Journey

Respond to a cyber attack

Emergency guidance for businesses experiencing a cyber attack. Immediate containment steps, who to report to, and what to do if personal data is affected.

Running a Business Updated 15 September 2026
5 milestones references 3 guides

A cyber attack requires immediate action to limit damage and meet your legal reporting obligations. This journey guides you through the critical first steps.

  1. Contain the attack

    Your first priority is stopping the attack from spreading. Disconnect affected devices from your network but do not turn them off - forensic evidence may be lost.

    If you have backups on separate systems, verify they have not been compromised before using them.

  2. Report the incident

    You may need to report to multiple authorities depending on what happened. Act quickly - the ICO requires notification within 72 hours if personal data is affected.

    Report a cyber incident

    Who to contact, what information to provide, and your legal deadlines

  3. If personal data was affected

    Customer or employee data accessed, stolen, or encrypted by ransomware triggers additional legal obligations under UK GDPR.

    Respond to a data breach

    The 72-hour ICO rule, when to notify individuals, and documentation requirements

  4. Get professional help

    For serious incidents, use an NCSC-assured Cyber Incident Response provider. Your cyber insurance may also provide incident response support.

  5. After the immediate crisis

    Once contained, review what happened and strengthen your defences to prevent recurrence.

    Cyber security requirements

    Protect against future attacks with Cyber Essentials and security controls