What to Do in the First 24 Hours After a Cyber Attack

Published On
February 25, 2026
Share this post
https://www.emrynetworks.com/post/what-to-do-in-the-first-24-hours-after-a-cyber-attack

The first day of an incident sets the trajectory for everything that follows — how much data leaves, how long you are down, how much it costs, and whether you can prove to a regulator or an insurer that you handled it correctly. Almost none of that is decided by how good your tools are. It's decided by whether the people responding are following a plan or improvising.

Panic slows recovery. A written sequence, rehearsed in advance, is what keeps a bad morning from becoming a bad quarter. Here is the sequence, hour by hour.

Hour 1–4: Contain the threat

The first job is to stop the spread, not to investigate. Disconnect affected systems from the network, disable compromised accounts, and block the suspicious outbound traffic an attacker uses to exfiltrate data or phone home. Isolate — don't power off. Shutting a machine down wipes volatile memory that often holds the clearest evidence of what happened.

Containment is where a flat network hurts most. If one compromised laptop can reach the file server and the backups, the blast radius is the whole company. Segmentation, decided long before the incident, is what limits an attacker who gets in through a phished invoice to a corner of the environment instead of all of it.

Hour 4–12: Preserve the evidence

Resist the urge to wipe and rebuild immediately. Once systems are contained, capture logs, take forensic images or at least screenshots, and start a written timeline of who noticed what, when. That record does three jobs at once: it guides the investigation, it supports an insurance claim, and it becomes the evidence a regulator will ask for.

Detection quality shows up directly in the bill. IBM's Cost of a Data Breach Report 2025 found organizations that detected a breach themselves saved roughly $900,000 compared with those first notified by the attacker. Knowing quickly, and being able to show what you knew, is worth real money — and it depends on logging and monitoring you set up before the incident, not during it.

Why fast, documented detection pays

~$900K

The average saving IBM's Cost of a Data Breach Report 2025 attributes to detecting a breach internally rather than learning about it from the attacker. The organizations that save it are the ones that were already logging and monitoring before the incident.

Hour 12–18: Verify backups before you trust them

Before you restore anything, confirm you have a clean, recent, uninfected restore point. Modern ransomware specifically hunts for and deletes or encrypts backups before triggering, and it often sits in an environment for weeks — so the most recent backup may already be compromised. Identify the newest stable point, verify it is actually clean, and confirm the backup itself wasn't reachable by the attacker.

This is also where backups-only thinking breaks down. A clean restore brings your systems back, but it does nothing about data the attacker already copied out the door — the leverage behind double-extortion ransomware. Restoring is necessary; it is not the whole recovery.

Hour 18–24: Communicate — internally and legally

Inform leadership, bring in legal and compliance, and prepare clear, structured communication for staff before rumor fills the vacuum. This is also when the regulatory clock becomes real. Under the HIPAA Breach Notification Rule, individuals and HHS must be notified without unreasonable delay and no later than 60 days after discovery; the FTC's Health Breach Notification Rule uses the same 60-day outer limit. Some contracts and state laws are tighter, and a proposed HIPAA Security Rule update would push HHS notification for large breaches to 72 hours — that one is still proposed, not law, as of mid-2026, but it signals the direction.

The practical takeaway: know your notification obligations before an incident, because the countdown starts at discovery, not when you finish cleaning up.

The one thing that changes all of it: a plan written in advance

Every hour above assumes you already decided who does what. Organizations that build response readiness ahead of time recover measurably faster and cheaper. IBM's 2025 report found that extensive use of security AI and automation — the tooling that supports fast detection and response — cut the breach lifecycle by about 80 days and saved roughly $1.9 million on average. The specific numbers vary; the pattern doesn't. Preparation compresses both the timeline and the cost.

A one-page incident plan — roles, order of operations, phone numbers for legal, insurance, and your IT partner — is cheap to write and decisive the day it matters. If you don't have one, that is the gap to close before anything else, and it pairs directly with the year-round compliance readiness that keeps your evidence in order.

Have a plan before you need one

Emry Networks helps regulated SMBs build and rehearse incident response — containment, evidence, notification, and recovery — so the first 24 hours are a procedure, not a panic.

Book a security posture review

Frequently asked questions

What is the single most important thing to do first?

Contain, not investigate. Disconnect affected systems from the network and disable compromised accounts to stop the spread — but isolate rather than power off, because shutting a machine down destroys memory-based evidence. Once the bleeding is stopped, move to preserving evidence. Trying to diagnose before containing usually lets the incident grow while you look at it.

Should we pay the ransom?

That is a legal and business decision to make with counsel and, ideally, law enforcement — not a technical one, and not one to make under pressure at hour two. Paying does not guarantee the data is returned or deleted, and in double-extortion cases the stolen copy may be leaked or sold regardless. This is exactly why the decision, and who makes it, should be settled in your incident plan before an incident happens.

How quickly do we have to report a breach?

It depends on the regime, and the clock starts at discovery. Under the HIPAA Breach Notification Rule, notice to individuals and HHS is due without unreasonable delay and no later than 60 days; the FTC's Health Breach Notification Rule uses the same 60-day outer limit. Contracts, cyber-insurance policies, and state laws are often tighter. Know your specific obligations in advance, because you cannot research them and meet them at the same time.

Do backups mean we're safe from ransomware?

Backups solve one half of the problem: getting systems running again. They do nothing about data the attacker already copied out, which is the leverage behind modern double-extortion attacks. And backups only help if they are clean and reachable — ransomware routinely deletes or encrypts backups first, so you must verify an uninfected restore point before trusting it.

How do we recover faster next time?

Write and rehearse an incident response plan before you need it. IBM's 2025 research ties faster detection and response — supported by monitoring, logging, and automation set up in advance — to dramatically shorter breach lifecycles and lower cost. A rehearsed one-page plan naming roles, order of operations, and key phone numbers is the highest-leverage preparation most SMBs are missing.

Sources

  • IBM & Ponemon Institute, Cost of a Data Breach Report 2025 — ~$900,000 saved where a breach was detected internally rather than disclosed by the attacker; extensive security AI and automation associated with an ~80-day shorter breach lifecycle and ~$1.9M lower cost.
  • HHS Office for Civil Rights, HIPAA Breach Notification Rule (45 CFR §§164.400–414) — individual and HHS notification without unreasonable delay and no later than 60 days after discovery.
  • U.S. Federal Trade Commission, Health Breach Notification Rule — 60-day outer limit for notification; and the 2025 HIPAA Security Rule NPRM proposing a 72-hour HHS notification window for large breaches (proposed, not finalized as of mid-2026).

Every exact figure is attributed to its primary source and reflects the most recent published edition available at the time of writing; regulatory status was verified as proposed-vs-final at publication and may change.

Share this post
https://www.emrynetworks.com/post/what-to-do-in-the-first-24-hours-after-a-cyber-attack

Ready to strengthen your compliance?

Get hands-on assessment and guidance from our compliance experts.