In February 2024, Change Healthcare — one of the largest health payment processors in the U.S. — was hit by a ransomware attack that disrupted claims processing for thousands of hospitals, pharmacies, and clinics nationwide. UnitedHealth Group, its parent company, later confirmed the breach affected roughly 100 million individuals. The company paid a reported $22 million ransom. And yet, the fallout continued for months. If you're reading this because you want to know how to respond to a cyberattack, understand one thing: the quality of your first 72 hours determines whether you survive or spiral.

I've worked through incidents where the response was textbook and the damage was contained in hours. I've also seen organizations freeze, make panicked decisions, and turn a manageable incident into a catastrophic one. The difference is almost never about having better technology. It's about having a plan, practicing it, and executing it under pressure.

How to Respond to a Cyberattack: The First 60 Minutes

The initial hour after detection is chaos. Alerts are firing, employees are confused, and leadership wants answers you don't have yet. Here's what actually matters in those first 60 minutes.

Step 1: Confirm the Incident Is Real

Not every alert is an active breach. Your security team needs to triage fast — determine whether you're looking at a false positive, a minor policy violation, or a genuine threat actor inside your environment. Check your SIEM, endpoint detection tools, and network logs. Talk to the person who reported the anomaly.

But don't take too long. According to the Verizon 2024 Data Breach Investigations Report, the median time for a user to fall for a phishing email is under 60 seconds. Attackers move fast. Your confirmation process should take minutes, not hours.

Step 2: Activate Your Incident Response Team

If you don't have a designated incident response (IR) team, you're already behind. Your IR team should include representatives from IT, security, legal, communications, and executive leadership. Every person should know their role before an incident happens.

Call the team together immediately. Use an out-of-band communication channel — not your corporate email or Slack, which may be compromised. I've seen organizations try to coordinate their response over the same systems the attacker was actively monitoring. Don't make that mistake.

Step 3: Contain the Threat

Containment is your top priority. Isolate affected systems from the network. Disable compromised accounts. Block malicious IPs and domains at the firewall. If you're dealing with ransomware, disconnect infected machines immediately — but do not power them off, as volatile memory may contain forensic evidence.

CISA's StopRansomware guide is one of the best practical references for containment actions. Bookmark it now, before you need it.

What Comes After Containment: Investigation and Eradication

Once you've stopped the bleeding, the real work begins. You need to understand what happened, how the threat actor got in, and what they accessed or exfiltrated.

Determine the Attack Vector

Was it a phishing email that led to credential theft? A vulnerable VPN appliance? A compromised third-party vendor? The Verizon DBIR consistently shows that the human element is involved in the majority of breaches — social engineering and stolen credentials remain the top attack vectors year after year.

Trace the attack back to its origin. Review email logs, authentication records, and endpoint telemetry. If you don't have the internal capability, bring in a digital forensics firm. This is not the time to guess.

Eradicate the Threat Actor's Presence

Containment stops the spread. Eradication removes the attacker entirely. This means patching the exploited vulnerability, removing malware and backdoors, resetting all compromised credentials, and revoking unauthorized access tokens.

Here's a mistake I've seen repeatedly: organizations reset the passwords for the accounts they know were compromised but skip everything else. Sophisticated threat actors establish multiple persistence mechanisms. If you only address the obvious ones, they'll be back within days.

The $4.88M Lesson in Delayed Communication

IBM's 2024 Cost of a Data Breach Report pegged the global average cost of a data breach at $4.88 million. One of the biggest cost amplifiers? Delayed notification and poor communication.

Notify the Right People at the Right Time

Your legal team should guide notification timing based on applicable regulations — GDPR requires 72-hour notification to supervisory authorities, while U.S. state breach notification laws vary. The FTC's Health Breach Notification Rule imposes strict requirements on health-related data.

Notify law enforcement. File a report with the FBI's Internet Crime Complaint Center (IC3). They may have intelligence on the threat actor that helps your investigation. Don't assume reporting makes things worse — in my experience, it almost always helps.

Communicate Clearly With Stakeholders

Your customers, employees, board, and partners all need to hear from you — but they need different messages. Customers want to know if their data is safe. The board wants to know about financial and legal exposure. Employees want to know if their jobs and personal information are affected.

Draft holding statements in advance as part of your incident response plan. Trying to write clear communications while your network is burning is a recipe for PR disaster.

What Does an Effective Cyberattack Response Plan Include?

An effective cyberattack response plan includes six core phases: preparation, identification, containment, eradication, recovery, and lessons learned. It designates an incident response team with defined roles. It includes communication templates, escalation procedures, contact lists for legal counsel and forensic firms, and a tested backup and recovery strategy. Most importantly, it's practiced through tabletop exercises at least twice a year. A plan that only exists in a binder on a shelf isn't a plan — it's a liability.

Recovery: Getting Back to Business Without Getting Hit Again

Recovery isn't just about restoring from backups. It's about restoring trust and hardening your environment so the same attack can't succeed twice.

Restore From Clean Backups

Verify your backups are clean before restoring. I've seen organizations restore from compromised backups and reintroduce the same malware they just spent days eradicating. Test backup integrity in an isolated environment first.

Implement Immediate Hardening Measures

Enforce multi-factor authentication across every account — especially privileged ones. Segment your network. Deploy endpoint detection and response (EDR) if you haven't already. Move toward a zero trust architecture where no user or device is inherently trusted.

These aren't aspirational goals. They're the minimum standard after an incident.

Prevention Is Cheaper Than Response — Every Single Time

Every dollar you invest in prevention saves multiples in response costs. And the most cost-effective investment you can make is in your people.

Most cyberattacks start with a human being making a mistake — clicking a phishing link, reusing a password, trusting a spoofed email. Your employees are your largest attack surface and your most effective defense, depending on their training.

If your organization hasn't implemented a structured cybersecurity awareness training program, you're leaving your front door unlocked. Consistent training reduces the likelihood of successful social engineering attacks dramatically.

And generic training isn't enough. Your team needs to face realistic attack simulations. A dedicated phishing awareness training program for organizations gives employees the pattern recognition they need to spot credential theft attempts before they click. Phishing simulation results also give you measurable data on your organization's risk posture — data you can take to leadership and act on.

The Post-Incident Review Nobody Wants to Do

After the adrenaline fades, most teams want to move on. Don't. The post-incident review — sometimes called a lessons-learned session or after-action report — is where real improvement happens.

Ask the Hard Questions

How long did it take to detect the intrusion? Where did your response plan break down? Were there tools or permissions gaps that slowed containment? Did any employees or departments not know their role?

Document everything honestly. Assign owners to each remediation item. Set deadlines. Then follow up. The organizations that get breached twice are the ones that skip this step.

Update Your Plan Based on Evidence

Your incident response plan should be a living document. After every incident — and after every tabletop exercise — update it. Add new threat scenarios. Revise contact lists. Incorporate new tools and processes. The threat landscape shifts constantly, and your plan needs to shift with it.

Knowing How to Respond to a Cyberattack Starts Before the Attack

The time to figure out how to respond to a cyberattack is not during the attack. It's right now. Build your plan, train your team, practice your response, and invest in the security awareness programs that keep incidents from happening in the first place.

The organizations that survive breaches aren't the ones with the biggest security budgets. They're the ones that prepared, practiced, and treated cybersecurity as a business function — not an IT afterthought.