
Most small business owners assume cyber attacks are something that happens to large companies – the ones with massive databases and household names worth targeting. That assumption is wrong, and it's exactly why small businesses are increasingly the primary target. They're easier to breach, less likely to have incident response plans, and often hold valuable data without adequate protection. When an attack hits, the decisions made in the first few hours can mean the difference between a managed recovery and a business-ending event.

This guide walks through what to do immediately, what to do next, and how to protect yourself going forward – without requiring a cybersecurity background to follow.
The first challenge in a cyber attack is knowing one has happened. Some attacks are immediately obvious – ransomware that locks your systems and demands payment, for example, announces itself clearly. Others are quiet. A business email compromise might involve a fraudster operating as a trusted vendor for weeks before anyone notices. A data breach might run for months before being discovered through external notification or unusual account activity.
Common signs that something is wrong include: computers that suddenly run slowly or display unexpected messages, systems locking you out without explanation, unusual charges or transactions on business accounts, emails you didn't send appearing in your sent folder, or customers and vendors reporting strange communications from your address. If something feels off with your systems, accounts, or communications, take it seriously immediately – the instinct to rationalize unusual behavior as a technical glitch is one of the reasons breaches run so long before discovery.
The moment you suspect an attack is underway, containment is the priority. Every minute of additional access for an attacker can mean more systems compromised, more data exfiltrated, or more damage done. You don't need to understand exactly what happened before you start limiting the attacker's ability to continue.
Disconnect affected systems from the network by unplugging ethernet cables or disabling Wi-Fi on machines that appear compromised. If you're not sure which machines are affected, consider isolating the entire network temporarily – the disruption of going offline is far less costly than allowing an active attacker to continue. Do not turn off affected computers, despite the instinct to do so. Powered-down machines lose volatile memory that can contain critical forensic information about what happened and how. Leave them on but disconnected from the network unless a security professional instructs otherwise.
Change passwords immediately for any accounts that may have been accessed or that connect to affected systems – starting with email, banking, and administrative accounts. Use a device that you're confident isn't compromised to do this, such as a personal phone on cellular data rather than your business network. Enable multi-factor authentication on critical accounts if it isn't already active. Notify your team not to use the affected systems and to watch for unusual requests or communications, since attackers often use compromised business email to send fraudulent payment requests or instructions to employees.
Before you start cleaning up, take time to document what you're seeing. This documentation matters for insurance claims, legal proceedings, regulatory reporting, and forensic investigation. Take screenshots of any ransom notes, error messages, or unusual system behavior. Note the time and date you first noticed the issue and what led you to notice it. Write down which systems appear affected and what was happening on those systems at the time of discovery.
If you have IT support or a managed service provider, contact them immediately and let them know not to begin remediation until you've agreed on an approach to evidence preservation. The instinct to clean up quickly is understandable but can destroy evidence that matters later. If law enforcement becomes involved – which is often the right call in serious incidents – they will want as much forensic evidence intact as possible.
Trying to handle a cyber attack without outside help is a common mistake, particularly for small business owners who aren't technical. The attack has already happened – getting the right expertise involved quickly is far more important than trying to manage it alone.
Your cyber insurance carrier should be the first call if you have a policy. Most cyber insurance policies include incident response services as a covered benefit – this means the carrier will connect you with forensic investigators, legal counsel, and crisis communications support at no additional cost. If you have coverage, using those services is both the fastest way to get help and the most cost-effective. Do not begin paying for outside services before contacting your insurer, as doing so without authorization can complicate coverage.
A managed security service provider or incident response firm is the call to make if you don't have cyber insurance. Companies like Coveware, Mandiant, or Secureworks specialize in cyber incident response for businesses of all sizes. Expect to pay $200–$500 per hour for qualified incident response support, with total costs for a small business breach investigation running $5,000–$50,000 depending on scope. This is expensive – which is exactly why cyber insurance exists.
Your bank should be notified if any financial accounts may have been accessed or if you're dealing with a business email compromise that could involve fraudulent payment instructions. Banks have fraud departments equipped to freeze transactions, reverse wire transfers when caught quickly, and monitor accounts for further unauthorized activity. Speed matters here – wire transfer fraud is very difficult to reverse once the funds have moved, but rapid notification gives the best chance of intervention.
An attorney with data privacy experience is worth involving early if there's any possibility that customer, employee, or vendor data was compromised. Notification obligations under state data breach laws and federal regulations vary, and the window for required notification is often shorter than business owners realize. Acting without legal guidance in this area creates additional compliance risk on top of the breach itself.
If personal data belonging to customers, employees, or vendors was exposed, you very likely have legal notification obligations – and failure to comply carries its own penalties separate from the breach itself. Every US state has data breach notification laws, and the requirements vary significantly: who must be notified, how quickly, and in what format differ across jurisdictions.
As a general rule, assume you need to notify affected individuals promptly if their personal information – names combined with Social Security numbers, financial account numbers, health information, or login credentials – was potentially exposed. Some state laws require notification within 30–72 hours of discovery. Certain regulated industries have additional notification requirements: healthcare businesses under HIPAA, financial services firms under the FTC Safeguards Rule, and businesses that take payment cards under PCI DSS standards all have specific breach reporting obligations.
The Federal Trade Commission (FTC), your state attorney general, or sector-specific regulators may also need to be notified depending on your industry and the size and nature of the breach. This is another reason having legal counsel involved early is worth the cost – the compliance map for breach notification is genuinely complex, and getting it wrong compounds the problem.
Once containment is underway and the right people are involved, the focus shifts to understanding what actually happened. This is the investigation phase, typically led by forensic security professionals who can analyze logs, examine affected systems, and determine the attack vector, the timeline of access, and what data was reached.
For small businesses without detailed logging infrastructure, this investigation may be limited by what data is actually available to analyze. One of the most common frustrations in small business breach response is discovering that the systems didn't have audit logging enabled, making it impossible to determine exactly what the attacker accessed. Understanding this limitation before an incident – and implementing basic logging – is one of the most practical preventive steps available.
The scope assessment should answer: how did the attacker get in (phishing email, stolen credential, unpatched software, third-party vendor access), what did they access or exfiltrate, what systems were affected, and is the threat fully contained or still active? These answers drive the remediation plan and determine what notifications are required.
Restoration from a cyber attack should happen systematically, not in a rush to get back to normal. Restoring from backups is the primary recovery path for most attacks – which is why having clean, recent, offline backups is so important. Cloud backups that are continuously synced to your live environment are not reliable recovery tools for ransomware attacks, because the ransomware encrypts the backup along with the original. Backups that are disconnected from the production environment on a regular schedule are what actually allow clean restoration.
Before bringing systems back online, confirm that the attack vector has been closed. Restoring systems into the same vulnerable state that allowed the initial breach results in reinfection – a scenario that's unfortunately common and extremely demoralizing. Work with your security support to verify that the entry point is identified and patched before restoration begins.
If ransomware is involved, the decision of whether to pay demands a separate conversation. Law enforcement agencies including the FBI generally advise against paying ransoms because payment doesn't guarantee data return, encourages further attacks, and may in some cases violate sanctions laws if the attacker is on a prohibited entity list. That guidance is worth taking seriously. Some businesses with no backups and no other recovery path feel they have no choice – if you're in that position, involve legal counsel before any payment is made.
Trying to fix it yourself and quietly move on is the mistake that turns a manageable incident into a much larger one. Incomplete remediation, missing notification obligations, and uncontained attacker access all stem from businesses that try to handle breaches internally without qualified help.
Paying ransom before exploring all options is worth thinking carefully about. Forensic security firms have increasing capability to decrypt some ransomware strains without payment, and the No More Ransom project (nomoreransom.org) provides free decryption tools for many known ransomware families. These options should be explored before assuming payment is the only path.
Delaying notification to avoid embarrassment is a genuine risk. Most business owners feel a strong impulse to manage how the breach is perceived before telling anyone. But delayed notification that falls outside the required window creates legal liability that doesn't exist if notification is made promptly. The reputational damage from a breach handled transparently and quickly is almost always less than the reputational damage from a breach covered up and later discovered.
Using compromised systems to manage the response continues to give attackers access to your communications and decisions. All breach response communication should happen through a confirmed clean device and, where possible, an out-of-band communication channel.
Once the immediate crisis is resolved, use the incident as a forcing function for the security improvements that should have been in place before. The most impactful steps for most small businesses, in order of priority, are: regular offline backups tested for successful restoration, multi-factor authentication on all email and financial accounts, employee training on phishing recognition, a cyber insurance policy sized to your actual risk, and a documented incident response plan so that when something happens again, the team knows what to do in the first 30 minutes without having to figure it out under pressure.
A cyber incident response plan doesn't need to be complicated. A one-page document identifying who to call (IT support, insurer, attorney, bank), who inside the business has decision-making authority, and what the first containment steps are provides enormous value in the chaos of an active incident. Get it written, share it with key team members, and review it annually.
Do I need to report the attack to law enforcement? It depends on the nature and severity of the attack. The FBI's Internet Crime Complaint Center (IC3) accepts reports from businesses of all sizes and is the standard reporting destination for cybercrime in the US. Reporting doesn't obligate you to cooperate with an investigation, but it contributes to the intelligence picture that helps law enforcement respond to attack patterns. For ransomware attacks, the FBI recommends reporting even if you choose not to pursue investigation. For financial fraud involving wire transfers, contacting the FBI as well as your bank quickly gives the best chance of recovery.
What if I don't have cyber insurance? You'll need to fund incident response, legal counsel, and notification costs out of pocket. For small businesses, a serious breach without insurance can cost $20,000–$200,000 depending on scope. Cyber insurance for small businesses typically costs $1,000–$3,000 per year for meaningful coverage. If you don't have it and have just been through an incident, getting it in place before anything else happens again should be the top priority once you're recovered.
Can I recover funds lost in a business email compromise attack? Sometimes, if you act fast. Wire transfer fraud is very difficult to reverse once funds have been moved internationally, but domestic transfers can sometimes be recalled if the bank is notified within hours. The FBI's Financial Fraud Kill Chain is specifically designed to assist with rapid intervention in business email compromise cases – report through IC3 immediately if wire fraud is involved.
How long does recovery from a cyber attack typically take? For small businesses, a well-managed recovery from a significant ransomware or breach event typically takes two to eight weeks from containment to full restoration. The range is wide because it depends heavily on the quality of backups, the scope of affected systems, and the speed of investigation. Businesses without backups that are forced to rebuild from scratch can take months. Having tested backups is the single biggest factor in recovery timeline.
Will my customers find out? If personal data was compromised, they will find out – through your required notification. Managing that communication proactively, transparently, and with clear information about what happened and what you're doing about it, produces significantly better outcomes than notifications that feel evasive or minimize the incident. Customers respond better to honest, prompt communication than many business owners expect.
A cyber attack is one of the most stressful things a small business can experience, and the decisions made in the first few hours matter enormously. Contain quickly, document before cleaning up, get the right people involved without delay, understand your notification obligations, and restore only after the entry point is closed. None of that requires technical expertise – it requires having a plan before something happens and executing it calmly when it does. The businesses that recover well aren't necessarily the ones with the best security – they're the ones that respond well.
FBI Internet Crime Complaint Center (IC3): https://www.ic3.gov
CISA – Small Business Cybersecurity Corner: https://www.cisa.gov/resources-tools/resources/small-business-cybersecurity-corner
FTC – Data Breach Response – A Guide for Business: https://www.ftc.gov/business-guidance/resources/data-breach-response-guide-business
No More Ransom – Free Ransomware Decryption Tools: https://www.nomoreransom.org
U.S. Department of Justice – Business Email Compromise: https://www.justice.gov/criminal/criminal-fraud/business-email-compromise
National Institute of Standards and Technology (NIST) – Small Business Cybersecurity: https://www.nist.gov/system/files/documents/2019/08/06/nistsmallbizguide.pdf


















