Cyber attack response plan
Cybersecurity February 6, 2026 10 min read

What to Do After a Cyber Attack: First 24‑Hour Response Plan

When minutes matter, your first actions can reduce damage and recovery time. Use this checklist to contain the incident and recover safely.

0–30 minutes: contain

  • Disconnect affected devices from Wi‑Fi/Ethernet (don’t power off unless advised).
  • Disable suspicious accounts and reset admin credentials (use MFA).
  • Stop the spread: isolate servers/shared drives if ransomware is suspected.

30–120 minutes: assess + preserve evidence

  • Document what happened, when, and which systems are impacted.
  • Preserve logs/emails/screenshots. Avoid wiping devices.

2–24 hours: recover safely

  • Restore from known-good backups (test restores first).
  • Patch vulnerabilities and rotate credentials.
  • Enable stronger baselines: MFA, device security, backup monitoring.

If you are in Auckland or working remotely in New Zealand, do not pay a ransom and do not wipe devices until someone has captured evidence. Call your IT provider, your bank if payments were hit, and the Police if money or personal data was stolen. 365wiz can help contain the incident, restore from backup, and lock accounts down the same day where possible.

Related reading

Reduce future incidents with proactive support: Why Managed IT Services Save You Money Long Term.

Need urgent help?

If you suspect ransomware or account compromise, contact us. We’ll help contain, recover, and harden your environment.

Need a hand?

Remote anywhere in New Zealand. We visit in Auckland.