← Back to blog

2026-09-27 · Security Basics

First 60 Minutes After a Cyber Incident: A Self-Help Checklist for Small Businesses

A calm, printable checklist for the first hour after a suspected cyber incident at a 5–50 person business: isolate the device, keep the evidence, call the right people, and report.

This is a first-hour checklist, not a recovery plan.

If you see a ransom note, locked files, a bank alert, or a mailbox you can't open, slow down, write down what you see, and call for help.

It's for businesses of about 5–50 people. CISA (the Cybersecurity and Infrastructure Security Agency) publishes the #StopRansomware Guide with a response checklist. NIST (the National Institute of Standards and Technology) SP 800-61 Rev. 3, Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile (April 2025) supersedes Rev. 2 (August 2012) under a new title. This page covers the first hour only. It is not legal advice, insurance advice, or a promise that files or money come back.

What should a small business do in the first 60 minutes after a suspected cyber incident? Write it down, isolate without wiping, call by phone, keep the logs, lock admin and bank accounts from a clean device, and report.

Minute 0–5: Write down what you see

What do I write down first? The time, the device, and the words on the screen.

Stop clicking. Don't open more files, and don't run a cleanup tool you found in a search.

Capture the facts

On paper, write the time, the computer or phone, who was signed in, and the screen text, including any ransom note or new payee at the bank. Note if others see the same thing. The CISA guide starts by naming which systems were impacted. Leave blanks as unknown.

Photograph the screen

Use a personal phone, and catch the on-screen clock if it shows. Don't send the photo over company email or chat.

  • Time, device, and screen text written down
  • Screen photographed on a personal phone
  • Photo kept off company email and chat
  • No extra clicks on the affected machine

Minute 5–15: Isolate the device and keep the evidence

How do I limit spread without destroying evidence? Unplug the network cable or turn off Wi-Fi, leave the machine on, and don't wipe or reimage it.

Disconnect from the network

Unplug ethernet or turn off Wi-Fi on every machine showing the same note. If several systems look affected, the #StopRansomware Guide says to take the network offline at the switch. Do that only if you know which cable to pull. Otherwise, call your IT provider. Unplugging one PC does nothing about a cloud admin account.

Leave the power on

By default, don't wipe, reimage, or power off. CISA says to shut a device down only if you can't disconnect it, because shutting down loses evidence in memory. Also shut down if your IT provider or responder tells you to, and write down why. Don't delete the note, emails, or files.

  • Ethernet unplugged or Wi-Fi off
  • Devices left powered on
  • No wipe, reimage, or factory reset
  • Notes, emails, and files still there
  • Any shutdown written down, with the reason

Minute 15–30: Call on a phone, not on company email

Who do I call, and from where? From your phone, or from a computer that wasn't on the affected network. Skip company email and chat.

The guide says to use out-of-band methods such as phone calls. Read them your notes, and if their instructions differ from this page, follow theirs.

Who to call

  1. Your IT provider. Tell them what you unplugged or powered off, and ask them to take over. Question 7 on the IT-host renewal card covers this call on a calm day.
  2. Your cyber insurer, if you have a policy. Use the hotline and follow any steps the policy lists. This page doesn't describe coverage and doesn't tell you to file a claim.
  3. Your bank, if money moved or a payment changed. Don't wait on the affected mailbox.
  4. Your counsel, if you have one. Follow counsel, the insurer, or law enforcement where they instruct you. This is not legal advice.

Do not answer the attacker

Don't pay, reply, or negotiate. A reply tells them a person is there. Keep the note. If it says a copy of your data was taken, deleting local files won't undo that.

The Internet Crime Complaint Center (IC3) says it doesn't work with outside firms to recover money and won't contact you to demand payment. If a stranger asks for a fee, stop.

  • Calls by phone, not company email or chat
  • IT provider called, or an after-hours message left
  • Insurer hotline used if a policy exists
  • Bank called if money or payees changed
  • No payment, reply, or negotiation

Minute 30–60: Lock critical accounts and report

What do I change, and what do I leave alone? From a clean device, change email-admin and banking passwords, confirm multi-factor methods weren't swapped, sign out other sessions, and leave logs in place.

MFA (multi-factor authentication) means a password plus a second step, such as an authenticator app or a security key.

Use a clean device

Use a phone browser or a computer that wasn't on the office network. Change the email admin (Microsoft 365 or Google Workspace), bank, payroll, and password-manager admin passwords there, not on the machine with the note.

Look for a new MFA method, phone number, recovery email, forwarding rule, or unknown session. Sign other sessions out. Don't turn MFA off. If you're locked out, call your IT provider and stop there.

The guide saves the full password reset for after cleanup and rebuild. This hour is about admin and money, and if your IT provider says to wait, wait.

Keep the record

Don't clear logs, mail, or backups, and don't restore onto the office network this hour. The 15-minute backup test is for a calm day.

File the report

Report to CISA, your local FBI field office, or the FBI's IC3. The guide also lists U.S. Secret Service field offices. CISA's Report Ransomware page says one report notifies the other agencies. Use the live forms, since this page isn't a filing instruction. IC3 says to call 911 if a person is in immediate danger, and to file when you're unsure. Write the confirmation number below.

  • Admin and bank passwords changed on a clean device
  • MFA methods and recovery info checked
  • Other sessions signed out
  • Logs, mail, and the note kept
  • No restore onto the affected network
  • CISA or IC3 started; FBI field office noted

One-page printable first hour

Copy or print this table. Leave blanks as unknown. Don't guess.

#MinuteActionDone?Who
10–5Time, device, and screen text written downY / N
20–5Screen photo on a phone, not company emailY / N
35–15Ethernet unplugged or Wi-Fi offY / N
45–15Left on; no wipe, reimage, or default shutdownY / N
55–15Notes, emails, and files not deletedY / N
615–30IT provider called by phoneY / N
715–30Insurer hotline called, if a policy existsY / N
815–30Bank called if money or payees changedY / N
915–30No pay, no reply, no negotiationY / N
1030–60Admin and bank passwords changed on a clean deviceY / N
1130–60MFA and recovery checked; other sessions signed outY / N
1230–60CISA or IC3 started; FBI field office notedY / N

Date: YYYY-MM-DD · Filled by: · Suspected or confirmed:

Save it as first-hour-YYYY-MM-DD alongside your ransomware prep checklist.

Incident notes log

Use one row per thing you saw or call you made. On a calm day, write after-hours numbers for your IT provider, insurer, bank, and counsel beside this log.

TimeWhat you sawWho you calledWhat they told you

Confirmation number: · Devices left on: · Powered off, and why:

What if the calls disagree? Follow counsel, the insurer, or law enforcement when they give instructions. Until then, follow your IT provider. This page does not decide coverage.

After the hour

Rebuilding, restoring, and the wider password reset wait until your IT provider says the affected systems are contained. Use the guides below on a calm day.

Related guides


Educational content only — not legal, insurance, or compliance advice.

Need help implementing this in Houston?

Houston Secure IT can walk through MFA, backups, and a practical baseline with you.

713-364-8666 — Houston Secure IT / shop line