If your business gets hit by a cyberattack, the first hour decides almost everything. Here’s exactly what to do — step by step — even if you’re not a tech person.
It’s 9:14 on a Tuesday morning. You walk into your Bradenton office, coffee in hand, and your office manager meets you at the door: “None of our files will open. There’s a weird message on every screen.”
Your stomach drops. You don’t know whether to shut everything down, call the police, or Google “what to do during a cyberattack.”
What you do in the next sixty minutes will determine whether this is a rough week — or a catastrophe that costs your firm six figures and months of recovery.
The average ransomware shutdown lasts 24 days
That’s not a typo. Accounting firms, law offices, dental practices — the businesses we work with across Tampa Bay lose an average of 24 days of productivity after a ransomware attack. For a small firm, that can mean $120,000 to over $1 million in total costs.
But here’s the thing most people get wrong: the biggest damage usually isn’t from the attack itself. It’s from what the business owner does (or doesn’t do) in those first panicked minutes.
So let’s fix that right now. Print this page. Bookmark it. Share it with your office manager. Because if this ever happens to you, you won’t be thinking clearly — and you’ll want a checklist.
Rule zero: don’t make it worse
Before you touch anything, avoid these common mistakes:
- Don’t turn the affected computer off. I know it feels right, but powering down can wipe the digital evidence your IT team and investigators need. Disconnect it from the network instead.
- Don’t delete anything. Leave the ransom note, the suspicious email, and any error messages exactly where they are.
- Don’t pay a ransom on the spot. Seriously. Not yet.
- Don’t use the hacked email to discuss the attack. If an attacker is sitting in your inbox, they can read every message you send. Pick up the phone instead.
Your 7-step plan (no tech skills required)
Step 1: Cut the cord
Unplug the network cable from the affected computer. If it’s a laptop, turn on airplane mode. The goal is to stop the infected device from talking to the rest of your network — while keeping it powered on so evidence is preserved.
Ransomware can spread across a network in minutes. Disconnecting that one machine buys your team critical time.
Step 2: Pick up the phone
Call your IT provider. Don’t email them. If the attacker has access to your Microsoft 365 or email account, they’ll see that message and know you’ve caught on.
A phone call keeps the conversation off the compromised system. If you have a managed IT provider, ask if they already have an incident response plan set up for your account. (If they don’t, that’s a red flag.)
Step 3: Grab your phone and document everything
Take photos of every error message, ransom note, or strange screen with your personal phone. Write down the exact time you first noticed the problem and anything unusual you’ve seen — failed logins, weird emails, files with scrambled names.
This evidence is gold when investigators try to piece together what happened.
Step 4: Check your bank accounts — right now
Log into your bank from a different, unaffected device. Look for wire transfers, payment changes, or invoices you didn’t authorize.
If money has already been sent, call the bank immediately. The FBI’s Recovery Asset Team reports roughly a 66% recovery rate on fraudulent wires — but only when reported within about 72 hours. After that, your odds drop fast.
Step 5: Reset passwords from a clean device
If any account may have been accessed, change the password and turn on multifactor authentication (that’s the code sent to your phone when you log in). Do this from a device you know is safe — not the one that’s been compromised.
Also check whether the attacker changed any settings, set up email forwarding, or added inbox rules you didn’t create. Attackers love to quietly forward copies of your email to themselves.
Step 6: Tell the people who need to know
That means your leadership team, your attorney, and your cyber insurance carrier. Depending on what data was exposed, you may also need to notify regulators or the clients whose information was affected.
Notification requirements vary based on the type of data and where your business operates — your attorney and IT provider can help you figure out what applies. For financial advisors and CPAs, there may be additional regulatory obligations worth discussing with a compliance professional.
Step 7: Don’t wipe anything yet
It’s tempting to nuke the affected machines and start fresh. Resist that urge. Your IT team may need forensic images of the drives, and some cyber insurance policies require evidence preservation as a condition of paying your claim.
Where to report it
In the United States, file a report with the FBI’s Internet Crime Complaint Center at ic3.gov. For ransomware specifically, you can also report through CISA at cisa.gov/report.
If you’re in a regulated industry — financial services, healthcare, legal — there may be additional reporting requirements. Your attorney can advise you on those.
When your regular IT person isn’t enough
Your everyday IT provider is great for printers and password resets. But if any of these are true, you likely need a cybersecurity specialist involved:
- Sensitive client data — tax records, financial plans, legal files, medical records — may have been accessed or stolen
- You’re facing a legal or regulatory reporting deadline
- You’re not sure how far the attacker got into your systems
- You need forensic evidence for law enforcement or an insurance claim
A cybersecurity consultant or incident response firm can work alongside your IT team to handle the parts that require specialized expertise.
The attack is over. Now what?
Once the immediate threat is contained, don’t just breathe a sigh of relief and move on. Run a post-incident review:
- How did the attacker get in?
- What did they access?
- Were your backups intact and actually usable?
- What needs to change so this doesn’t happen again?
This step is easy to skip when everyone’s exhausted. But it’s the difference between getting hit once and getting hit twice.
Your first-hour cheat sheet
- Disconnect affected devices from the network (don’t power off)
- Call your IT provider by phone — not email
- Take photos of error messages and write down the timeline
- Check bank accounts for unauthorized transfers
- Reset compromised passwords from a clean device
- Notify leadership, your attorney, and your cyber insurer
- Preserve all evidence — don’t wipe anything
If you’re a CPA firm, law office, or financial advisory practice in Bradenton or the Tampa Bay area, you don’t have to figure this out alone. Book a free 15-minute risk assessment with Justin and Sara at Reef Cyber Security. We’ll tell you where your gaps are — before an attacker finds them first.
