Skip to main content
28 August, 2024
# Topics
Follow Us

Your Houston Business Just Got Hit by a Cyberattack. Here's What to Do in the Next 60 Minutes.

24 August, 2026

The first 60 minutes after a cyberattack are the most important—and the easiest time to make a mistake that amplifies the damage. Turning off the wrong machine can destroy forensic evidence. Sending messages from a compromised account can give an attacker even more access. Making a ransom payment in the first panicked hour, before you understand what you are dealing with, is among the most expensive decisions a Houston business can make.

This is the step-by-step response for when something goes wrong. None of these steps require technical expertise. They are the actions any team member can take correctly before your IT provider arrives. For Houston businesses without a managed cybersecurity plan in place, having this response committed to memory—or printed and posted somewhere—is the minimum preparation that can limit the damage significantly.

What Not to Do First

Four common reactions in the first minutes of an attack make the situation measurably worse.

Do not power off the affected computer. If you can avoid it. Evidence stored in memory—encryption keys, attacker tools, event logs that document what happened—can be wiped the moment a machine shuts down. Disconnecting from the network is almost always the better first step.

Do not delete anything. Leave the ransom note on screen. Leave the suspicious email in the inbox. Leave the pop-up exactly where it is. Everything that documents the attack is what your IT team and investigators need to understand what happened and how far it spread.

Do not use a compromised email account to discuss the attack. If an attacker has access to your inbox, they can read every message you send. Switch to a phone call or a separate personal account for anything related to the incident.

Do not pay the ransom in the first hour. That decision requires input from law enforcement, your cyber insurance carrier, and your IT provider. It is not a decision to make alone under pressure.

The Six Steps to Take Right Now

Step 1: Disconnect the Affected Devices from the Network

Unplug the network cable and disable Wi-Fi on anything that appears compromised. This stops the problem from spreading to other machines and, critically, to your backups. CISA guidance is to isolate rather than power off—only shut a device down completely if you cannot get it off the network by any other means.

Step 2: Call Your IT Provider by Phone—Not Email

If an attacker has access to your email, they are reading it. Call your managed IT provider in Houston or cybersecurity team’s emergency line directly. If you carry cyber insurance, call the insurer’s incident response team as well. Many policies require early notification to trigger coverage, and delaying that call can affect your claim.

Step 3: Leave the Evidence Alone

Take screenshots of the ransom note, suspicious emails, and error messages. But leave the originals exactly where they are. Do not wipe, reinstall, or clean up affected machines until your IT team has preserved what is there. The evidence determines the scope of the breach and what data may have been exposed.

Step 4: Call Your Bank Immediately If Money Has Moved

If a wire transfer has already gone to a fraudulent account, call your bank within the hour and request a wire recall. Then report the fraud to the FBI’s Internet Crime Complaint Center at ic3.gov as quickly as possible. The FBI’s Recovery Asset Team reports approximately a 70% success rate recovering wire fraud funds when reports arrive within 72 hours of the transfer. Every hour beyond that reduces the probability of recovery.

Step 5: Reset Passwords from a Clean, Unaffected Device

Start with email and administrator accounts. Use a device you know was not connected to the affected system—a personal phone or a machine in a different physical location. Enable multi-factor authentication on anything that does not already have it. This step blocks the attacker from continuing to use credentials they may have already captured.

Step 6: Report It

In the United States, file with the FBI’s Internet Crime Complaint Center at ic3.gov and with CISA. If personal data belonging to your clients or employees may have been exposed, Texas law and federal regulations impose notification timelines—often 72 hours for certain categories of data. Your legal counsel or managed IT provider can confirm what reporting requirements apply to your specific situation and industry.

Should Your Houston Business Pay the Ransom?

The FBI does not recommend it. Paying does not guarantee your data is returned or that the attacker does not sell it anyway. It also marks your organization as one that pays, which invites future attacks. That said, it is ultimately your decision—but make it with your IT provider, your cyber insurer, and ideally law enforcement present. Before any payment is considered, check whether a free decryption tool already exists for the specific ransomware involved. In many cases, one does, and the payment is unnecessary.

What Elevate Technology Delivers for Houston Businesses

Elevate Technology provides managed cybersecurity services for businesses across Houston, Dallas, and San Antonio, including 24/7 monitoring, managed detection and response, and incident response planning developed before an attack occurs. Every element of the six-step response above is faster and less costly when infrastructure is already managed: monitored backups confirm within minutes whether clean copies exist; documented systems accelerate the scope assessment; and an emergency IT line means your team is already in motion while you are still on that first phone call. For context on how cyberattacks unfold, see our earlier post on why cyber threats never sleep. Houston businesses and Dallas companies that have never experienced a cyberattack often believe the risk is overstated. Businesses that have been through one do not make that assumption twice.

What is the single most important thing to do in the first five minutes of a cyberattack?

Get the affected device off the network by unplugging its cable and disabling Wi-Fi, then call your IT provider or managed cybersecurity team by phone. Isolating the device stops the attack from spreading to other computers and to your backups, and reaching your IT provider quickly gives them the maximum time to respond before evidence is lost or the attack escalates further.

We wired money before we realized it was fraud. What do we do?

Call your bank immediately and request a wire recall. Then report the fraud to the FBI’s Internet Crime Complaint Center at ic3.gov as quickly as possible. The FBI’s Recovery Asset Team reports approximately a 70% success rate recovering wire fraud funds when reports arrive within 72 hours of the transfer. Every hour matters. Your managed IT provider should also be notified immediately so they can assess whether the fraudulent wire was connected to a broader network compromise.

→ Talk to Elevate Technology about building a managed cybersecurity plan for your Houston business. Visit our Managed Cybersecurity page.