Cyberattack Response Plan: What Houston Businesses Should Do in the First Hour
If your business gets hit by a cyberattack, what you do in the first hour matters more than almost anything else. At Griffin Technology Solutions, we work with businesses across Houston, Texas to prepare for exactly this moment, because it's also the easiest time to make a costly mistake. Powering off the wrong machine, deleting evidence, or replying from a compromised email account can all make recovery harder.
This guide walks Houston business owners through the exact steps to take, in order, so you're not guessing under pressure. None of it requires technical expertise. It also covers where to report a cyberattack in the US, UK, and Australia.
Before Anything Else: Don't Make It Worse
Before you touch anything, avoid these common mistakes:
Don't turn the affected computer off, if you can avoid it. Disconnecting it from the network is safer, since powering it down can wipe evidence that helps determine what happened.
Don't delete anything. Leave the ransom note, the suspicious email, and any alerts exactly where they are. Your IT team and investigators will need them.
Don't pay a ransom on the spot.
Don't use the hacked email or accounts to discuss the attack. If an attacker is inside your inbox, they can read those messages. Switch to phone calls or a separate account instead.
Step-by-Step: Your Cyberattack Response Plan
Work through these steps in order, starting the moment you notice something is wrong.
Disconnect the affected devices from the network. Unplug the network cable and turn off Wi-Fi on anything that looks affected. This helps stop the problem from spreading to other computers and your backups. CISA recommends isolating devices rather than powering them off when possible, and shutting a device down only if you can't get it off the network any other way.
Call your IT provider right away, by phone. Avoid email in case the attacker is monitoring your inbox. If your business has cyber insurance, call your insurer next, since many policies require you to involve their incident response team early. Griffin Technology Solutions offers emergency IT support for Houston area businesses facing exactly this kind of situation.
Leave the evidence alone. Don't wipe, reinstall, or clean up the affected machines yet. Screenshots of the ransom note or suspicious emails are helpful, but keep the originals too.
If money was sent, call your bank immediately. Ask them to recall the transfer and freeze it if possible. With wire and bank fraud, acting within the first few hours makes the biggest difference.
Reset passwords from a clean device, and enable multi-factor authentication. Start with email and admin accounts, using a device you know hasn't been compromised.
Report the incident. Reporting can help with recovery, and it's sometimes legally required. Where you report depends on your location.
Where to Report a Cyberattack
Where you report an attack depends on where your business operates:
United States: File a report with the FBI's Internet Crime Complaint Center (IC3), and report to CISA.
United Kingdom: Report through the NCSC, and to Action Fraud.
Australia: Report through ReportCyber, or call the 24/7 hotline at 1300 CYBER1.
If money was wired to a scammer, report it fast. The FBI notes that reporting wire fraud to IC3 within 72 hours gives its Recovery Asset Team the best chance of recovering the funds, with a recovery rate of about 70% for cases reported in time.
If personal data belonging to your customers or staff was exposed, you may be legally required to notify a regulator and the affected individuals, sometimes within 72 hours. The specific rules depend on where you operate, including GDPR in the UK and Europe, state breach notification laws across the US (including Texas), and the Notifiable Data Breaches scheme in Australia. Loop in your lawyer or IT provider early so you don't miss a deadline.
Should You Pay the Ransom?
If it's a ransomware attack, the biggest question is whether to pay.
The FBI does not recommend paying. It doesn't guarantee you'll get your files back, it marks your business as one that pays, and the money helps fund future attacks.
The decision is ultimately yours, but it should be made alongside law enforcement, your IT or incident response team, and your insurer, not alone in a panicked first hour. In some cases, a free decryption tool already exists for the exact ransomware variant that hit you, which is one more reason to bring in experts before paying anyone.
The Best Time to Prepare Is Before It Happens
All of this is far easier if some of it has been decided in advance. You don't need a thick binder, just a simple plan that covers:
Who to call first (your IT provider, your insurer) and their phone numbers, stored somewhere you can access without your main systems.
Where your backups are, along with proof they've been tested by actually restoring from them.
Which accounts and devices matter most, so you know what to protect first.
A single page covering those three items is enough for most small businesses, and it will save a lot of scrambling if the day ever comes. If your Houston business needs help building a cyber incident response plan, Griffin Technology Solutions can help you put one together before you ever need it.
Frequently Asked Questions
What's the first thing to do in a cyberattack?
Disconnect the affected devices from the network by unplugging the network cable and turning off Wi-Fi, then call your IT provider by phone. Getting the device off the network helps stop the problem from spreading while you get help.
Should I turn off the computer if I get ransomware?
If you can, disconnect it from the network instead of powering it off. Shutting it down can wipe evidence stored in memory that helps determine what happened. Only power a device off if you can't get it off the network any other way.
Should I pay the ransom?
The FBI does not recommend it. Paying doesn't guarantee you'll get your data back, and it helps fund more attacks. Make this decision together with law enforcement, your IT or incident response team, and your insurer, and check whether a free decryption tool already exists first.
We wired money to a scammer. What do we do?
Call your bank immediately and ask them to recall the transfer. If you're in the US, report it to the FBI's IC3 within 72 hours, since cases reported quickly have about a 70% recovery rate through their Recovery Asset Team. Outside the US, contact your bank and your national reporting service right away.
Who do I report a cyberattack to?
In the US, report to the FBI's IC3 and CISA. In the UK, report to the NCSC and Action Fraud. In Australia, report through ReportCyber. Also notify your cyber insurer, and check whether you have a legal duty to notify a regulator if personal data was exposed.
Need Help Securing Your Houston Business?
Cyberattacks can happen to businesses of any size, and having a plan in place before disaster strikes makes all the difference. Griffin Technology Solutions provides proactive cybersecurity, IT support, and incident response planning for businesses throughout Houston, Texas. Contact us today to build a response plan that protects your business before an attack ever happens.

