What Small Businesses Should Do in the First Hour After a Cyber Incident

For many small businesses, the most dangerous part of a cyber incident is not always the technical problem itself. It is the confusion that follows.

Blog Main Image

What Small Businesses Should Do in the First Hour After a Cyber Incident

For many small businesses, the most dangerous part of a cyber incident is not always the technical problem itself. It is the confusion that follows.

Someone clicks a suspicious link. A member of staff sees files suddenly changing names. A Microsoft 365 login alert appears from a location nobody recognises. The first reaction is often panic, guesswork or silence. Someone restarts the device. Someone else deletes the email. Another person waits until later because they do not want to cause a fuss.

That delay can make a manageable problem much worse.

For a UK SME, the first hour after a cyber incident can shape how much downtime, cost and disruption follows. A calm, simple response does not guarantee that nothing serious will happen, but it can dramatically reduce the damage.

Why the first hour matters so much

Cyber incidents often get worse when businesses lose time.

If one compromised device stays connected, malware may keep spreading. If a stolen password is still active, an attacker may keep accessing email, files or cloud systems. If staff start "fixing" things without a plan, important evidence can disappear before your IT provider has a chance to understand what happened.

This is why the goal in the first hour is not to solve everything. It is to contain the issue, protect the rest of the business, and get the right people involved quickly.

That mindset alone can make a big difference.

What counts as a cyber incident for a small business?

Not every incident looks dramatic. In fact, many of the most important warning signs look quite ordinary at first.

Examples include:

  • a staff member clicking a suspicious link or opening an unexpected attachment
  • repeated password prompts or MFA requests nobody expected
  • a laptop behaving strangely, locking up, or showing unfamiliar pop-ups
  • emails being sent from an account without the user's knowledge
  • missing files, renamed folders, or signs that data has been encrypted
  • a supplier or client reporting an unusual message that appeared to come from your business

For a small business owner, the key point is simple: if something looks wrong, treat it seriously early. It is better to investigate a false alarm than to downplay a real one.

A practical first-hour checklist

You do not need a full corporate security department to respond sensibly. You just need a short checklist that people can follow without overthinking it.

1. Isolate the affected device

If a laptop, desktop or phone looks compromised, disconnect it from the network as soon as possible.

That might mean:

  • turning off Wi-Fi
  • unplugging the network cable
  • removing remote access where appropriate
  • stopping the user from carrying on with normal work on that device

This step helps limit spread. It is especially important if ransomware, malicious downloads or unauthorised remote access may be involved.

Do not rush to wipe the device or "have a go" at fixing it yourself. Isolation first, diagnosis second.

2. Report it immediately to the right person

Every business should be clear about who gets told first.

That could be:

  • your internal operations lead
  • your office manager
  • your external IT support provider
  • a named director or senior contact

The important thing is speed and clarity. Staff should know that reporting early is the right decision, even if they are worried they may have caused the issue.

Blame slows everything down. Fast reporting protects the whole business.

3. Preserve the evidence

One of the biggest mistakes small businesses make is deleting the suspicious email, clearing the browser, or restarting the machine before anyone has looked at it.

That can remove clues your IT partner needs.

If possible, make a note of:

  • what the user saw
  • what time it happened
  • what they clicked or opened
  • any error messages or strange behaviour
  • whether the same issue appears on other devices or accounts

A quick photo on a phone can sometimes help if a warning message disappears later.

4. Check whether the problem is wider

Once the immediate issue is contained, the next question is whether it affects only one user or more of the business.

For example:

  • has the same phishing email gone to multiple staff?
  • are other users getting MFA prompts they did not trigger?
  • is a shared mailbox sending strange replies?
  • are files on a server or shared drive also affected?

This is where managed IT support becomes especially valuable. A good provider can check Microsoft 365, endpoints, backups, alerts and account activity much more quickly than a business owner trying to piece it together manually.

5. Protect access quickly

If there is any sign that an account may be compromised, act quickly to secure it.

That may include:

  • disabling the account temporarily
  • forcing a password reset
  • revoking active sessions
  • checking MFA status
  • reviewing forwarding rules or suspicious mailbox changes

Again, this should be done carefully and in a controlled way. The aim is to stop continued access without creating more confusion than necessary.

A simple real-life example

Imagine a member of staff in a Bolton office receives an email that appears to be from Microsoft 365 asking them to re-authenticate. They click the link, enter their password, then start getting repeated MFA prompts on their phone.

A poor response would be to ignore it, keep working, or just change the password at the end of the day.

A better first-hour response would be:

  1. stop using the device
  2. report the issue straight away
  3. alert the IT provider
  4. reset the password and review account sessions
  5. check whether other users received the same email
  6. review mailbox rules, sign-in logs and any suspicious activity

That does not remove all risk instantly, but it gives the business a much better chance of containing the problem before it turns into account takeover, fraud or wider disruption.

Build the process before you need it

The best time to decide how your business will respond is before there is a real incident.

For most SMEs, a useful first step is to create a one-page response checklist covering:

  • who staff should contact first
  • how to isolate a device
  • what information to capture
  • who can authorise urgent account changes
  • how to reach your IT support provider quickly

Keep it simple. If the plan is too long or technical, people will not use it when they are under pressure.

This is part of having your technology managed the right way. Good cybersecurity is not only about tools. It is also about having calm, practical processes that reduce business risk when something goes wrong.

What to do next

If your business does not yet have a clear first-hour cyber incident plan, now is a good time to put one in place.

Start with a short checklist, make sure staff know how to report problems quickly, and review whether your current IT setup gives you the visibility and support you would need during a real incident.

If you would like a straightforward review of how prepared your business is, Managed IT Support can help you assess your current response process and identify a few practical improvements without overcomplicating it.

Ready to Work With an IT Company That Actually Gives a Damn?

Book a free IT review and we'll show you exactly where your current setup is costing you money, leaving you exposed, or slowing your team down. No obligation, no hard sell.

IT Review Consultation