Quick Tip

What to Do in the First 5 Minutes of a Cyber Incident

Jul 19, 2026

"If we got hacked, we'd know right away." The logic-IT team hears this regularly from small-business owners. The reality is that many breaches go unnoticed for days or weeks, and when something suspicious does surface, the instinct to start clicking around and investigating on your own is one of the most damaging things you can do.

The first five minutes of a suspected cyber incident shape everything that comes after. Getting those minutes right can mean the difference between a contained problem and a full recovery nightmare.

Why the First Five Minutes Are So Critical

When an attacker is active on your network, every second of continued connection gives them more access. They can move from one device to others, pull data, plant additional tools, or lock files before anyone realizes what is happening. At the same time, the actions taken by well-meaning employees in those early moments often destroy the evidence an IT team needs to understand what happened and how far it spread.

Panic is normal. Acting on that panic without a plan is where things go wrong.

The Right Steps, in Order

  • Disconnect the device from the network first. Unplug the ethernet cable or turn off Wi-Fi on the affected machine. This cuts the attacker's access without disturbing what is on the device itself.
  • Do not power the device off. This is the most common mistake. Shutting down a computer can wipe the temporary memory that holds critical forensic information, including what processes were running, what connections were active, and what the attacker was doing. Your IT provider needs that data.
  • Do not log in, click through files, or try to find the problem yourself. Every action taken on a compromised machine can overwrite evidence or trigger additional malicious activity.
  • Call your IT provider before touching anything else. Give them a clear description of what you saw, when you saw it, and what, if anything, was done before the call. That information helps them move faster.

What logic-IT Sees Most Often

A significant portion of incident response work involves undoing actions taken before the call came in. An employee notices something strange, tries to investigate, runs a scan, or rest

Dealing with something similar at your business? We can help.

Talk to logic-IT
← Back to all posts