What Should You Do First After a Hack?
The moment you realize your network has been compromised, your instinct is probably to start clicking around and trying to fix it yourself. Resist that instinct, whether it’s a ransomware note on every screen, a flood of odd login alerts, or a call from a customer asking why they received a strange invoice. What you do in the first sixty minutes after discovering a hack has a direct effect on how much damage the incident causes and how quickly your business gets back to normal.
For a manufacturer in Warren or a professional services firm in Cleveland, that first hour usually determines whether this becomes a contained, manageable event or a multi-week disruption. You can’t solve everything immediately. You need to stop the bleeding and preserve what your response team will need later.
At a high level, your first moves should be:
- Contain the threat: Disconnect affected devices from the network (unplug the ethernet cable or disable Wi-Fi) rather than shutting them down completely.
- Don’t touch the evidence: Avoid restarting machines, deleting files, or running your own cleanup tools before your incident response team has looked at what happened.
- Call your IT or security provider immediately: If you have a managed security partner, this is the call that matters most. If you don’t, this is the moment to find one.
- Loop in leadership: Whoever owns legal, financial, and customer-facing decisions needs to know now, not after the situation is contained.
Everything else, from forensic investigation to customer notification, follows from how well you handle these first steps.
What Steps Should You Take After Discovering a Data Breach?
The first steps after discovering a data breach are to isolate affected systems, preserve evidence, and bring in qualified help before making any other decisions. Disconnect compromised devices from the network immediately, but leave them powered on. Turning a machine off can erase the memory-resident evidence that investigators need to understand how attackers got in.
Next, change passwords for any accounts you suspect were involved. Start with administrator and financial system credentials, but do this from a device you know is clean. Document what you’re observing. Include timestamps, error messages, screenshots, and anything unusual employees noticed in the hours before discovery.
Then contact your incident response provider, your cyber insurance carrier, and legal counsel, in roughly that order. Your insurance policy may require specific vendors or notification timelines. Involve the carrier early rather than after decisions are already made. Avoid making public statements or notifying customers until you understand the scope of what happened. Premature or inaccurate communication can create more problems than it solves.
Why Are Small and Mid-Sized Businesses Now Bigger Targets?
Many business owners still assume attackers only go after large corporations with deep pockets. That assumption doesn’t hold up anymore. Small and mid-sized businesses are now attractive targets precisely because they tend to have weaker defenses and fewer dedicated security staff than a Fortune 500 company. This is true even while they’re still holding valuable data and processing real money.
Attackers have also gotten faster. In the many aggressive cases, attackers now move from initial access to stealing data in about less than two hours. This leaves almost no window for a business to notice and respond manually. Most breaches trace back to preventable gaps too, like unpatched software or weak remote access controls (rather than sophisticated new techniques). That’s a meaningful detail for any Cleveland or Warren business owner who assumes a breach requires an unusually skilled attacker.
What Does Recent Ransomware Research Show?
The data on small business breaches makes the notion that some businesses are too small to be a target even harder to defend. A 2025 report from Verizon found that small businesses had roughly four times as many confirmed breach victims as large organizations. Ransomware showed up in 88% of small business breaches, compared to 39% among large enterprises.
The cost of getting this wrong keeps climbing too. A 2025 IBM report, based on research conducted with the Ponemon Institute, put the global average cost of a breach at $4.44 million. That’s with organizations taking an average of 241 days to identify and contain a breach. For a small or mid-sized business without dedicated security staff, this kind of timeline can be the difference between a manageable setback and a business-ending event. This is a big part of why more businesses in the Cleveland area are moving toward managed security built for continuous monitoring.
Should You Pay the Ransom?
There’s no single right answer, but the trend among businesses is moving away from paying. The aforementioned Verizon report found that a majority of ransomware victims now refuse to pay. This is a shift from just a few years ago, when payment was far more common.
There are practical reasons behind that shift. Paying doesn’t guarantee you’ll get a working decryption key. It doesn’t guarantee attackers won’t leak your data anyway or come back for a second payment either. Law enforcement agencies generally discourage payment because it funds further attacks. It doesn’t remove stolen data from circulation either.
That said, this decision should never be made alone or under pressure in the moment. Talk to your legal counsel, your cyber insurance carrier, and your incident response provider together before deciding anything. Some cyber insurance policies have specific requirements around ransom negotiations. Paying without following those requirements can affect your coverage. The right call depends on:
- what exactly was taken
- whether you have clean backups to restore from
- how critical the affected systems are to keeping your business running
What Should You Know About Notifying Customers After a Breach?
Businesses generally have legal obligations to notify affected customers, employees, or partners after a data breach. The specific requirements, however, depend heavily on your state, your industry, and what type of data was involved. These obligations often come with strict timelines and specific language requirements. This isn’t something to draft on your own after reading a blog post.
Bring your legal counsel into the conversation as soon as you understand the scope of the breach. Your cyber insurance carrier should be involved at the same stage, since many policies include breach coaching and notification support as part of the coverage, and some require you to use approved vendors to remain compliant with your policy terms.
Because notification laws vary by state and change over time, and because different industries (healthcare, finance, and government contractors, among others) carry additional requirements on top of general state law, treat this as a legal question with a legal answer. Don’t just handle it internally. Getting the timing or content of a notification wrong can create liability that outlasts the original breach.
Why Build a Response Plan Ahead of Time
The businesses that recover fastest from a hack are rarely the ones that were never targeted. They’re the ones that had already decided, calmly and in advance, who to call and what to do first. It’s recommended to write an incident response plan and to rehearse it before an incident happens. (A plan you’ve never tested is a plan you cannot count on when it matters most.)
We consistently hear from clients that what they value most is knowing there’s a live, known local team to call the moment something looks wrong (instead of an anonymous call center reading from a script). That’s the difference between having managed IT and simply having IT.
If your business doesn’t have a documented response plan yet, that’s the place to start. Whether you’re building one from scratch or strengthening what you already have, our cybersecurity services, co-managed IT services, and managed IT services are built around exactly this kind of preparation, so a hack becomes a contained incident instead of a crisis.
TL;DR: Responding to a Network Hack
The first hour after a hack determines whether it stays a contained incident or turns into a multi-week disruption.
Contain First, Decide Second:
- Disconnect affected devices but leave them powered on, and call your IT or security provider right away.
- Loop in leadership immediately so legal, financial, and customer decisions don’t get made in isolation.
Ransom and Notification Aren’t DIY Decisions:
- Most businesses now refuse to pay a ransom, and doing so without following your cyber insurance policy can affect coverage.
- Notification requirements depend on your state and industry, so legal counsel and your insurance carrier need to be involved early.
