Journey
Respond to a cyber attack
Emergency guidance for businesses experiencing a cyber attack. Immediate containment steps, who to report to, and what to do if personal data is affected.
A cyber attack requires immediate action to limit damage and meet your legal reporting obligations. This journey guides you through the critical first steps.
-
Contain the attack
Your first priority is stopping the attack from spreading. Disconnect affected devices from your network but do not turn them off - forensic evidence may be lost.
If you have backups on separate systems, verify they have not been compromised before using them.
-
Report the incident
You may need to report to multiple authorities depending on what happened. Act quickly - the ICO requires notification within 72 hours if personal data is affected.
Report a cyber incident
Who to contact, what information to provide, and your legal deadlines
-
If personal data was affected
Customer or employee data accessed, stolen, or encrypted by ransomware triggers additional legal obligations under UK GDPR.
Respond to a data breach
The 72-hour ICO rule, when to notify individuals, and documentation requirements
-
Get professional help
For serious incidents, use an NCSC-assured Cyber Incident Response provider. Your cyber insurance may also provide incident response support.
-
After the immediate crisis
Once contained, review what happened and strengthen your defences to prevent recurrence.
Cyber security requirements
Protect against future attacks with Cyber Essentials and security controls