If a cyberattack hits your business, the first hour matters more than any other. It’s also the easiest moment to make an expensive mistake — powering off the wrong machine, deleting the evidence investigators need, or replying from an email account the attacker is already reading. The steps below tell you what to do, in order, so you’re not guessing under pressure. None of them require technical knowledge.
Before you touch anything, avoid these four:

Work through these in order, from the moment you notice something’s wrong:
In Canada, report cybercrime to the Canadian Anti-Fraud Centre and the Canadian Centre for Cyber Security. If money was wired to a scammer, report it fast — speed is everything with fraudulent transfers.
There’s also a legal dimension for Ontario businesses. Under PIPEDA, a breach of personal information that creates a real risk of significant harm requires you to notify the Office of the Privacy Commissioner and the affected individuals, and to keep records of the breach. Health information brings PHIPA obligations on top. Miss a notification duty and the fallout can outlast the attack itself — so loop in your lawyer or IT provider early so you don’t blow a deadline.
If it’s ransomware, that’s the big question. Law enforcement generally advises against it: paying doesn’t guarantee you get your files back, it marks you as a business that pays, and the money funds more attacks. It’s ultimately your decision — but one to make with law enforcement, your IT or incident-response team, and your insurer, not alone in the first panicked hour. Sometimes a free decryption tool already exists for the exact strain that hit you, which is one more reason to get experts involved before paying anyone.
All of this is far easier if you’ve decided some of it in advance. You don’t need a thick binder — just a one-page plan covering: who to call first (IT provider, insurer) and their numbers, kept somewhere reachable without your main systems; where your backups are, and proof they’ve been tested by actually restoring from them; and which accounts and devices matter most, so you know what to protect first. For most small businesses, a single page is enough — and it saves a lot of scrambling if the day ever comes.
Disconnect the affected devices from the network — unplug the cable, turn off Wi-Fi — then call your IT provider by phone. Getting the device off the network stops the spread while you get help.
If you can, disconnect it from the network instead. Shutting it down can wipe evidence stored in memory. Only power off if you can’t isolate it any other way.
Law enforcement advises against it — payment doesn’t guarantee recovery and funds more attacks. Make that call with police, your incident-response team, and your insurer, and check whether a free decryption tool already exists first.
Call your bank immediately and ask them to recall the transfer, then report it to the Canadian Anti-Fraud Centre. The faster you act, the better the odds of clawing it back.
The Canadian Anti-Fraud Centre and the Canadian Centre for Cyber Security. Also tell your cyber insurer, and check whether PIPEDA/PHIPA require you to notify the Privacy Commissioner and affected individuals if personal data was exposed.
Worth sorting out before it happens: our cybersecurity services include incident response for GTA businesses, and business continuity planning is what turns that first hour from guesswork into a checklist.
Prepared by the EB Solution team — managed IT and cybersecurity for businesses across the Greater Toronto Area. Want a one-page incident plan built for your business before you need it? Let’s put one together.