Cyber Security

What to Do After a Cyberattack

4 August 2020

How To Deal With a Cyberattack

With a growing proportion of the global economy and communication moving online, more and more companies are at risk of falling prey to a wide range of cyberattacks. Digital threats like malware, social engineering schemes and phishing scams are responsible for an ever-increasing cybercrime rate.
This makes it crucial for companies of all sizes to have a business disaster recovery plan in place to mitigate and alleviate any losses if such an event occurs. 
Recovering from a cyber security incident can be challenging, especially if you have lost information that was critical to your business operations. The good news is that you can limit the amount of damage to your company by developing a robust IT recovery plan in advance and by testing its effectiveness. 
However, if your business has already fallen victim of a data breach and you need to know what to do after a cyberattack, Redpalm have compiled a list of steps to assist you in minimising and containing the damage.
Let’s take a look at how this can be done.

  • Limit and Control the Extent of the Data Breach

After an attack, the first thing you should do is work out which servers and IT equipment have been compromised. Once you have that information, contain the spread of the breach as swiftly as you can by securing endpoints, devices and servers that aren’t affected by the attack. 
Below, is our list of things you can do to immediately try to contain and limit the spread of the breach:

  • Disconnect your internet connection
  • Restrict remote access
  • Fortify your firewall settings
  • Install any pending security updates or patches
  • Change your passwords across your business network

Once you’re certain you’ve been compromised, isolate any known compromised devices by taking them off your network. However, if you want any forensics performed on them to identify the source of the attack, DO NOT shut them down as most forensic data is lost on system shut down.
Ensure that you create strong new passwords for every affected account immediately. It’s also important that you avoid reusing old passwords or the same password across multiple accounts. This way, if a cyberattack were to happen again in the future, the damage will be restricted to one system or account. 
It is understandable that after a data breach occurs, you’d want to delete all your old records and data. However, we highly recommend preserving the evidence to find out how the breach occurred and understand the weaknesses in your infrastructure.

  • Manage the Fallout by Notifying Employees and Managers

Inform your staff about the cyberattack and define clear authorisations for all team members moving forwards. Ensure that both internal and external business communications are monitored and properly encrypted. 
It is crucial for your business that all the employees and teams remain on the same page as your company recovers from the attack. Depending on the extent of the damage, you may wish to seek legal advice to ascertain if, when and how to inform your customers about the data breach. 
If you have been the victim of a data breach, you need to report it to the ICO within 72 hours of discovery. To find out more about reporting to the ICO, click here.
Moving forwards, we’d suggest implementing routine security checks and evaluating your response to future test cybersecurity incidents, to minimise the likelihood of a similar attack taking place in the future. 
Identify the lessons you have learnt and make adjustments to your security response plan to remain prepared. 

  • Analyse and Evaluate the Breach

If your business is a victim of a wider-reaching cyberattack that has infected several other businesses, ensure that you closely follow any developments and updates on the situation. This way you’ll be kept aware of any additional help that is made available. 
Irrespective of whether you are a part of an extensive network breach or a solitary victim, you will need to assess and evaluate the root cause of the cyberattack. You need to find out its basis and point of origin within your business network so that you can safeguard yourself against a similar attack, should it happen again. 
Ask yourself these questions to thoroughly gauge the extent of the breach:

  • Which employees had access to the compromised servers?
  • Which network connections were being used when the data breach occurred?
  • How was the breach initiated?

Check your security data logs on your antivirus program, email providers or Intrusion Detection System to find out the exact moment the attack was initiated. If you are finding it difficult to pinpoint the origin and scope of the breach, the experts at Redpalm can provide assistance. 
We have a team of qualified cybersecurity professionals who will not only help you recover from the breach but also protect your IT environment from being compromised in the future.

  • Evaluate, Improve and Implement Security Measures

After a cyberattack, it is incredibly important that you update your IT disaster recovery plan, along with your business processes and techniques. This should be tested routinely and rigorously to ensure security and stability. At Redpalm, we conduct these tests in a simulated environment for our cyber security partners to stress test your security processes and ensure your business network is kept as secure as possible from digital threats. 
As a part of your business recovery plan, restoring and backing up of company data should be the obvious next step. As part of our service, we reinstall operating systems on compromised endpoints as we conduct a thorough scan of your IT environment. Our IT solutions come with backup and disaster recovery solutions that will help your business re-establish and manage data backup easily and efficiently with zero downtime. 
At Redpalm, our clients benefit from our comprehensive data protection solutions that ensure the safety and security of their IT infrastructure and equipment including physical workstations, servers and devices.

Get in Touch

Your business cannot predict when, where or how a digital breach will occur but you can take proactive measures to ensure that you are well-prepared if the worst happens. Putting together tried and tested cyber security solutions, as well as a preventative business recovery plan, is the key to protecting your business and to mitigating the impact an incident could have on your business if the worst happens. 
Our managed services provide endpoint security that delivers protection in real-time against email threats, malicious links and malware. Our IT solutions consist of the latest security measures with the best host intrusion prevention applications. 
Cyberattacks tend to put your brand’s credibility on the line and we can help you uphold your reputation with our cybersecurity solutions. If you have been searching for professional IT support and cybersecurity services based in Northampton and operating across the Midlands, then give us a call today!

Latest From The Blogs

pstn switch off 2027, an IT and networking team working
General

What Happens If a School Suffers a Phishing Breach Without an Incident Plan?

A phishing breach can escalate rapidly if a school lacks a documented cyber incident response plan. Clear procedures for identifying, containing, reporting and recovering from cyber incidents help minimise disruption, protect sensitive data, meet regulatory obligations and enable schools to respond quickly and effectively when security breaches occur. Call 0333 006 3366 today to book a free IT review of your school’s cyber security preparedness.

Read More
break fix vs msp, A close up shot of an IT professional working on a laptop
Business

Why Cheap Break-Fix IT Support Is Costing Your Business More Than Fully Managed Services

Break-fix IT support may appear cheaper initially, but recurring outages, lost productivity and preventable security risks often increase the true cost. Managed IT services provide proactive monitoring, maintenance and support that help reduce downtime, improve business resilience and give organisations more predictable IT costs as they grow.

Read More
what to do if you click on phishing link, A cybersecurity agency on alert after a threat is detected.
Cyber Security

What Happens When an Employee Clicks a Phishing Link in 2026?

Clicking a phishing link does not always result in a data breach, but a rapid response is essential. Prompt reporting, account protection, device investigation and data breach containment can significantly reduce the impact of phishing attacks. Clear employee guidance, incident response planning and ongoing security awareness training are key to limiting organisational risk.

Read More
Is Cyber Essentials Plus mandatory, An inside view of Redpalm's workplace
Cyber Security

Do I Need Cyber Essentials Plus If I Already Have the Basic Certificate?

Cyber Essentials Plus is not mandatory for most UK organisations, but it provides independently verified assurance that cyber security controls are working effectively. It is particularly valuable for businesses handling sensitive data, bidding for public sector contracts or meeting higher customer security expectations, offering greater confidence than Cyber Essentials alone.

Read More
failed cyber insurance audit, A photo of an cyber security professional's working desk.
Cyber Security

Failed a Cyber Insurance Technical Audit? 5 Risks Your Business May Face

Failing a cyber insurance audit highlights security weaknesses that could increase exposure to cyberattacks, regulatory risks and financial losses. 

Read More
ai powered social engineering, A cyber security expert examining a source code.
Cyber Security

Protecting Your Business From AI-Powered Social Engineering Deepfakes

AI-powered deepfake social engineering combines artificial intelligence with manipulation tactics to impersonate trusted individuals through realistic voice, video and text content. 

Read More
DDoS attack prevention methods, a cybersecurity analyst scanning for security threats.
Cyber Security

The Canonical Cyberattack Shows Why DDoS Protection Can’t Be Ignored

The 2026 Canonical cyberattack demonstrated how even globally trusted technology providers can be disrupted by large-scale DDoS attacks. The incident highlights the growing importance of proactive cyber security, DDoS mitigation and resilient IT infrastructure for businesses of all sizes.

Read More
geopolitical cyber threats, A cyber attack being detected in a tech control room.
Business, Cyber Security

Why Rising Geopolitical Tensions May Increase Cyber Risks & Threats for UK Businesses

Geopolitical conflict is increasing the scale and sophistication of cyber threats affecting UK businesses, particularly SMEs. Attacks such as ransomware, phishing and supply chain breaches exploit vulnerabilities and global instability. Strengthening basic cyber hygiene, access controls and incident readiness is essential to reduce risk and maintain operational resilience in a heightened threat environment. 

Read More
Cyber Security

Why Shadow AI is the Biggest Unseen Threat to UK GDPR Compliance in 2026

Shadow AI, which is the unauthorised use of AI tools by employees, is rapidly increasing as accessibility and adoption grow. It creates significant risks to data security and UK GDPR compliance by enabling unmonitored data sharing, loss of control, and a lack of audit trails. Effective mitigation requires visibility, governance policies, technical controls, approved alternatives, and employee training. Connect with Redpalm’s team to manage shadow AI risks.

Read More
cloud migration mistakes, Redpalm's experts working from their headquarters
Cyber Security

Understanding ITDR and Why Identity Is the New Security Perimeter

Identity is now the primary security perimeter as cloud adoption, SaaS usage, and remote work reduce the effectiveness of traditional network defences. Identity Threat Detection and Response (ITDR) addresses this shift by monitoring and protecting against credential misuse and identity-based attacks, enabling organisations to detect, respond to, and mitigate threats through continuous monitoring, behavioural analysis, and integrated security controls. Don’t wait, strengthen your identity access security. Book a free review with Redpalm today.

Read More