What to do after a cyber attack – the short answer
In an emergency, the first 2 hours count: isolate affected systems (disconnect from the network), do not try to delete or decrypt yourself, bring in IT security experts and, for serious attacks, inform the BSI and the police. Damage assessment follows. If you have planned this response chain in advance, nobody has to guess in a crisis – exactly what Beraterium supports SMEs with as part of the risk analysis for mid-market businesses.
This article delivers both: the emergency checklist for the acute case and the prevention that stops it getting that far.
The first 2 hours: emergency checklist
Work through these steps in order – speed beats perfection:
- Isolate systems: Disconnect affected PCs and servers from the network (unplug LAN cable, disable Wi‑Fi). Do not shut down – forensic traces sit in memory.
- Delete nothing, decrypt nothing: No DIY rescue attempts, no payment of ransom demands. Both almost always make things worse.
- Activate emergency contacts: Call your IT provider or security experts. Numbers belong on paper or in a personal phone – not only on a possibly encrypted system.
- Secure access: Change all passwords for central accounts (email, bank, cloud) from a clean device; check two-factor authentication.
- Document the situation: Photos of screens, times, affected systems – important for insurer, police and reporting duties.
- Start notification chains: For serious attacks, inform the BSI and police (ZAC); if data has leaked, the data protection authority (see next section).
Who must I inform – and by when?
After an attack, several deadlines run in parallel. The most important at a glance:
- Data protection authority (GDPR Art. 33): Within 72 hours if personal data protection is breached – that applies to practically every attack where customer or employee data may have leaked.
- BSI (NIS2-regulated businesses only): Initial notification within 24 hours, assessment notification within 72 hours, final report after one month. Whether your business falls under NIS2 and what management is personally responsible for is explained on NIS2 for SMEs.
- Police / ZAC: No fixed deadline, but strongly recommended – state criminal investigation cyber contact points specialise in businesses and work discreetly.
- Cyber insurer: Immediately, or you risk cover. Many policies also provide their own incident response teams.
- Affected individuals: Under GDPR, high risk to customers or staff may require direct notification.
How do I protect myself preventively – without my own IT department?
The good news: the most effective measures against common attacks (phishing, ransomware, stolen passwords) are achievable for any SME:
- Two-factor authentication on all accounts, without exception – the cheapest protection with the greatest effect.
- Offline backups following the 3-2-1 rule (three copies, two media, one off-site) – and test at least quarterly that restore really works.
- Automatic updates for operating systems and all programmes.
- Password manager instead of reused passwords.
- Short, regular training: Most attacks start with an email to a person, not a hack of technology.
- Written emergency plan: Who does what, who is called, where are backups? On paper, not only digitally.
Deeper scenarios and measure packages for mid-market businesses: Cyber attacks as a business risk.
How does Beraterium place cyber risk in the overall risk analysis?
Cyber is a major risk for most SMEs – but rarely the only one and not always the largest. In Beraterium's three-tier hazard catalogue, cyber risk is captured alongside outage, market and financial risks, assessed in euros and prioritised in the risk matrix. The result: you see in black and white whether a ransomware shutdown or, say, the loss of a key person would hit your business harder – and you invest budget where it reduces risk most. The basics of this approach are explained in What is risk management?.
If you want to know where your business stands today: in a free intro call we clarify in 30 minutes which risks should top your list – cyber included.
