NUURBY:// Technologies

What Should We Do After a Cyberattack?

Just like a first-aid kit matters after an injury, having a clear plan for after an attack matters just as much as trying to prevent one in the first place.

Stay Calm and Don't Panic-Delete

The instinct to immediately shut everything down or delete things can accidentally destroy evidence needed to understand what actually happened — and understanding what happened is what actually prevents it from happening again. Panic makes people erase the exact trail that would tell investigators (or automated tools) how the attacker got in.

Contain It

Disconnect the affected device or account from the network so whatever happened can't spread further, without destroying anything that might be useful evidence. This single step — contain without destroying — is exactly what separates organizations that recover in days from ones that take months, and the data backs this up clearly. Ransomware recovery speeds have genuinely improved industry-wide: only 22% of organizations recovered within a week in 2023, rising to 35% in 2024, and reaching 53–54% by 2025.1 That's a real, measurable shift toward faster containment and recovery, driven by better backup infrastructure and more organizations actually having a tested plan rather than improvising one mid-crisis.

More Organizations Recover Within a Week Every Year
Temporal — share of organizations recovering from ransomware within 1 week
In more technical terms
Containment
Isolating an affected system to stop an incident from spreading, without destroying logs or artifacts that would help explain how it happened.
Runbook / playbook
A predefined, step-by-step response procedure for a specific type of incident — written and rehearsed in advance, so nobody is improvising the first response while under real pressure.
Chain of custody
Careful documentation of who accessed evidence and when, preserving its integrity — important if an incident ever leads to legal action or a formal investigation.
Post-incident review
A structured analysis after recovery, focused specifically on what allowed the incident to happen and what changes would prevent a repeat — the step most often skipped under pressure to just move on.

Automated Response Beats Manual Scrambling

The gap between having a tested, automated response process and improvising one live is bigger than most people expect. Organizations using automated recovery playbooks contained breaches in a median of 51 days, compared to 79 days for organizations without them.2 That's not a marginal difference — it's roughly a month of additional exposure, additional cost, and additional opportunity for an attacker to do more damage, purely from the absence of a plan that already existed and just needed to run.

Automated Playbooks Cut Containment Time Nearly in Half
Comparison — median days to contain a breach

Notify the Right People — Not Just Internally

Who needs to know goes beyond your own IT team. Depending on what was involved, that can include law enforcement, regulators, affected customers, and business partners — and in many places, some of these notifications are legally required within a specific window, not optional or discretionary. Involving law enforcement specifically has a measurable practical benefit too: victims who did so were more likely to avoid paying a ransom at all, since investigators sometimes have decryption tools or intelligence that isn't publicly available. Waiting to notify anyone until you've "figured everything out" usually just burns the notification window without actually buying useful clarity.

Change Passwords, Starting with the Important Ones

Prioritize email and financial accounts first — email especially, since it's often the key to resetting everything else. If ransomware or extortion is involved specifically, one more decision looms: whether to pay. The trend here is encouraging — in 2025, 63% of ransomware victims refused to pay, up from 59% the year before, while the share who paid dropped correspondingly to 37%.3 Law enforcement guidance consistently discourages payment, since paying doesn't guarantee data recovery and directly funds further attacks — and more victims each year are choosing not to.

Fewer Victims Are Paying the Ransom
Part-to-whole — ransomware victims' payment decision, 2025

Learn From It

A good incident response process ends with understanding exactly what happened and what changes would prevent it from happening the same way again — not with everyone simply relieved it's over and eager to move on. Skipping this step is one of the most common, and most costly, mistakes: without a genuine post-incident review, the same gap that let the attacker in the first time is often still sitting there, wide open, for the next attempt.

A real review covers more than just the technical root cause. It should also honestly assess how well the response itself went: were the right people notified quickly enough, did the plan (if one existed) actually match what the situation needed, and how long did each stage genuinely take compared to what was assumed going in. This is uncomfortable to do well, since it means examining decisions made under pressure with the benefit of hindsight — but it's exactly that discomfort that makes the next response faster and more effective than this one was.

What This Actually Means for You

The single biggest factor separating a costly, drawn-out incident from a contained, manageable one is whether a real plan existed before it happened. A few practical takeaways:

Sources
  1. Sophos State of Ransomware, cited via totalassure.com, 2025
  2. Halcyon research, cited via cnicsolutions.com, 2026
  3. Fortinet Ransomware Stats, cited via brightdefense.com, 2026

This is precisely what automated incident response means — a real playbook that runs the moment something is detected, not a scramble to figure it out after the fact.