes-first-hour)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Adam Nichols"
  },
  "dateModified" : "2026-10-05T10:38:22.361Z",
  "datePublished" : "2026-10-05T10:37:13Z",
  "headline" : "What to Do in the First Hour After a Cyber Attack: A Guide for SMEs",
  "image" : {
    "@type" : "ImageObject",
    "height" : 1005,
    "url" : "https://noble-it.co.uk/hubfs/cyber-incident-response-smes-first-hour-noble-it.jpg",
    "width" : 1600
  },
  "mainEntityOfPage" : "https://noble-it.co.uk/blog/cyber-incident-response-smes-first-hour",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60.0,
      "url" : "https://25894449.fs1.hubspotusercontent-eu1.net/hubfs/25894449/Branding/Noble%20it_Icon_Black-1.png",
      "width" : 100.23866
    },
    "name" : "Noble IT Blog"
  }
}
```