Worried about a disruption right now? Call us today
← All insights
Cyber12 Jun 20258 min read

What to do in the first hour of a cyber incident.

Most businesses lose the first hour to confusion. Here's a simple sequence to follow when the email or systems go dark — written for an owner, not an IT manager.

By ResilientQLD

You get the call at 7:14am. The office manager can't log in. Neither can anyone else. The accounts inbox is bouncing. Something's wrong, and no one quite knows what.

The next hour matters more than most people realise. Not because you'll solve the problem in an hour — you won't — but because the decisions you make in that first hour shape the next three days.

1. Stop and write down what you know

Grab a notebook. Time-stamp the first symptom. Who noticed it, what they were doing, what changed. If it later turns out to be an incident that involves regulators, insurers, or lawyers, this note is worth its weight in gold.

2. Pull the plug — carefully

If you suspect ransomware or an active intruder, disconnect affected machines from the network (unplug the ethernet cable, turn off Wi-Fi). Do NOT power them off — you'll lose forensic evidence your IT provider or insurer will need.

3. Call your people in the right order

  • Your IT provider or MSP — first call, always.
  • Your cyber insurance hotline — most policies require early notification.
  • Any staff who need to stop transacting (bookkeeper, accounts).
  • Your leadership team — one short message, facts only.

4. Decide what you're telling customers

Silence is worse than an honest holding message. A short line — "We're experiencing a technical issue and are working on it, we'll update you by 2pm" — buys you hours of goodwill. Nominate one person to speak. Everyone else stays quiet.

"The businesses that recover fastest aren't the ones with the best tech. They're the ones who agreed in advance who makes the first call."

5. Keep the log going

Every decision, every call, every timestamp. In two weeks, when the insurer asks what happened and when, this log is your defence.

None of this replaces a proper incident response plan. But if the plan doesn't exist yet, this is the shape of the first hour.