Skip to content
Skip to article text

Cyber attack on my business – what do I do? Emergency help for SMEs

IT lead in an SME working through an emergency checklist after a cyber attack

After a cyber attack, the first 2 hours count. The emergency checklist for SMEs, reporting duties and deadlines – plus prevention without an IT team.

What to do after a cyber attack – the short answer

In an emergency, the first 2 hours count: isolate affected systems (disconnect from the network), do not try to delete or decrypt yourself, bring in IT security experts and, for serious attacks, inform the BSI and the police. Damage assessment follows. If you have planned this response chain in advance, nobody has to guess in a crisis – exactly what Beraterium supports SMEs with as part of the risk analysis for mid-market businesses.

This article delivers both: the emergency checklist for the acute case and the prevention that stops it getting that far.

The first 2 hours: emergency checklist

Work through these steps in order – speed beats perfection:

  1. Isolate systems: Disconnect affected PCs and servers from the network (unplug LAN cable, disable Wi‑Fi). Do not shut down – forensic traces sit in memory.
  2. Delete nothing, decrypt nothing: No DIY rescue attempts, no payment of ransom demands. Both almost always make things worse.
  3. Activate emergency contacts: Call your IT provider or security experts. Numbers belong on paper or in a personal phone – not only on a possibly encrypted system.
  4. Secure access: Change all passwords for central accounts (email, bank, cloud) from a clean device; check two-factor authentication.
  5. Document the situation: Photos of screens, times, affected systems – important for insurer, police and reporting duties.
  6. Start notification chains: For serious attacks, inform the BSI and police (ZAC); if data has leaked, the data protection authority (see next section).

Who must I inform – and by when?

After an attack, several deadlines run in parallel. The most important at a glance:

  • Data protection authority (GDPR Art. 33): Within 72 hours if personal data protection is breached – that applies to practically every attack where customer or employee data may have leaked.
  • BSI (NIS2-regulated businesses only): Initial notification within 24 hours, assessment notification within 72 hours, final report after one month. Whether your business falls under NIS2 and what management is personally responsible for is explained on NIS2 for SMEs.
  • Police / ZAC: No fixed deadline, but strongly recommended – state criminal investigation cyber contact points specialise in businesses and work discreetly.
  • Cyber insurer: Immediately, or you risk cover. Many policies also provide their own incident response teams.
  • Affected individuals: Under GDPR, high risk to customers or staff may require direct notification.

How do I protect myself preventively – without my own IT department?

The good news: the most effective measures against common attacks (phishing, ransomware, stolen passwords) are achievable for any SME:

  • Two-factor authentication on all accounts, without exception – the cheapest protection with the greatest effect.
  • Offline backups following the 3-2-1 rule (three copies, two media, one off-site) – and test at least quarterly that restore really works.
  • Automatic updates for operating systems and all programmes.
  • Password manager instead of reused passwords.
  • Short, regular training: Most attacks start with an email to a person, not a hack of technology.
  • Written emergency plan: Who does what, who is called, where are backups? On paper, not only digitally.

Deeper scenarios and measure packages for mid-market businesses: Cyber attacks as a business risk.

How does Beraterium place cyber risk in the overall risk analysis?

Cyber is a major risk for most SMEs – but rarely the only one and not always the largest. In Beraterium's three-tier hazard catalogue, cyber risk is captured alongside outage, market and financial risks, assessed in euros and prioritised in the risk matrix. The result: you see in black and white whether a ransomware shutdown or, say, the loss of a key person would hit your business harder – and you invest budget where it reduces risk most. The basics of this approach are explained in What is risk management?.

If you want to know where your business stands today: in a free intro call we clarify in 30 minutes which risks should top your list – cyber included.

Frequently asked questions

What do I do if my business is affected by a cyber attack?

In an emergency, the first 2 hours count: isolate affected systems (disconnect from the network), do not try to delete or decrypt yourself, bring in IT security experts and, for serious attacks, inform the BSI and the police. Damage assessment follows. Beraterium helps SMEs plan this response chain in advance – so nobody has to guess in a crisis.

Should I pay the ransom in a ransomware attack?

The BSI and police clearly advise against it. Payment guarantees neither decryption nor prevents a second extortion – and it funds further attacks. More important is to involve experts immediately and check whether clean backups exist before anything is deleted or rebuilt.

Who must I inform after a cyber attack?

If personal data is lost, the relevant data protection authority within 72 hours (GDPR Art. 33). NIS2-regulated businesses report significant incidents to the BSI: initial notification within 24 hours, assessment within 72 hours, final report after one month. Also advisable: report to the Central Contact Point Cybercrime (ZAC) of the state police and inform your cyber insurer.

How do I protect my SME from cyber attacks without my own IT department?

The most effective baseline measures need no IT department: two-factor authentication everywhere, automatic updates, separate offline backups with regular restore tests, a password manager and short staff training against phishing. Crucially, a written emergency plan with responsibilities and contact details – reachable even when systems are down.

What does a cyber attack typically cost a small business?

The largest items are business interruption, system recovery and lost revenue – often far more expensive than direct damage. Depending on downtime, total costs for an SME can quickly reach five or six figures. That is why Beraterium assesses cyber risk in euros so prevention and insurance cover match actual damage potential.

How does Beraterium place cyber risk in the overall risk analysis?

Cyber risks are one of several hazard classes in Beraterium's three-tier hazard catalogue. They are not viewed in isolation but assessed in euros together with outage, market and financial risks and prioritised in the risk matrix – so you see whether cyber is truly the most urgent risk or another topic should come first.

Clarify risks in your business?

Book a free intro call – 30 minutes, no obligation.

Book a free intro call