## Datalyst Blog

Datalyst delivers expert managed IT services in Providence, RI. Optimize performance, secure your systems, and grow with us. Contact us today!

 [ Categories ](https://datalyst.directivesites.com/blog/categories "Categories")

 [ Tags ](https://datalyst.directivesites.com/blog/tags "Tags")

 [ Categories:  All Categories ](https://datalyst.directivesites.com/javascript:void(0); "Categories")

 Search...Suggested keywords

 [  x ](https://datalyst.directivesites.com/javascript:void(0);)

 <a class="eb-image-viewport"></a>

#  What to Do in the First 60 Minutes of a Cyberattack

  [Datalyst Blog](https://datalyst.directivesites.com/blog/categories/blog)   [Security](https://datalyst.directivesites.com/blog/categories/security)

  [Daniel Mathieu](https://datalyst.directivesites.com/blog/blogger/daniel-mathieu)

  Wednesday, 13 August 2025

   [ 0 Comments ](https://datalyst.directivesites.com/blog/what-to-do-in-the-first-60-minutes-of-a-cyberattack#comments)

 [ ![What to Do in the First 60 Minutes of a Cyberattack](//datalyst.directivesites.com/images/easyblog_shared/August_2025/08-13-25/b2ap3_large_TimeIT46624263_400.jpg) ](//datalyst.directivesites.com/images/easyblog_shared/August_2025/08-13-25/TimeIT46624263_400.jpg "What to Do in the First 60 Minutes of a Cyberattack")

Cyberattacks are not to be underestimated. The damage that they can do—even in the first hours—is considerable. This means you need to have a strategy to respond to these incidents, conveniently called an incident response plan.

This procedure should be both tested and documented, preparing you to withstand any cyberattack with minimal damage or disruption. As you might expect, the first hour or so will be a crucial period during this process. Let’s go over what you need to do.

## Essential Actions to Take in the First 60 Minutes of a Cyberattack

To be clear, this is not the stage at which you should try to fix everything. This is when you need to be in damage control mode and prepare your recovery measures.

### What You Need to Do:

**Contain the Threat** Before anything else, you need to keep whatever it is that’s impacting your systems from spreading further. That might mean [shutting down a server](https://datalyst.directivesites.com/it-services/hardware-services/server-migration) or disconnecting a workstation from the network. Once you’ve stopped the spread of the attack, you can move on to the next step.

**Communicate with Contacts** You should have a communication tree laid out and planned for these kinds of events, specifically one that outlines who is responsible for what. Who’s the person who informs the boss of what’s going on, and who reaches out to your [business’ insurance provider ](https://datalyst.directivesites.com/blog/stay-ahead-of-cyberthreats-compliance-requirements-for-massachusetts-business-insurance)and legal representation? Critically, someone needs to reach out to your IT provider (ideally, us), so who is assigned to do so? Getting everyone up to speed will be crucial to successfully navigating this kind of event.

**Control Communication** As you’re sorting through the [cyberattack](https://datalyst.directivesites.com/it-security-overview), ensure that your business has a single point of contact handling all public communications regarding the incident. Outside of that person, your staff should not speak publicly, which will help avoid misinformation being spread and prevent your business from being liable.

**Create a Record** Ensure that you document everything, including when the incident was discovered, what data was breached, and the steps taken to resolve the incident. Critically, wait for IT’s go-ahead before deleting any data from or even turning off an infected machine, as these actions can destroy valuable evidence.

## This Barely Scratches the Surface of What an Incident Response Plan Should Look Like

This critical process is not one to neglect, and the only thing more important than having such a plan is to have the security that prevents you from having to use it. We can help on all fronts.

We’ll not only implement strong protections to keep your business safe, but we’ll also help you craft, test, and implement all the plans that a business needs, including an incident response plan. Ready to get started? Give us a call at (774) 213-9701.

 [  ](https://datalyst.directivesites.com/javascript:void(0);) [  ](https://datalyst.directivesites.com/javascript:void(0);) [  ](https://datalyst.directivesites.com/javascript:void(0);)

Tags:

  [Ransomware](https://datalyst.directivesites.com/blog/tags/ransomware)   [Best Practices](https://datalyst.directivesites.com/blog/tags/best-practices)   [Security](https://datalyst.directivesites.com/blog/tags/security)

 [  Use Version Control for More Effective File Manage... ](https://datalyst.directivesites.com/blog/use-version-control-for-more-effective-file-management)

 [  Is Slow IT Costing Your Business a Secret Salary? ](https://datalyst.directivesites.com/blog/is-slow-it-costing-your-business-a-secret-salary)

 About the author

 [ ![Daniel Mathieu](https://datalyst.directivesites.com/images/easyblog_avatar/808_808_blogauthor.png) ](https://datalyst.directivesites.com/blog/blogger/daniel-mathieu)

 [Daniel Mathieu](https://datalyst.directivesites.com/blog/blogger/daniel-mathieu)

  [  ](https://datalyst.directivesites.com/javascript:void(0); "Subscribe to updates from author") [  ](https://datalyst.directivesites.com/javascript:void(0);)   [  ](https://datalyst.directivesites.com/blog/blogger/daniel-mathieu)

Dan is a trusted IT advisor with a background of over 25 years in IT and continuously works on the challenges of putting the right people in place to drive business growth and customer satisfaction.

Author's recent posts

  [More posts from author](https://datalyst.directivesites.com/blog/blogger/daniel-mathieu)

 [ Friday, 31 July 2026  Are You Paying for Inactive Software? ](https://datalyst.directivesites.com/blog/are-you-paying-for-inactive-software)

 [ Wednesday, 29 July 2026  3 Reasons Why Storing Business Files Locally is Obsolete ](https://datalyst.directivesites.com/blog/3-reasons-why-storing-business-files-locally-is-obsolete)

 [ Tuesday, 28 July 2026  Combating Software Bloat and Cyber Risks ](https://datalyst.directivesites.com/newsletter-content/combating-software-bloat-and-cyber-risks)

 <a class="eb-anchor-link" data-allow-comment="1" id="comments" name="comments"> </a> Comments

  No comments made yet. Be the first to submit a comment

   **![Guest](https://datalyst.directivesites.com/media/com_easyblog/images/avatars/author.png)**   Already Registered? [Login Here](https://datalyst.directivesites.com/home/login-logout?return=aHR0cHM6Ly9kYXRhbHlzdC5kaXJlY3RpdmVzaXRlcy5jb20vYmxvZy93aGF0LXRvLWRvLWluLXRoZS1maXJzdC02MC1taW51dGVzLW9mLWEtY3liZXJhdHRhY2s=)

 Tuesday, 04 August 2026

  Subscribe to the blog (Please fill in your email address to subscribe to updates from this post.)

 **Captcha Image**
