What to do when a cyber attack hits your business (in plain English)

The National Cyber Security Centre published new guidance in late July on recovering from a disruptive cyber attack. It’s genuinely good advice, but it’s written for organisations with a CISO, a Board and a dedicated IT team. If you run a smaller business, some of it won’t map onto your world at all. Here’s what it actually means for you, and where the guidance falls short if you don’t have fifty people to call on.

Infographic showing a 3-step plan for cyber incident response: first hours to stabilise and assess by deciding who's in charge, bringing in specialists, and reporting to the NCSC; days and weeks to recover safely by restoring essentials, using workarounds, and keeping people informed; and months ahead to rebuild stronger by fixing root causes and capturing lessons learned.

Your cyber attack response plan: the first few hours

The first thing to sort out is who’s actually making decisions. It sounds obvious, but in the panic of an incident, decisions get made by whoever’s shouting loudest, or don’t get made at all. Pick one person, even if that’s just you, and make sure everyone knows to check with them before switching anything off or telling a customer anything.

Get help fast. The guidance talks about engaging an assured incident response provider, which for a large organisation means a specialist firm on retainer. For most small businesses, that starts with a call to your existing IT support and asking them directly: is this beyond what you can handle, and who do you know who specialises in this? Don’t be embarrassed to ask. Attacks like this are exactly what specialist help exists for.

Work out what’s actually broken, as opposed to what’s merely inconvenient. Which systems do you need to serve customers today? Which can wait? And check your legal position early: if personal data is involved, you may have 72 hours to notify the ICO under UK GDPR. It’s also worth reporting the incident to the NCSC directly, which is free and doesn’t replace any other legal reporting you’re required to do, but can get you expert guidance quickly.

The days and weeks that follow

Here’s the most reassuring part of the whole document, once you strip out the jargon: you don’t need everything back at once. The guidance calls this recovering to ‘minimum viable operations’, which really just means getting the essentials running safely rather than restoring everything perfectly in one go. If you can take orders, pay your staff, and keep your core promise to customers, you’re in a workable position even if half your systems are still down.

The guidance describes separate workstreams for communications, legal, HR, customer relations and finance, each with its own lead. In a small business, that’s realistically one or two people juggling all of it at once. If that’s you, be honest about the limits of what you can do in a day, and lean on outside help where you can: your accountant for the financial side, your insurer if you have cyber cover, a trusted contact for anything legal.

Keep customers and staff briefed, even when there’s not much to say yet. Silence gets filled with speculation. And build in some slack for the timeline: recovery from a disruptive attack almost always takes longer than expected, often weeks rather than days, so set expectations accordingly with anyone waiting on you.

The months ahead

Once the immediate pressure is off, resist the urge to just patch things up and move on. Take the time to understand what actually let the attack happen, and fix that properly rather than the symptom in front of you. This is also the point to look after the people who carried you through the incident, not just the systems. Recovery takes a toll, and burnout among the people who stepped up is a real risk if it goes unacknowledged.

Write down what you learned while it’s fresh, even briefly. What would have helped you respond faster? What did you wish you’d had in place beforehand? That record is worth more to your future self than any amount of good intentions after the event.

None of this needs a security team or a six-figure budget. It starts with knowing which of your systems truly matter and what you’d do without them, which is exactly what a business impact analysis sets out to answer, and it’s a lot easier to think through calmly before an incident than during one.

Share The Post

Helen Molyneux Director RiskReady

Helen Molyneux is the founder of Cambridge Risk Solutions, a specialist resilience consultancy with nearly two decades of experience in business continuity, crisis management and information security. She holds Lead Auditor certifications for ISO 22301 and ISO 27001, and has worked across both public and private sectors helping organisations prepare for, respond to, and recover from disruption. RiskReady is her e-learning platform, built to make that same practical expertise accessible to individuals and teams at every level.

Find out more about Cambridge Risk Solutions →

Leave a Comment

Your email address will not be published. Required fields are marked *