Insights

What the First 72 Hours After a Small-Business Cyber Attack Look Like

A closed sign hanging on the glass door of a small shop — photo by Ekaterina Belinskaya on Pexels

Every week, owners post the same kind of message in small-business forums. The details differ; the shape does not. Something stopped working. Nobody is sure what happened. The person who set up the computers is no longer answering.

We read a lot of those threads this month. What struck us is how little of the pain is technical. Most of it is decision-making under pressure, with no plan and no one to call.

Here is what those three days actually look like, and what makes them easier.

TL;DR

Contain first, investigate second, restore third. Do not clean up before you have preserved evidence. Get a competent person on the phone within the first few hours, even if you have to pay for a few hours of their time. And check whether your backups are actually restorable before you need them, not after.

Hour zero: you notice something is wrong

Usually it is small. Files will not open. A vendor calls to ask why you emailed them a strange invoice. Staff cannot log in. Sometimes it is loud, a screen with a demand on it, but more often it is quiet.

The first instinct is to poke at it. That is the wrong instinct, and it is worth knowing in advance.

What actually helps at this point: write down what you see and when you first saw it. Do not delete anything. Do not reboot the machines that are affected. Note who has logged in and from where.

Hours one to four: contain, do not clean

The goal for the first few hours is to stop the spread, not to fix anything.

Disconnect affected machines from the network. If email is involved, get with whoever administers it and cut off the compromised accounts, and check for rules that quietly forward or delete mail. Change the passwords on the accounts you know are involved, from a device that is not part of the problem.

Resist the urge to wipe and rebuild on day one. Rebuilding destroys the evidence that tells you how they got in and, more importantly, whether they are still in.

Hours four to twenty-four: get help you can actually reach

This is where most small organizations lose time. The website person does not do email. The email person does not do insurance. Nobody knows who to call at 8 p.m. on a Thursday.

Two calls matter most. First, call your insurance agent and ask specifically whether your policy covers cyber incidents, what the notification requirements are, and whether there is a retained vendor you are supposed to use. Many small commercial policies now include some coverage, and the carrier often has a hotline. Second, get a technical person engaged who handles incidents, not just someone who is good with computers.

If you have never met that person, this is not the moment to shop around. Call someone you already trust and ask who they would call.

Day two: figure out what was actually taken

By the second day the immediate bleeding has usually stopped and the harder questions start.

What accounts were accessed, and what could someone do with them. Whether customer or donor data was exposed, and whose records specifically. Whether money moved, and whether bank or payment accounts need to be alerted. Whether the attackers still have a way back in, which is the question most people skip and most attackers depend on.

Write it down as you go. If you end up needing to notify anyone, this list is the foundation of that notification.

Day three: the decisions nobody wants to make

Three decisions tend to land around the third day.

Whether to pay. Our position is the same as every reputable advisor's: paying funds the next attack and does not reliably get your data back. Whether to notify customers, clients, or members, which is often a legal question and almost always a relationship question, and the answer is frequently yes even when it is not strictly required. And whether to bring in counsel, which for anything touching personal data is worth at least a phone call.

What owners say afterward

The same handful of things come up in almost every account we read.

The downtime hurt more than the ransom figure. The backups existed but had never been tested, and the restores did not work. And nobody had a phone number for the moment it mattered.

Every one of those is fixable in advance, cheaply. That is the whole reason we keep writing about tested backups and a written call list.

If you want to know whether your own organization would survive these three days, that is exactly what our free 30-minute IT review is built to find out. We will tell you plainly what we find, including if the answer is that you are in better shape than you think.