top of page

Hit by a cyberattack? What to do in the first hour

Writer: Jeremy
Jeremy
28 minutes ago
6 min read

If a cyberattack hits your business, the first hour decides how bad it gets.


It's also the hour where most of the expensive mistakes happen. Someone powers off the wrong machine and wipes the evidence. Someone deletes the ransom note to stop people panicking. Someone emails the whole team about the breach from the very inbox the attacker is sitting in, reading along.


None of that comes from carelessness. It comes from wanting to fix it right now, which is the correct instinct and the wrong first move.


Here is the order to work in, so you're not making it up under pressure. None of it requires technical skill. The technical part is your IT provider's job - this is the part that's yours.


Before you touch anything


Four things not to do, because each one costs you something you can't get back.

  • Don't power the machine off if you can avoid it. Pull the network cable and switch off Wi-Fi instead. Shutting a computer down wipes what's held in memory, and that's often where the answer to "how did they get in, and are they still in?" lives.

  • Don't delete anything. The ransom note, the phishing email, the odd alert nobody could explain last Tuesday - leave all of it exactly where it is. That's the evidence your IT team, your insurer, and possibly the police will work from.

  • Don't pay a ransom in the first hour. That decision has more moving parts than it looks like. More on it below.

  • Don't discuss the attack in a compromised account. If an attacker is in your email or your Teams tenant, they can read your incident response as you type it. Move to phone calls, or to an account and a device you know are clean.


The first hour, in order


Start the moment something looks wrong. Work down the list.


  1. Get the affected devices off the network. Unplug the network cable, turn off Wi-Fi. This stops it spreading to the rest of your machines and, this is the one people forget, to your backups. The Canadian Centre for Cyber Security and CISA both say the same thing: isolate rather than power off, and only shut a device down if you genuinely can't get it off the network any other way.

  2. Phone your IT provider. Actually phone them. Don't email, in case your inbox is being read. If you have cyber insurance, they're the next call, and don't skip it - most policies require you to bring their incident response team in early, and some will reduce or deny a claim if you brought in your own people first. Your policy number and their 24-hour line should be somewhere you can reach without your systems.

  3. Leave the scene alone. No wiping, no reinstalling, no tidying up. Take screenshots of the ransom note and the suspicious emails by all means, but keep the originals. A rebuilt machine is a machine nobody can learn anything from, and if you're making an insurance claim, it's also the evidence gone.

  4. If money went out the door, call the bank now. Ask them to recall the transfer and freeze the receiving account. This one is measured in hours, not days - funds move through intermediary accounts quickly, and the odds drop with every one. Call the bank first, then report it (see below).

  5. Reset passwords from a device you trust. Start with email and any admin accounts, and do it from a machine you're confident isn't affected. Turn on multi-factor authentication anywhere it isn't already. Resetting a password from a compromised computer just hands the attacker the new one.

  6. Report it. It helps you recover, it's sometimes legally required, and in Alberta there's a specific place to do it.


Where to report it in Alberta


Most articles on this topic were written for an American audience, which is not much help in Calgary. Here's the Canadian version.


Report the crime. File at reportcyberandfraud.canada.ca, the joint RCMP and Canadian Anti-Fraud Centre portal, or call the CAFC at 1-888-495-8501 (Monday to Friday, 10:00 a.m. to 4:45 p.m. Eastern). The CAFC is clear that you should also contact your local police - the Calgary Police Service if you're in the city, your local RCMP detachment through much of Southern Alberta. Local police investigate; the CAFC holds the central intelligence picture that connects your incident to others.


Report the incident. Organizations can report cyber incidents to the Canadian Centre for Cyber Security at cyber.gc.ca. This is separate from reporting the crime, and it's how the national picture gets built.


Report the privacy breach, if there was one. This is the part with legal deadlines attached, and the rules that apply to you depend on how your business is regulated:


  • Most Alberta businesses fall under Alberta's Personal Information Protection Act (PIPA). If a breach creates "a real risk of significant harm" to anyone, you must notify the Office of the Information and Privacy Commissioner of Alberta without unreasonable delay (s. 34.1). The Commissioner can then require you to notify the people affected - though in practice most organizations notify them first, without waiting to be told.

  • Federally regulated businesses - banks, airlines, telecoms - and personal information crossing provincial or national borders fall under PIPEDA. Same threshold, real risk of significant harm; report to the Privacy Commissioner of Canada as soon as feasible, notify the affected individuals, and keep a record of every breach for two years, including the ones you decided didn't need reporting.


If you also serve customers in the US, the UK, or the EU, you may have notification duties there too, and some of those clocks are shorter. That's a conversation to have with your lawyer early, not on day three.


Should you pay the ransom?


The FBI's position, and the Canadian Centre for Cyber Security's, is that you shouldn't. Paying doesn't guarantee your files come back, it marks your business as one that pays, and the money funds the next attack.


It's still your call - but it's a call to make with your incident response team, your insurer, and law enforcement, not alone at 11 p.m. on the first night. There's also a practical reason to wait: for some ransomware strains a free decryption tool already exists. Paying for a key that's available for nothing is a bad afternoon.


The version of this you can control

Everything above is easier if some of it was decided in advance. You don't need an incident response binder. For most small businesses one page covers it:


  • Who you call first, and their numbers, somewhere you can reach without your systems. Your IT provider's after-hours line, your insurer's 24-hour claims line, your account manager at the bank. Printed, or in your phone. Not in a document on the server that just got encrypted.

  • Where your backups are, and the date you last restored from one. A backup nobody has tested is a hypothesis, not a backup.

  • Which accounts and systems matter most, so the first hour isn't spent arguing about what to protect first.


One page, reviewed twice a year. That's the difference between a bad week and a very bad quarter.

If you'd like a hand putting that page together for your business, talk to us - Summit Systems works with businesses across Calgary and Southern Alberta, and we'd rather help you write it now than help you find out you needed it.


Frequently asked questions

What's the first thing to do in a cyberattack?

Disconnect the affected devices from the network, unplug the network cable and turn off Wi-Fi , then phone your IT provider. Getting the device off the network stops the attack spreading to your other computers and your backups while you wait for help.


Should I turn off the computer if I get ransomware?


No, if you can avoid it. Disconnect it from the network instead. Powering a machine down wipes evidence held in memory that helps determine how the attackers got in and whether they're still there. Only shut a device down if there's no other way to get it off the network.


Should I pay the ransom?


The FBI and the Canadian Centre for Cyber Security both advise against it. Paying doesn't guarantee your data comes back and it funds further attacks. Make the decision with your incident response team, your insurer, and law enforcement - and check whether a free decryption tool already exists for that strain.


We wired money to a scammer. What do we do?


Call your bank immediately and ask them to recall the transfer and freeze the receiving account. Then report it to the Canadian Anti-Fraud Centre at 1-888-495-8501 or reportcyberandfraud.canada.ca, and to your local police. Recovery odds fall sharply after the first few hours.


Who do I report a cyberattack to in Canada?


Report the crime to the Canadian Anti-Fraud Centre and your local police - the Calgary Police Service or your RCMP detachment. Organizations can report the incident to the Canadian Centre for Cyber Security. If personal information was exposed, most Alberta businesses must also report to the Office of the Information and Privacy Commissioner of Alberta under PIPA.


Do I have to tell my customers about a data breach in Alberta?


If the breach creates a real risk of significant harm, you must report it to Alberta's Information and Privacy Commissioner without unreasonable delay, and the Commissioner can require you to notify the individuals affected. Most organizations notify affected people themselves rather than waiting. Federally regulated businesses follow PIPEDA instead.


Article adapted with permission from The Technology Press.

Comments


Commenting on this post isn't available anymore. Contact the site owner for more info.
bottom of page