Blue Orbit Technologies logo Back to TechHub

Cybersecurity Guide

What to do in the first hour after a suspected security incident

Most small businesses do not have a security team, so the first hour after something looks wrong, whether it's a ransomware note, a suspicious login, or a system suddenly behaving strangely, is often handled by whoever is available. Having a clear, calm sequence ready in advance makes a real difference.

The goal in the first hour is containment, not diagnosis

You do not need to know exactly what happened before you act. The priority is stopping the problem from spreading and preserving evidence, not immediately fixing everything or figuring out the full cause.

First-hour checklist

  • Disconnect the affected device from the network, but do not power it off if ransomware is suspected
  • Note the exact time the issue was noticed and what was seen
  • Check whether other devices on the same network segment show similar signs
  • Change passwords for any accounts that may have been exposed, starting with admin and remote-access logins
  • Confirm whether backups are intact and have not been affected
  • Avoid restoring or wiping anything until the situation is understood, in case evidence is needed later
  • Contact whoever handles IT or security support for the business immediately

Why segmentation and backups matter before an incident happens

The businesses that recover fastest from a security incident are usually the ones that already had CCTV, office, and guest networks separated, and backups that were tested, not just scheduled. Segmentation limits how far a problem can spread, and a verified backup turns a potential disaster into a recovery task.

Building a simple incident contact list in advance

Every small business should have one page, printed or saved somewhere accessible without network access, listing who to call first for IT support, who has admin access to critical systems, and where the most recent verified backup is stored. Writing this down before an incident, not during one, is what keeps the first hour calm instead of chaotic.

Need help preparing an incident response plan?

Blue Orbit can help set up network segmentation, verified backup routines, and a simple incident response reference for small business and institutional sites, so the first hour after a problem is handled with a plan instead of guesswork.

Talk to Blue Orbit Request a review

Related content

  • Basic cybersecurity checklist for small business
  • Password and access hygiene for small business IT
  • Small business server backup checklist before the first failure
  • Network audit checklist
WhatsApp Home