RESOURCE — IT EMERGENCY

Cyberattack — what to do now

When there is reason to believe a company has been attacked, one thing matters above all: stay calm and act in the right order. This guide lays out the most important immediate steps, the typical mistakes — and how to find out what is actually happening on your network.

Published: June 5, 2026 · 9 min read · AEGYS DATALYTICS editorial

If you are in the middle of an incident right now: take a breath. Hasty action often makes things worse. The steps below are ordered by urgency.

The first steps — in the right order

The order matters more than the speed. These steps apply regardless of who eventually helps you respond.

01

Stay calm and avoid hasty action

The first impulse is often to shut everything down or wipe systems immediately. That can destroy evidence and make later investigation harder. Get an overview first.

02

Isolate affected systems — do not destroy them

Disconnect affected devices from the network (unplug the cable, disable Wi-Fi) — but where possible, do not power them off and do not delete anything. Shutting down can erase volatile traces that are important for the investigation.

03

Inform the right people

Leadership, IT owners, and your IT service provider. Decide early who coordinates the response. In larger incidents, clear ownership is decisive.

04

Document what you observe

Capture what was noticed and when: time, affected systems, visible symptoms, actions taken. This record helps the investigation — and is valuable later for insurers and authorities.

05

Check legal reporting obligations

Depending on the type of incident and the data involved, there may be reporting obligations under data-protection law, often within tight deadlines. Clarify this early with qualified counsel.

06

Understand what actually happened

Before systems are restored, it should be clear what really took place on the network: which systems were affected, how far the activity reached, and whether communication is still running in the background. Without that view, there is a risk of missing part of the problem — and pulling it right back in after recovery.

Common mistakes in an emergency

  • Do not shut everything down in a rush. Volatile evidence is lost; investigation becomes harder.
  • Do not wipe and rebuild prematurely. A system restored too quickly can bring an unclosed gap right back with it.
  • Do not engage with extortion demands without qualified advice. Payments rarely solve the problem and carry their own risks.
  • Do not slip into activism. The right order beats blind speed.
  • Do not assume that removing the visible part ends the matter. The visible part is often only one piece.

How an incident typically unfolds

A cyberattack is rarely a single moment. It has phases — and each phase has a sensible response.

The phases of an incident

Contain

stop the spread

Understand

what happened, how far it reached

Remediate

remove malware, close the gap

Recover

bring systems back online

Learn

prevent next time

The phases of an incident. Understanding what actually happened decides whether remediation is truly complete.

Most incidents go through similar phases: containing (stop the spread), understanding (what happened, how far it reached), remediating (remove malware, close the gap), recovering (bring systems back online), and learning (what can be prevented next time). The step most often shortchanged in practice is understanding — under time pressure, teams remediate and recover before it is clear how far the activity actually reached. And anyone waiting for visible signs of compromise tends to see only the loud incidents like ransomware — quiet activity stays invisible unless someone actively looks.

OUR ROLE

See what is actually happening on the network during an incident

AEGYS DATALYTICS is not an incident-response firm that takes over the whole investigation — forensics, recovery, and negotiation belong to specialised IR teams and your IT service provider. What AEGYS contributes is the independent view of the network: the passively connected AEGYS Pulse appliance shows, during the incident, which systems are currently talking to which destinations, how far the activity reaches, and whether communication is still running in the background.

This view is valuable precisely in the phase that is often shortchanged — understanding. It helps your IT provider or IR team decide on facts instead of remediating in the dark. And after the acute phase it answers the question that otherwise stays open: is it really over — or is something still running that was missed during cleanup?

We work alongside your existing provider or IR partner. On request we make contact quickly to assess the situation together.

In the middle of an incident — or unsure whether it is really over?

We provide the independent view of your actual network activity and work alongside your IT service provider.

15 minutes to get oriented. If it's not a fit, we'll say so.

FAQ

Frequently asked questions about an IT emergency

Sources