
What Happens in the First Hour of a Cyber Attack
The decisions you make in the first sixty minutes of a cyber attack shape everything that follows - what evidence survives, how far the damage spreads, and how quickly your business recovers. This is what those sixty minutes actually look like.
David Taylor
Managing Director

Your IT provider is invaluable. They know your systems, your infrastructure, your users. When it comes to getting things back up and running, they are exactly who you need.
But incident response is a different discipline.
A specialist is trained to think like the attacker. They know what criminals do once they are inside a network - how they move between systems, how they cover their tracks, how they position themselves before striking. They know how to stop the spread without destroying the evidence, and how to confirm the attacker is actually out before anyone declares the all-clear.
Your IT provider can restart your server. An incident responder can tell you whether the attacker left a back door before they were removed.
You need both. They are not the same thing.
The first thirty minutes: what needs to happen
If you have a specialist on the phone, they will guide you through this. If you do not, here is the broad shape of what needs to happen.
First, identify the scope. Which accounts, devices and systems are affected? Do not assume it is isolated. Business email compromise in particular tends to be far wider than it first appears - by the time one account shows signs, others may already be compromised.
Second, do not communicate over the affected channels. If your email is compromised, do not use email to coordinate your response. Use a personal phone, WhatsApp, or speak in person. Attackers sometimes monitor compromised inboxes in real time.
Third, do not pay anything. No transfers, no gift cards, no changed bank details. Freeze anything that can be frozen and call your bank if there is any suggestion that a fraudulent payment is in motion.
Fourth, contact your incident response support if you have it. This is exactly what it is there for.
The next thirty minutes: triage and containment
A good incident response specialist will triage the situation quickly. They will ask structured questions: what has happened, what do you know so far, what has already been done, which systems are involved. They are building a picture.
Once they understand what they are dealing with, they will guide you through containment. That typically means disabling compromised accounts, revoking active sessions, removing any malicious email rules the attacker may have created, isolating affected devices and resetting credentials.
Each step is deliberate. The goal is to cut off the attacker's access without destroying the evidence of how they got there in the first place.
Containment does not mean recovery. The business is not back to normal at this point. But the bleeding has stopped.
Keep reading
Get practical cybersecurity thinking in your feed.
Subscribe to Aruga's LinkedIn Newsletter for practical insight on cyber risk, incident response and security operations.

David Taylor
Managing Director
Keep reading
Related posts


Defending your inbox – SPF, DKIM and DMARC explained!
Read article →
