Nobody plans to read this on the day they need it. But if a ransom note has replaced a desktop wallpaper this morning, or your bank just called about wires you never sent, or nobody on your team can open a file — take a breath. The next 24 hours have an order to them. Businesses that follow it recover faster, keep their insurance coverage intact, and stay on the right side of their legal obligations. Businesses that improvise — wiping machines, hiring help out of pocket, emailing customers in a panic — usually turn an expensive day into a much more expensive month. Here is the order.
The first 24 hours at a glance
Print this, or keep it open on a phone that is not connected to your office network. The detail for each window follows below.
| Window | What to do | What to avoid |
|---|---|---|
| Hour 0–1 | Disconnect affected machines from the network. Call your IT provider. Start a written timeline. | Powering everything off, wiping or reimaging machines, deleting anything. |
| Hours 1–4 | Call your cyber-insurance carrier. Preserve evidence. Identify what systems and data are affected. Reset credentials from a known-clean device. | Hiring outside help before your insurer approves it. |
| Hours 4–12 | Name one spokesperson. Verify backup integrity. Begin containment with professionals. | Public speculation, customer emails, or restoring from backups nobody has checked. |
| Hours 12–24 | Triage notification obligations with your attorney. Set your ransom stance with insurer and counsel. Plan the restore order. | Sending notices without legal review, or deciding on the ransom alone. |
Hour 0–1: Contain the damage without destroying the evidence
The instinct in the first ten minutes is to shut everything down or start wiping infected machines. Resist both. Powering a machine off can erase evidence that only lives in memory — including, in some ransomware cases, material an incident-response team can use. A machine caught mid-encryption and interrupted the wrong way can leave files in a state nobody can bring back. And wiping or reimaging destroys the record of how the attacker got in, which is the one question every later decision depends on.
What you do instead:
- Disconnect affected machines from the network. Unplug the Ethernet cable, turn off Wi-Fi, and if the problem is spreading, isolate at the switch or firewall. Leave the machines powered on unless a professional tells you otherwise.
- Call your IT provider or MSP. If you have managed cybersecurity with monitoring and endpoint detection, isolation may already be underway — confirm it, and let them drive the technical response from here.
- Start a written timeline. On paper or a personal phone, not on a company system that may be compromised: when the problem was noticed, what people saw, and every action taken, with times. Your insurer, your attorney, and the investigators will all ask for this, and memory does not survive a day like this one.
Hours 1–4: Call your insurer before you hire anyone
This is the step that surprises most owners: your cyber-insurance carrier comes before any outside help. Most policies name a breach coach — an attorney who quarterbacks the response — and a panel of approved incident-response firms. Engaging your own vendors first, or paying for help out of pocket, can jeopardize your coverage for the entire event. The claims hotline is on your policy documents; call it, describe what you know, and follow their direction on who gets engaged.
While those calls happen, three workstreams run in parallel:
- Preserve evidence. Do not delete the phishing email, clear logs, run cleanup tools, or throw away the ransom note. Everything is evidence — for investigators, for the insurance claim, and for the lawyers.
- Identify the scope. With your IT provider, list what systems are affected and what data lives on them: customer records, payroll, health information, client files. This inventory drives every legal obligation you will triage tonight.
- Change credentials from a known-clean device. A machine that was powered off, or a personal phone on cellular data, is your clean starting point. Reset passwords for the accounts that matter most — email administration, banking, payroll, remote access — sign out all active sessions, and re-enroll multi-factor authentication. Attackers often keep working through stolen sessions long after the password changes.
Hours 4–12: Discipline in communications, caution with backups
By mid-day, two mistakes are waiting to be made. The first is talking too much. Name one spokesperson — usually the owner or a designated manager — and give everyone else a single sentence: “We are dealing with an IT incident and will share verified information as soon as we have it.” No speculation, no guesses about what was taken, and no customer notices until your attorney has reviewed the wording. Even the word “breach” carries legal weight; let counsel choose the words. A well-meaning email sent at noon can contradict what the investigation finds at midnight.
The second mistake is rushing to restore. Attackers know your backups are the thing that lets you refuse to pay, so they target them first — deleting cloud snapshots, encrypting backup servers, and in many cases sitting quietly in a network for days or weeks first, which means recent restore points can contain their tools. Before anything is restored, your backup and disaster recovery chain needs to be verified: are the backups intact, is there an offline or immutable copy the attacker could not reach, and which restore point is confirmed clean? Restoring an infected backup replays the whole attack.
Meanwhile, containment proceeds with professionals: isolating compromised accounts and machines, blocking the attacker’s access, and closing the door they came through. This is careful, methodical work — the goal is an attacker who is actually gone, not one who is quiet.
Hours 12–24: Legal obligations, the ransom question, and the road back
With the fire contained, the evening belongs to decisions — none of which you make alone.
Notification triage happens with your attorney. Which obligations apply depends entirely on what data was involved, and your attorney makes the final call. The list they will walk through with you:
- Oklahoma’s Security Breach Notification Act covers unencrypted personal information of Oklahoma residents — generally names combined with Social Security numbers, driver’s license numbers, or financial account details. If that data was exposed, notice obligations to affected residents follow.
- HIPAA, if protected health information is involved: the notification clock starts at discovery, not at cleanup, so the timeline you started in hour one matters already.
- The FTC Safeguards Rule, for covered financial businesses such as CPA and tax firms: breaches involving unencrypted information of 500 or more consumers must be reported to the FTC no later than 30 days after discovery.
- Your contracts. Client and vendor agreements often carry their own notice requirements and deadlines — sometimes shorter than the statutes.
- The FBI. A report to the Internet Crime Complaint Center (IC3) is encouraged, often expected by insurers, and occasionally genuinely helpful — law enforcement sometimes has intelligence on the specific group involved.
The ransom stance is set with your insurer and counsel — never alone. Payment does not guarantee working decryption, it may be restricted depending on who is on the other end, and it is sometimes still the least bad option. That judgment belongs to the breach coach, the insurer, and you together, in that conversation, documented.
Plan the restore order before restoring anything. Identity systems and email first, then core line-of-business applications, then file shares, then individual workstations — with each layer verified clean before the next comes back. An order planned at hour 20 beats one improvised at hour 30.
The one-page plan that makes this day survivable
Everything above goes better — hours better — when the answers exist before the attack. The plan is one printed page:
- Who to call, in order: your IT provider’s emergency line, your cyber-insurance claims hotline with the policy number written next to it, your attorney, your bank.
- How to isolate: where the switch and firewall live, who has the credentials, and which cable to pull.
- Who speaks: the one spokesperson, named now, plus the holding sentence everyone else uses.
- Where the timeline template lives — printed, because a plan stored only on a server that just got encrypted is not a plan.
An incident-response plan is one line on our broader SMB cybersecurity checklist, and it is the line that pays for itself in the first hour. NSN Management has been Tulsa-owned since 2012, and incident-response planning is part of the cybersecurity work we do with Tulsa-area businesses precisely because the plan is cheap and the improvisation is not.
How tested backups change the entire day
Read back through the hard moments above and notice what changes if your backups are tested, current, and kept where an attacker cannot reach them. The ransom conversation loses its leverage. The restore order is rehearsed instead of invented. The scope of what you could lose is known instead of feared. A backup that has never been restored is a hope, not a plan — the businesses that walk out of a cyberattack bruised instead of broken are almost always the ones that knew, before the bad morning, exactly what their recovery looked like.
If this morning is the bad morning: disconnect, call your IT provider, call your insurer, and write down the times. If it is a quiet morning, that is the best possible day to build the one-page plan and test the backups — book a Discovery Call with NSN Management and we will walk through your incident readiness together.
Questions Tulsa businesses ask about this
Who do we call first after a cyberattack?
Your IT provider or MSP first, so isolation starts immediately — then your cyber-insurance carrier before you engage anyone else. Most policies name a breach coach and an approved incident-response panel, and hiring your own vendors without the insurer’s approval can jeopardize coverage. Keep both numbers on a printed one-page plan.
Should we turn computers off during a cyberattack?
In most cases, no. Disconnect affected machines from the network — unplug Ethernet, turn off Wi-Fi — but leave them powered on. Shutting down can destroy evidence that exists only in memory and can leave half-encrypted files unrecoverable. Let your incident-response team make the machine-by-machine call.
Should we pay the ransom?
Never decide alone. The stance is set with your attorney, your insurer, and their breach coach: payment does not guarantee working decryption, some payments carry legal risk depending on who receives them, and tested offline backups usually remove the leverage entirely. Whatever is decided, it is decided together and documented.
Do we have to report a cyberattack in Oklahoma?
Possibly, on several fronts: Oklahoma’s Security Breach Notification Act for unencrypted personal information of residents, HIPAA if health information is involved, the FTC Safeguards Rule’s 30-day notice for covered financial businesses, and notice clauses in your own client contracts. Which apply depends on the data involved — your attorney makes the final call.
Can we just restore from backups and move on?
Not until the backups are verified. Attackers deliberately target backup systems, and recent restore points can contain their tools if they were in your network for days before striking. Confirm the backups are intact, identify a clean restore point, and bring systems back in a planned order — identity and email first — with each layer checked.