If a cyberattack hits your business, the first hour matters more than any other. It’s also the easiest moment to make an expensive mistake — powering off the wrong machine, deleting the evidence investigators need, or replying from an email account the attacker is already reading. The steps below tell you what to do, in order, so you’re not guessing under pressure. None of them require technical knowledge.

First rule: don’t make it worse

Before you touch anything, avoid these four:

  • Don’t power the affected computer off if you can avoid it. Disconnecting it from the network is better — shutting it down can wipe evidence that helps work out what happened.
  • Don’t delete anything. Leave the ransom note, the suspicious email, and any alerts exactly where they are. That’s what your IT team and investigators will need.
  • Don’t pay a ransom on the spot.
  • Don’t use the compromised email or accounts to discuss the attack. If an attacker is in your inbox, they can read those messages. Switch to phone calls or a clean account.
Toronto small business responding to a cyberattack

The step-by-step

Work through these in order, from the moment you notice something’s wrong:

  1. Disconnect the affected devices from the network. Unplug the network cable and turn off Wi-Fi on anything that looks affected. This stops the problem spreading to other computers and to your backups. CISA’s guidance is to isolate devices rather than power them off where you can — and only shut a device down if you can’t get it off the network any other way.
  2. Call your IT provider immediately — by phone. Don’t email, in case the attacker is watching your inbox. If you have cyber insurance, call them next; many policies require you to involve their incident team early.
  3. Leave the evidence alone. Don’t wipe, reinstall, or tidy up the affected machines yet. Screenshots of the ransom note or suspicious emails are useful, but keep the originals too.
  4. If money was sent, call your bank immediately. Ask them to recall and freeze the transfer if they can. With wire and bank fraud, acting in the first few hours makes the biggest difference.
  5. Reset passwords from a clean device and turn on MFA. Start with email and any admin accounts, using a device you know isn’t affected.
  6. Report it. It can help you recover, and it’s sometimes legally required.

Where to report it (and the Canadian angle)

In Canada, report cybercrime to the Canadian Anti-Fraud Centre and the Canadian Centre for Cyber Security. If money was wired to a scammer, report it fast — speed is everything with fraudulent transfers.

There’s also a legal dimension for Ontario businesses. Under PIPEDA, a breach of personal information that creates a real risk of significant harm requires you to notify the Office of the Privacy Commissioner and the affected individuals, and to keep records of the breach. Health information brings PHIPA obligations on top. Miss a notification duty and the fallout can outlast the attack itself — so loop in your lawyer or IT provider early so you don’t blow a deadline.

Should you pay the ransom?

If it’s ransomware, that’s the big question. Law enforcement generally advises against it: paying doesn’t guarantee you get your files back, it marks you as a business that pays, and the money funds more attacks. It’s ultimately your decision — but one to make with law enforcement, your IT or incident-response team, and your insurer, not alone in the first panicked hour. Sometimes a free decryption tool already exists for the exact strain that hit you, which is one more reason to get experts involved before paying anyone.

The best time to prepare is before it happens

All of this is far easier if you’ve decided some of it in advance. You don’t need a thick binder — just a one-page plan covering: who to call first (IT provider, insurer) and their numbers, kept somewhere reachable without your main systems; where your backups are, and proof they’ve been tested by actually restoring from them; and which accounts and devices matter most, so you know what to protect first. For most small businesses, a single page is enough — and it saves a lot of scrambling if the day ever comes.

Frequently asked questions

What’s the first thing to do in a cyberattack?

Disconnect the affected devices from the network — unplug the cable, turn off Wi-Fi — then call your IT provider by phone. Getting the device off the network stops the spread while you get help.

Should I turn off the computer if I get ransomware?

If you can, disconnect it from the network instead. Shutting it down can wipe evidence stored in memory. Only power off if you can’t isolate it any other way.

Should I pay the ransom?

Law enforcement advises against it — payment doesn’t guarantee recovery and funds more attacks. Make that call with police, your incident-response team, and your insurer, and check whether a free decryption tool already exists first.

We wired money to a scammer. What do we do?

Call your bank immediately and ask them to recall the transfer, then report it to the Canadian Anti-Fraud Centre. The faster you act, the better the odds of clawing it back.

Who do I report a cyberattack to in Canada?

The Canadian Anti-Fraud Centre and the Canadian Centre for Cyber Security. Also tell your cyber insurer, and check whether PIPEDA/PHIPA require you to notify the Privacy Commissioner and affected individuals if personal data was exposed.

Worth sorting out before it happens: our cybersecurity services include incident response for GTA businesses, and business continuity planning is what turns that first hour from guesswork into a checklist.


Prepared by the EB Solution team — managed IT and cybersecurity for businesses across the Greater Toronto Area. Want a one-page incident plan built for your business before you need it? Let’s put one together.

Watch Our Latest Tech Videos From EB Solution

Call Now