Cyberattack response planning illustration

If you suspect a cyberattack, start by stopping it from spreading. Then preserve what happened, report the incident under your policy, and bring in the people who can help with the technical and legal work.

You don’t need to solve the whole problem in the first hour. You do need to keep a bad situation from getting worse.

The First Hour: Contain, Document, And Call For Help

  1. Isolate affected systems. Disconnect suspicious devices from Wi-Fi and wired networks. If several systems appear affected, call your IT team, managed service provider, or an incident-response firm.
  2. Preserve what you see. Photograph ransom notes or error messages, record the discovery time, and keep a factual incident log. Do not delete messages, logs, or files.
  3. Do not reboot by default. CISA notes that powering down can lose volatile-memory evidence. Power down only if a device cannot otherwise be disconnected and further spread is the immediate concern.
  4. Notify your carrier or broker promptly. Use the reporting instructions in your policy before committing to outside forensic, legal, or remediation vendors.

Step 1: Contain The Incident Without Making It Worse

Start by separating suspected systems from the network. For ransomware or an active intrusion, CISA recommends determining which systems are affected and immediately isolating them. If it is not feasible to take a network offline, unplug Ethernet connections or remove affected devices from Wi-Fi. Use the phone or another out-of-band method to coordinate the response when possible.

Do not wipe, reimage, or casually restart affected devices. Logs, memory, and other records can help qualified responders determine what happened and what data may be involved. If cloud resources may be affected, talk with your IT team before changing configurations. A point-in-time snapshot may help preserve evidence for later review.

Step 2: Activate Your Cyber Liability Response

Check your policy’s reporting instructions, then tell the carrier or your broker about the incident as soon as you can. Cyber policies often spell out how forensic firms, breach counsel, notification vendors, or extortion specialists are brought in. Calling before you approve outside work can prevent confusion about the process and the bill.

Prepare A Short Incident Summary

  • When and how the incident was discovered.
  • The devices, accounts, applications, or data that may be involved.
  • Known operational impacts, such as downtime, locked files, suspicious transfers, or customer reports.
  • Containment actions already taken.
  • The names and contact details of your internal IT lead and any managed service provider.

Your carrier may send you to an approved forensic firm, breach counsel, or another response specialist. Coverage, limits, exclusions, and vendor requirements come from your specific policy. Check the policy and claim guidance before you assume a cost is covered.

Step 3: Secure Accounts From A Known-Clean Device

Once the affected systems are separated, close the doors an attacker may still use. Start with administrator accounts, email, remote access, cloud-storage access, financial systems, and third-party applications. Work with your IT responders on the order.

  • Reset critical credentials from a known-clean device.
  • Revoke suspicious sessions, app passwords, and access that is no longer needed.
  • Enable multi-factor authentication for critical accounts where it is not already in place.
  • Review mailbox-forwarding rules, privileged accounts, remote desktop access, and recent changes to financial-payment instructions.

Step 4: Keep A Claim And Recovery Record

Create one access-controlled incident log. Record decisions, dates, contacts, downtime, invoices, overtime, and vendor work. Keep copies of relevant communications and do not speculate about the cause or scope before the facts are established.

This record helps the response team keep the work straight and may support a claim for eligible response costs or business-interruption losses. If your accounting system allows it, use a separate code or project label for incident expenses.

Step 5: Treat Ransomware And Extortion As A Legal And Technical Response

Do not negotiate with threat actors, click links in ransom messages, or authorize a payment on your own. The FBI does not support paying a ransom because payment does not guarantee data recovery and may encourage further attacks. The U.S. Treasury warns that ransomware payments can create sanctions risk when a sanctioned person or group is involved.

If ransomware is involved, bring in breach counsel, follow the insurer’s reporting process, and use the technical specialists assigned or approved for the claim. They can investigate the incident, assess recovery options, and help decide whether to report it to law enforcement. The FBI’s Internet Crime Complaint Center accepts reports from businesses affected by ransomware, data breaches, and intrusions.

Arizona Businesses: Data-Breach Notification May Be Required

Stopping an intrusion does not by itself resolve privacy obligations. Under Arizona’s data-breach notification law, a business that determines a covered security-system breach has occurred generally must notify affected individuals within 45 days after that determination. For breaches involving more than 1,000 Arizona residents, the law also requires notice to the Arizona Attorney General, the Arizona Department of Homeland Security, and the three largest nationwide consumer reporting agencies.

What you must do depends on the data involved, the facts of the incident, and the laws that apply. Have breach counsel review the situation before notices go out. The Arizona Attorney General provides a data-breach notification FAQ and submission form.

Step 6: Restore Carefully And Learn From The Incident

Recovery should follow the investigation, not just the calendar. NIST’s current incident-response guidance emphasizes verifying restoration assets before use, prioritizing recovery actions, checking restored systems for indicators of compromise, and documenting lessons learned. Before bringing systems back online, confirm that backups are clean, root causes have been addressed, and the restored service can operate safely.

After the immediate crisis, update the incident-response plan, test backups, review privileged access, improve multi-factor authentication, and schedule employee awareness training. Write down what happened, what slowed the team down, and which safeguards need work.

Need Help Reviewing Cyber Risk?

Learn more about cyber liability insurance or contact PJO Insurance Brokerage to talk through coverage and risk-management options for your business.

Frequently Asked Questions

Should We Turn Off An Infected Computer?

First try to isolate it from the network. CISA notes that powering down can lose volatile-memory evidence, but it may be necessary if you cannot otherwise disconnect the device and continued spread is the immediate risk.

How Fast Should We Notify Our Cyber Insurer?

Review the policy and report the incident promptly. The policy may include specific notice requirements and directions for engaging approved vendors.

Do Arizona Businesses Have A Data-Breach Deadline?

Arizona law generally requires notice to affected individuals within 45 days after a covered breach is determined. Legal counsel should confirm how the law applies to the facts of a particular incident.

Should We Pay A Ransomware Demand?

Do not make that decision alone. The FBI does not support paying ransoms, and Treasury warns of potential sanctions risk. Involve qualified legal, technical, and insurance professionals.

Sources For Further Guidance


This article provides general educational information only. It is not legal, cybersecurity, insurance-coverage, or claims advice. During an active incident, follow your policy requirements and consult qualified legal, technical, and insurance professionals.

PJO logo

PJO INSURANCE BROKERAGE
Email: patrick@pjobrokerage.com
Website: www.pjobrokerage.com

Arizona Location
4103 East Prickly Pear Trail
Phoenix, Arizona 85050

Office: 480-680-9951

California Location
107 Via Estrada, Unit A
Laguna Woods, California 92637

Office: 949-264-0889

Nevada Location
9850 S Maryland Parkway Suite A-5-262
Las Vegas, Nevada 89183

Office: 702-747-5403