1 October 2026

What To Do If Your Business Gets Hacked? A Step-by-Step Guide for SMBs in Shropshire and Shrewsburry

A hooded developer sitting in front of multiple computer monitors displaying green terminal code, HTML, and JavaScript

A cyber attack doesn’t always start with flashing warning signs. Sometimes the first clue is an employee who can’t access their email, a strange payment request, files that suddenly won’t open, or customers receiving suspicious messages from a company account.

So, what happens when a business gets hacked?

For a smalL-sized business, the answer can involve much more than simply changing a password. A cyber attack can affect computers, email accounts, customer data, finances and day-to-day operations.

The good news is that there is a process for responding. The National Cyber Security Centre (NCSC) has specific guidance for small-sized organisations covering preparation, identification, resolution, reporting and recovery.

Shropshire Computers has supported businesses with their IT for more than 3 years, and one of the most important things any business can have is a clear plan for what happens when something goes wrong.

Here’s what that process can look like.

What actually happens when a business gets hacked?

A “hack” can mean many different things. An attacker might steal a password, compromise an email account, infect a computer with malware, deploy ransomware or gain access to business data.

The NCSC lists several warning signs that can indicate a cyber incident, including unusual account activity, unauthorized payments, users being locked out, strange emails being sent from your domain and files becoming inaccessible.

Step 1: Someone notices something isn’t right

Imagine you’re the owner of a small engineering company in Shrewsbury.

It’s 9:15 on a Monday morning. One member of staff tells you they can’t access their email. A few minutes later, another employee says that several files on the shared drive won’t open.

Then you receive an email from your bank asking whether you authorised a payment.

At this point, you don’t know exactly what has happened.

It could be a technical problem. It could be an account compromise. It could be something much more serious.

This is where your response matters.

The NCSC recommends identifying what is happening and gathering information about the incident before deciding how to resolve it.

This scenario is fictional, but it demonstrates how an attack might become apparent in a real small business.

Step 2: The business needs to contain the attack

Once you suspect an attack, the priority becomes limiting the damage.

Depending on the incident, this could mean:

The exact response depends on what has happened. You don’t want employees randomly switching systems off, deleting files or wiping computers before someone has assessed the incident.

The NCSC specifically advises organisations with external IT providers to contact them when they experience a cyber incident.

What happens to a business’s data after a cyber attack?

One of the biggest questions following a hack is:

“What have they accessed?”

Unfortunately, you can’t answer that simply by looking at the computer that first showed the problem.

Attackers may gain access to accounts, files, cloud services, email systems or other connected resources. The investigation needs to establish what the attacker accessed and what they may have changed.

Customer and employee data

Businesses often hold personal information such as:

  • Names and addresses
  • Contact details
  • Customer records
  • Employee information
  • Financial information
  • Account details
  • Email correspondence

UK data protection law requires businesses to protect personal information and respond appropriately when a personal data breach occurs.

Emails and business accounts

An email account can be particularly valuable to an attacker.

If someone gains access to a business email account, they may be able to read conversations, impersonate employees or attempt to persuade customers and suppliers to make payments.

That’s why a compromised email account can become much more than an inconvenience. Here there’s more information on how to keep your email secure. 

Financial information

Cyber criminals may also target businesses because they want money.

For example, an attacker could compromise an account and attempt to redirect an invoice payment, or use stolen credentials to access financial services.

This is one reason why unusual payment requests should always receive additional scrutiny.

What should you do immediately after discovering a hack?

When a business discovers an attack, don’t try to solve everything at once.

The first objective is to understand and contain the incident.

Don’t panic or start deleting things

It can be tempting to start deleting suspicious emails, wiping computers or reinstalling software.

But information about what happened can help whoever investigates the incident.

Instead, record what you know:

  • When did you first notice the problem?
  • Which users are affected?
  • Which devices are affected?
  • What unusual activity have you noticed?
  • Has anyone received a suspicious email?
  • Have any payments or account changes occurred?

The NCSC’s small-business guidance recommends gathering information about the incident as part of the response process.

Contact your IT or cybersecurity provider

If you have an IT provider, contact them as soon as you suspect a serious incident.

A provider can help establish what happened, contain the attack, identify affected systems and begin the recovery process.

If the incident is preventing the organisation from operating normally, the NCSC has specific guidance for disruptive cyber attacks and provides a 24/7 reporting route for live cyber attacks.

Preserve evidence

Don’t assume the first computer you discover is the only affected device.

The investigation may need information from:

  • Computers and servers
  • Email accounts
  • Microsoft 365 or other cloud services
  • Firewalls and network equipment
  • Security software
  • Backups
  • Login records

The more information available, the easier it becomes to understand the attack.

Does a hacked business have to report the attack?

Potentially, yes, but not every cyber incident has the same reporting requirements.

If the attack involves personal data, the business needs to assess whether the breach creates a risk to people’s rights and freedoms.

Where a personal data breach is reportable to the Information Commissioner’s Office (ICO), the organisation generally needs to notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it.

That does not mean every cyber attack automatically requires an ICO report. The organisation needs to assess the nature and risk of the personal data breach.

Other incidents may also need reporting through appropriate channels. GOV.UK provides a service to help organisations determine where they should report a cyber incident.

For a business owner, this is another reason why having a response process matters. You don’t want to discover a potential data breach and then have to work out from scratch what you need to do.

How does a business recover after being hacked?

Stopping the attacker is only part of the job.

The business then needs to recover safely.

Removing the attacker’s access

The IT team needs to identify how the attacker gained access and make sure that route no longer works.

Depending on the incident, this might involve:

  • Resetting compromised passwords
  • Revoking stolen sessions or access tokens
  • Removing malicious software
  • Patching vulnerable systems
  • Securing email accounts
  • Reviewing administrator accounts
  • Checking other connected systems

The NCSC recommends actions such as patching software, cleaning infected machines, changing passwords and restoring services through backups as part of incident resolution.

Restoring systems and backups

This is where good backups can make a huge difference.

If ransomware has encrypted important files, for example, a business with reliable, tested backups may have a route back to normal operations without relying on the attacker.

But there’s an important distinction:

Having a backup isn’t the same as knowing you can recover from it.

Businesses should understand what they have backed up, how quickly they can restore it and whether their backups remain accessible during an attack.

Checking that everything is safe

Getting computers working again doesn’t necessarily mean the incident has finished.

The business needs confidence that the attacker no longer has access and that restored systems haven’t simply reintroduced the problem.

That investigation is one reason professional incident response can be valuable.

What can a small business do to prevent another attack?

No security strategy can promise that a business will never experience a cyber attack.

The objective is to reduce the likelihood of an attack succeeding and limit the damage when something does happen.

Use strong authentication

Protect important accounts with strong passwords and multi-factor authentication (MFA).

MFA adds another verification step, making it harder for an attacker to access an account using a stolen password alone.

Keep systems updated

Software updates don’t just add new features. They can also fix security vulnerabilities.

A business that consistently delays important security updates can leave known weaknesses exposed.

Maintain reliable backups 

Keep backups of important business data and make sure you understand how to restore them.

The NCSC recommends that organisations know how to restore backups following data loss, including ransomware incidents.

Train your staff

Employees don’t need to become cybersecurity experts.

They do need to know how to recognise suspicious emails, unexpected payment requests, unusual login prompts and other warning signs.

Have an incident-response plan

Perhaps the most overlooked step is deciding what you’ll do before something happens.

Your plan should answer simple questions:

  • Who do we contact first?
  • Who has authority to make decisions?
  • Which systems are critical?
  • Where are our backups?
  • How do we communicate with staff?
  • How do we communicate with customers?
  • Who handles potential data-breach reporting?

The NCSC’s small-business response-and-recovery guidance follows a similar structure: prepare, identify, resolve, report and learn.

Why having IT support before an attack matters

A cyber attack is difficult enough without having to find someone to help after it has already happened.

An established IT support relationship means your provider already understands your systems, users and technology environment.

That can make it easier to identify unusual activity and coordinate a response when something goes wrong.

For small businesses in Shropshire, this can be particularly valuable when there isn’t an internal IT department available to handle a serious incident.

The NCSC also advises businesses using external IT providers to contact them when responding to an incident.

The goal isn’t simply to have someone to call when your computer stops working.

It’s to have someone who understands your IT environment before you need them in an emergency.

Being hacked doesn’t have to mean being unprepared

So, what happens when a business gets hacked?

The immediate response usually involves identifying the incident, containing the threat, investigating what happened, assessing any data exposure, reporting where necessary and then safely restoring systems.

The most important things to remember are:

  • Act quickly: early containment can help limit the damage.
  • Don’t guess: get your IT or cybersecurity provider involved as soon as possible.
  • Understand your data: a cyber attack can involve more than the computer that first showed the problem.
  • Prepare beforehand: backups, MFA, updates, staff training and an incident-response plan can all make recovery easier.

For businesses across Shropshire, Shrewsbury and Telford, Shropshire Computers can help you review your existing IT security and understand where your biggest risks may be.

If you’re concerned about what would happen if your business were hacked tomorrow, get in touch with the Shropshire Computers team to discuss your cybersecurity requirements.

FAQ

What should I do if my business gets hacked?

First, try to contain the incident and prevent further unauthorised access. Contact your IT or cybersecurity provider immediately, record what you know and avoid deleting or altering potential evidence until the incident has been assessed.

Does a business have to report a cyber attack?

Not every cyber attack requires the same reporting. If the incident involves personal data, the business should assess the risk to individuals and may need to notify the ICO; reportable personal data breaches generally have a 72-hour notification window where feasible.

Can a hacked business recover its files?

Often, yes, depending on what happened and whether reliable backups are available. A proper recovery process should first make sure the attacker no longer has access before restoring systems and data.

How long does it take to recover from a cyber attack?

There is no single recovery time because incidents vary significantly in severity. A compromised email account may require a relatively contained response, while ransomware affecting servers and backups can cause much greater disruption.

Can a business prevent itself from being hacked?

No security measure can guarantee that a business will never be attacked. However, MFA, secure passwords, patching, backups, staff training, security monitoring and an incident-response plan can reduce risk and limit the impact of an incident.

Should a small business have an incident-response plan?

Yes. A simple plan can tell employees who to contact, what systems are critical, where backups are located and how the business should respond when something goes wrong. The NCSC specifically provides incident-response guidance for small and medium-sized organisations.

What is the difference between being hacked and a data breach?

A hack generally refers to unauthorised access to a system or account, while a data breach concerns unauthorised access to, loss of or disclosure of data. A cyber attack can therefore cause a data breach, but the two terms are not always interchangeable.

Subscribe to email news

Get occasional news, tips and tricks from us. We won’t use your email address for any other purpose.

More blog posts