What Happens After a Cyber Attack? The First 72 Hours for an Aberdeen SME

Quick answer: After a cyber attack, the first 72 hours decide how much damage you contain. You isolate affected systems without switching them off, preserve the evidence, work out what data was hit, and report a personal data breach to the ICO within 72 hours. The businesses that recover fastest are the ones that planned their response before anything went wrong.

Most conversations about cyber security stop at prevention. Firewalls, staff training, multi-factor login. All of that matters, and it is where Alto puts most of its effort. But there is a harder question that few Aberdeen business owners have a real answer to: what actually happens in the hours and days after an attacker gets through?

The National Cyber Security Centre put it plainly in its July 2026 recovery guidance. Organisations can and do recover from serious incidents, but recovery usually takes longer than leaders expect, and the first few hours shape everything that follows. This guide walks through that window from the point of view of a small or mid-sized Aberdeen business, so you know what the response looks like before you ever need it.

The first hour: contain, do not panic

The instinct when you spot a live attack is to pull the plug. Fight that instinct. Powering a machine off can wipe the volatile evidence a forensic investigator needs to work out how the attacker got in and what they touched. It can also trigger encryption routines in some ransomware strains.

Instead, the priority is containment. Disconnect affected devices from the network by unplugging the network cable or disabling Wi-Fi, but leave them running. Isolating a machine stops the spread while keeping the logs and memory intact. If your IT is managed, this is the moment your provider or in-house team should begin their incident response steps, not the moment you start troubleshooting alone.

A few practical actions belong in this first hour:

  • Disconnect affected systems from the network, but keep them powered on.
  • Stop using any account you suspect is compromised, and reset passwords from a clean device.
  • Start a simple written log with times: what you saw, when, and what you did.
  • Identify who is coordinating. Someone needs to be the single point of decision.

That written log matters more than it sounds. Insurers, investigators and the ICO will all ask for a timeline later, and memory is unreliable during a stressful day.

Hours 1 to 24: work out what was actually hit

Once the immediate spread is contained, the job shifts to understanding the scope. The NCSC recommends a short set of questions to anchor this: which systems and services are not working, is there any sign data has been taken or encrypted, and have you had any ransom demand or unusual account activity?

This assessment is slower and harder than most people expect. Working out exactly what data an attacker accessed often takes specialist tools and days of investigation, not a quick look. Resist the pressure to announce firm conclusions early. Saying “no customer data was affected” and then having to walk it back does more reputational harm than saying “we are still investigating and will update you.”

By the end of the first day you want a working answer to three things: what happened, what is affected, and who needs to know. That last point moves you into your legal duties.

Isolate affected devices but leave them powered on to preserve evidence

The 72-hour clock: your legal and reporting duties

This is where the specific 72-hour figure comes from, and it catches a lot of businesses out.

UK GDPR requires you to report the breach to the Information Commissioner’s Office within 72 hours of becoming aware of it, where there is a risk to people’s rights and freedoms. That clock starts when you become aware, not when you finish investigating. Under UK GDPR, penalties for serious data protection failures can reach 17.5 million pounds, so this is not a formality to leave until the dust settles.

There are other bodies to notify, and each has a different purpose:

  • Action Fraud (0300 123 2040) is the reporting route for the crime itself, and for many businesses is a requirement of their cyber insurance policy.
  • The NCSC offers support and threat intelligence, and wants to hear about significant incidents, particularly those affecting essential services or large volumes of data.
  • Your cyber insurer should be told early. Many policies require prompt notification and will appoint an approved forensic and legal team. Calling them late can affect your cover.

Contracts with larger organisations may add another layer. Your agreement can oblige you to notify that client within a set number of hours. In Aberdeen’s energy supply chain, those clauses are common, which we will come back to.

Why the aftermath costs more than the attack

The visible part of an attack, the locked screens and the downtime, is often the cheaper part. The real cost lands afterwards: investigating what was taken, rebuilding systems, notifying customers and handling their questions, and repairing trust.

Recovery timelines are sobering. Industry response guides for UK SMEs typically describe two to six weeks of meaningful disruption and 30 to 90 days to full recovery, and the NCSC warns it is common to operate with limited IT for weeks. A share of businesses never fully recover at all.

The single biggest factor in how quickly you bounce back is your backups. Not just whether you have them, but whether they are recent, tested, and out of the attacker’s reach. Some organisations have had to rebuild applications from scratch because their backups were encrypted in the same attack. Immutable backups, ones that cannot be altered or deleted once written, are what turn a potential closure into a bad week.

The 72-hour ICO reporting clock starts when you become aware of a breach

What this means for an Aberdeen SME specifically

National guidance is useful, but Aberdeen businesses face a few local pressures worth naming.

The North East economy runs heavily on the energy supply chain. Operators, drilling contractors, subsea firms and engineering suppliers sit in tightly linked networks where one company’s breach can ripple to its clients. That interdependence is exactly why larger operators increasingly demand security assurances from their suppliers, often written into tenders and framework agreements. If you supply the sector and you cannot demonstrate a credible response plan, you risk more than the incident itself. You risk the contract.

There is also a practical support gap. During a live incident you need someone who can act quickly, on-site or remotely, and who understands the local business context. A national helpline that dispatches an engineer with next-day parts to an AB postcode is not the same as a provider who already knows your systems. This is the case for working with a local managed security partner rather than assembling a response team while the clock is running. You can read more about how we approach this on our cyber security services in Aberdeen page.

The mistakes that make recovery slower and more expensive

A few avoidable errors turn a contained incident into a drawn-out one:

  • Acting too fast in the wrong direction. Wiping or rebuilding a machine before it is investigated destroys evidence and can breach insurance conditions.
  • No clear owner. When everyone assumes someone else is calling the insurer or the ICO, the deadlines slip.
  • Unmanaged tools and accounts. Shadow systems that IT does not know about are often where attackers get in and hide. We wrote about this in Shadow AI is already in your business, and the same logic applies to any unsanctioned app.
  • Backups nobody has tested. A backup you have never restored is a theory, not a safety net.
  • Going quiet with customers. Silence reads as either incompetence or a cover-up. A calm, honest holding message buys goodwill.

Tested, immutable backups are the biggest factor in fast recovery

How to prepare before it happens

You cannot control whether you are targeted, but you can control how ready you are. The businesses that treat the first 72 hours as a plan, not an improvisation, come out of incidents faster and cheaper.

Three things carry most of the weight:

A written incident response plan

It does not need to be 50 pages. It needs to answer three questions for anyone in your business at 2am: what do I do right now, who do I call, and what has to happen within 72 hours. Keep a copy offline, because the attack may take your systems with it.

Tested, immutable backups

Confirm your backups are running, are stored where an attacker cannot reach them, and can actually be restored. Test a restore on a schedule, not just when you need it.

Monitoring that catches the attack early

The gap between an attacker getting in and you noticing is where most damage happens. Continuous monitoring through a security operations centre shrinks that gap, so an incident is caught in minutes rather than discovered weeks later. This is the difference between a contained event and a full-scale recovery, and it is why we treat prevention and detection as one job, not two. If you are weighing up tools and providers, our thinking in you do not need to ban AI, you need a shortlist applies here too: fewer, well-chosen, properly managed systems beat a sprawl of half-configured ones.

Frequently asked questions

Do I have to report a cyber attack in the UK?

Where the attack involves personal data and poses a risk to the people it relates to, you must report it to the ICO within 72 hours of becoming aware. You should also report the crime to Action Fraud, notify your cyber insurer, and inform the NCSC for significant incidents. Contracts with larger clients may add their own notification deadlines.

How long does it take to recover from a cyber attack?

For most UK SMEs, expect two to six weeks of meaningful disruption and 30 to 90 days to return to normal, though it varies widely with the type of attack and the quality of your backups. The NCSC notes that full recovery often takes many months, so plan for a marathon, not a sprint.

Should I pay the ransom if I am hit by ransomware?

Law enforcement and the NCSC advise against paying. There is no guarantee you get your data back, it marks you as a business willing to pay, and it funds further crime. Payment can also raise legal and insurance complications. Good, tested backups remove the incentive to pay in the first place.

What is the very first thing to do after a cyber attack?

Contain it without destroying evidence. Disconnect affected devices from the network but leave them powered on, stop using any compromised accounts, and start a written log of what you are seeing. Then bring in your IT or security provider to begin formal incident response.

Can a small Aberdeen business really be a target?

Yes. Attackers automate their scanning and often go for the least defended, not the largest. Smaller firms in the energy supply chain are also targeted as a route into their bigger clients, which is why supply chain security assurances are increasingly written into North East contracts.

Prepare before the clock starts

The worst time to work out your response is during the attack. If you are not confident you could contain an incident, meet your 72-hour reporting duty and restore from clean backups, that is a gap worth closing now while it is cheap to fix.

Alto is a managed security provider based in Aberdeen. We help North East businesses prepare their incident response, harden their backups, and monitor for threats so problems are caught early. Book a cyber security review and we will show you exactly where you stand before an attacker does.

Recent case studies

Cloud Machine Management

Cloud Machine Management

We worked with Aberdeen oil service company, Unity Well to migrate the management of their devices from on-site infrastructure to Microsoft’s cloud based Azure Active…
Read more
Sharepoint Data Migration

Sharepoint Data Migration

We completed a data migration project for an Aberdeen engineering company, Caledonia Services. We migrated their corporate data from on-site infrastructure to cloud based storage…
Read more

Discover Hidden Gaps in Your IT Security

✓ Takes 3 minutes ✓ No obligation ✓ Instant results
Get a comprehensive analysis of your IT infrastructure and security posture. See exactly where you're vulnerable and how much it's costing your business.