Back to Insights
Blog25 August 2026 · 2 min read

What Happens in the First Hour of a Cyber Attack

The decisions you make in the first sixty minutes of a cyber attack shape everything that follows - what evidence survives, how far the damage spreads, and how quickly your business recovers. This is what those sixty minutes actually look like.

David Taylor

Managing Director

Clock on an office wall

Your IT provider is invaluable. They know your systems, your infrastructure, your users. When it comes to getting things back up and running, they are exactly who you need.

But incident response is a different discipline.

A specialist is trained to think like the attacker. They know what criminals do once they are inside a network - how they move between systems, how they cover their tracks, how they position themselves before striking. They know how to stop the spread without destroying the evidence, and how to confirm the attacker is actually out before anyone declares the all-clear.

Your IT provider can restart your server. An incident responder can tell you whether the attacker left a back door before they were removed.

You need both. They are not the same thing.

The first thirty minutes: what needs to happen

If you have a specialist on the phone, they will guide you through this. If you do not, here is the broad shape of what needs to happen.

First, identify the scope. Which accounts, devices and systems are affected? Do not assume it is isolated. Business email compromise in particular tends to be far wider than it first appears - by the time one account shows signs, others may already be compromised.

Second, do not communicate over the affected channels. If your email is compromised, do not use email to coordinate your response. Use a personal phone, WhatsApp, or speak in person. Attackers sometimes monitor compromised inboxes in real time.

Third, do not pay anything. No transfers, no gift cards, no changed bank details. Freeze anything that can be frozen and call your bank if there is any suggestion that a fraudulent payment is in motion.

Fourth, contact your incident response support if you have it. This is exactly what it is there for.

The next thirty minutes: triage and containment

A good incident response specialist will triage the situation quickly. They will ask structured questions: what has happened, what do you know so far, what has already been done, which systems are involved. They are building a picture.

Once they understand what they are dealing with, they will guide you through containment. That typically means disabling compromised accounts, revoking active sessions, removing any malicious email rules the attacker may have created, isolating affected devices and resetting credentials.

Each step is deliberate. The goal is to cut off the attacker's access without destroying the evidence of how they got there in the first place.

Containment does not mean recovery. The business is not back to normal at this point. But the bleeding has stopped.

Keep reading

Get practical cybersecurity thinking in your feed.

Subscribe to Aruga's LinkedIn Newsletter for practical insight on cyber risk, incident response and security operations.

David Taylor

Managing Director

Back to Insights

Keep reading

Related posts

Image: ITV News

8.7 million reasons to decide who you'd call. What the Manchester Airport breach teaches every business.

Read article →
"Security analysts monitoring live threat data across multiple screens in a cyber operations centre, responding to an active incident."

When Every Second Counts: A Practical Guide to Cyber Incident Response

Read article →

Cookies on this website

We use essential cookies to make this website work. With your permission, we also use analytics and marketing cookies to understand how the site is used and improve our communications.

Read our cookie policy