how-to
Recover From a Cyber Attack: Small Business Guide
Table of Contents
- Immediate Steps When You Discover a Cyber Attack
- Containment Strategies to Stop the Threat
- How to Restore Business Data From Backups
- Creating a Cyber Incident Response Plan Template
- Data Breach Notification Requirements and Compliance
- Forensic Analysis and Root Cause Investigation
- Rebuilding Security Posture After Recovery
- Frequently Asked Questions
Last Updated: September 22, 2026
Immediate Steps When You Discover a Cyber Attack
Panic is natural when your business is compromised, but action, not panic, will help you recover from cyber attack. Pause for 60 seconds to regain mental clarity; your decisions in the next few hours will determine whether you contain the damage or worsen it. Acknowledge the stress, then shift into structured response mode.
The first hour: Stabilize your mind and your network
Your first hour determines whether you make sound decisions or reactive ones you'll regret.
Isolate affected devices immediately, disconnect them from the network but do not shut them down; forensic investigators need to examine them running. Write down what you know: when you noticed the problem, what alerted you, and which systems are affected. This record prevents you from forgetting critical details under stress.
Change all passwords from a clean device (personal laptop, phone, or tablet from home). Create strong passwords: at least 16 characters mixing uppercase, lowercase, numbers, and symbols. Start with email, then critical business accounts. Go slowly and verify each one.
Alert your IT team or managed service provider immediately. If you don't have an MSP, call a local IT support company now. Provide them with the information you documented and let them lead on technical decisions.
Document a timeline: discovery time, affected systems, actions taken, and notifications made. Preserve evidence by not shutting down systems or attempting cleanup yourself; moving files or running scans destroys evidence and increases recovery costs.
Key actions in the first hour:
- Isolate compromised computers from the network
- Change passwords from a clean device
- Notify your IT support team or managed services provider
- Document the discovery time and affected systems
- Preserve evidence by not shutting down systems yet
- Write down your observations while they're fresh
- Delegate technical decisions to your IT team

Containment Strategies to Stop the Threat
Containment stops the attack from spreading. Segment your network to prevent lateral movement. Disable remote access tools (VPN, Remote Desktop Protocol) temporarily to limit attacker movement. Review user access logs, identify compromised accounts, and disable them immediately.
Containment checklist:
- Isolate infected systems from the network
- Segment your network to prevent lateral movement
- Disable remote access services temporarily
- Disable compromised user accounts
- Block suspicious IP addresses at your firewall
- Monitor remaining systems for new activity
VegaMSP's endpoint security and fully managed network services provide real-time monitoring, identifying compromised accounts and blocking malicious traffic.
How to Restore Business Data From Backups
This is where your data backup strategy either saves you or costs you everything.
Verify your most recent backups were not infected before restoring. Ransomware can sit dormant in backups for weeks, so a recent backup may be compromised. Connect backup drives to isolated computers and scan for malware before restoring. For cloud backups, ask your provider to verify integrity or provide a forensic scan.
Identify the oldest clean backup. For daily backups, restore from the day before detection. For weekly backups, you may lose several days of data, this is why frequent backups matter. Work with your IT team or forensic investigator to determine the attack timeline if unsure.
Restore to isolated systems first, not directly to production. Verify restored data is clean before bringing it back online to prevent re-infection.
Platform-specific restoration steps:
Microsoft 365 (Exchange Online, OneDrive, SharePoint):
- Use the Microsoft 365 admin center to restore deleted items from the recycle bin (available for up to 93 days)
- For mailboxes, use In-Place eDiscovery to recover deleted emails
- For OneDrive, use the version history feature to restore files to a previous state (available for up to 93 days)
- If ransomware encrypted files in SharePoint, restore the entire site from a backup if available through your backup solution
- Contact Microsoft Support if you need recovery beyond the 93-day window
Google Workspace (Gmail, Drive, Docs):
- Use Google Vault to recover deleted emails and chat messages (retention depends on your policy)
- For Google Drive, use version history to restore files to a previous version
- If an entire Drive folder was encrypted, restore from your backup solution (Google does not provide native folder-level recovery)
- Enable Google Drive's trash recovery feature to restore deleted files within 30 days
Local servers and on-premises systems:
- Restore from your most recent clean backup to a separate server or isolated network segment
- Verify file integrity and scan for malware before connecting to production
- If you use Windows Server, use Windows Server Backup or a third-party backup solution to restore to a point-in-time before the attack
- For databases (SQL Server, MySQL), restore to a test environment first, verify data integrity, then promote to production
Offsite and cloud backup best practices:
- Offsite backups are essential. If your backups live on the same network as your servers, ransomware can encrypt those too
- Use immutable backups (backups that cannot be deleted or modified, even by an administrator) to prevent ransomware from destroying your recovery point
- Test your backup restoration process quarterly, do not wait for a breach to discover your backups are corrupted or incomplete
- Maintain at least one backup that is completely disconnected from your network (air-gapped) for maximum protection
Backup restoration checklist:
- Verify backup integrity before restoring
- Identify the most recent clean backup (work with IT or forensics if unsure)
- Restore to isolated systems first
- Scan restored data for malware
- Test critical business functions (email send/receive, file access, database queries)
- Verify data is complete and not corrupted
- Gradually restore to production systems
- Monitor restored systems for 48 hours for signs of re-infection
The cost of backups is always less than the cost of losing data or paying ransom.
Creating a Cyber Incident Response Plan Template
You cannot respond effectively to something you have not planned for. A cyber incident response plan template gives your team a playbook.
Name an incident commander to make decisions and coordinate between IT, management, legal, and customer service.
Elements of a cyber incident response plan:
- Incident commander and decision-making structure
- Contact list for IT, legal, insurance, and law enforcement
- List of critical systems and data
- Communication templates for customers and regulators
- Recovery time objectives for each critical system
- Roles and responsibilities for each team member
- Steps for forensic analysis and evidence preservation
Data Breach Notification Requirements and Compliance
The moment you confirm a breach, you may have legal obligations to notify people. These requirements vary by state and industry.
Notification requirements typically include:
- Notification to affected individuals
- Notification to state attorneys general
- Notification to credit bureaus in some cases
- Documentation of your notification efforts
- Regular updates to affected parties
Forensic Analysis and Root Cause Investigation
After you stabilize the situation, you need to understand what happened. Forensic analysis answers three questions: How did they get in? What did they access? How do we prevent this in the future?
Forensic analysis typically reveals:
- The initial entry point
- Timeline of the attack
- Systems and data accessed
- Whether data was exfiltrated
- Tools and techniques used by the attacker
- Vulnerabilities that enabled the breach
Rebuilding Security Posture After Recovery
To fully recover from cyber attack, you must fix the vulnerabilities that allowed the breach. This is where you rebuild your security posture.
Post-recovery security improvements:
- Enable multi-factor authentication on all critical accounts
- Patch all software and systems
- Review and reduce user access permissions
- Implement endpoint security software
- Enable security logging and monitoring
- Conduct security awareness training for all employees
- Review and strengthen password policies
- Consider cyber insurance coverage
Frequently Asked Questions
What is the first thing to do when you discover a cyber attack?
Isolate affected systems immediately by disconnecting them from your network to prevent the threat from spreading. Alert your incident commander and key personnel, then preserve evidence by documenting what you observe without altering files. Contact your managed service provider or IT team right away. Avoid shutting down systems without guidance, as this may destroy forensic data needed to understand the breach. Speed matters, the first hour determines whether you contain the attack or watch it expand across your infrastructure.
How long does it typically take for a small business to recover from a cyber attack?
Recovery time depends on attack severity, backup quality, and response speed. Simple ransomware containment may take 24-48 hours; data restoration from backups typically requires 3-7 days for small businesses. Comprehensive forensic analysis and security hardening can extend recovery to 2-4 weeks. Having offsite backups and a documented cyber incident response plan template cuts recovery time significantly. Without proper backups, recovery stretches to weeks or months, and some data may be unrecoverable, making prevention through multi-factor authentication and regular security audits far more cost-effective than recovery.
What are data breach notification requirements for small businesses?
You must notify affected individuals without unreasonable delay under state breach notification laws. Most states require notification if personal information was accessed or reasonably believed to have been acquired. Federal laws like HIPAA (healthcare) and GLBA (financial services) impose stricter timelines, typically 30-60 days. Your notification must include what data was exposed, steps you are taking, and resources available to affected parties. Some states require notifying the state attorney general. Check your state's specific law and industry regulations. Document all notifications and timing for regulatory compliance.
Should we invest in cyber insurance after a breach?
Yes. Cyber insurance covers incident response costs, forensic investigation, legal fees, notification expenses, and potential liability claims. Premiums are typically lower after you implement security improvements like multi-factor authentication and endpoint security. For small businesses, cyber insurance is a critical part of business continuity planning alongside technical defenses. After a breach, obtaining coverage becomes more expensive and may exclude future incidents of the same type. Cyber insurance complements but does not replace strong security posture, it covers what prevention cannot eliminate entirely.