Last materially reviewed: September 3, 2026
Direct Answer
After a business cyberattack, the first priorities are to stop the attack from spreading, protect critical accounts, preserve evidence, understand what systems and data were affected, restore operations safely and determine whether the incident triggers reporting or notification duties. Do not wipe devices, delete logs or rush systems back online before the scope of compromise is understood.
Key Takeaways
- Contain first, but preserve evidence.
- Secure administrator, email, finance and recovery accounts immediately.
- Document the timeline and every major action.
- Restore only from trusted systems and verified backups.
- Assess personal-data impact under the Data Privacy Act and NPC breach rules.
First 30 minutes
- Activate the incident owner and response contacts.
- Disconnect compromised devices or systems from networks where safe.
- Block known malicious accounts, sessions or credentials.
- Preserve logs, screenshots and alerts.
- Confirm that backups are protected from the attacker.
- Move coordination to a trusted channel if email may be compromised.
Protect high-value accounts
Reset compromised credentials, revoke suspicious sessions and check forwarding rules, recovery addresses and MFA changes. Prioritize email, domain registrar, cloud administration, banking, accounting and identity-provider accounts because attackers often use one compromised system to reach another.
Determine the scope
Identify affected users, devices, applications, cloud services, data and business processes. Look for initial access, persistence, lateral movement and data exfiltration rather than assuming the visible symptom is the whole incident.
Preserve evidence
Retain logs, security alerts, suspicious emails, transaction records, affected device details and a timeline of actions. Evidence can help technical responders, insurers, banks, regulators or law-enforcement agencies understand what happened.
Personal-data breach assessment
If personal data may have been accessed, altered, lost or disclosed, assess the incident under the Data Privacy Act and NPC breach rules. Not every cyberattack is automatically a reportable personal-data breach, but every relevant incident should be evaluated. See Data Breach Notification Philippines.
Recover safely
Do not reconnect systems simply because they appear functional. Remove persistence, patch exploited weaknesses, rotate credentials and restore from verified backups. Monitor for signs of reinfection after recovery.
Communications
Decide who communicates with employees, customers, vendors, banks, regulators and law enforcement. Keep statements factual and avoid speculating before the investigation establishes what is known.
After the incident
Conduct a lessons-learned review covering root cause, response delays, missing logs, access weaknesses, backup performance, training gaps and vendor issues. Update policies and technical controls rather than treating recovery as the end of the event.
FAQs
Should a business immediately shut down everything?
Not always. Containment should be targeted where possible so the business preserves evidence and avoids unnecessary operational damage.
Should a compromised device be reformatted immediately?
Usually not before evidence and scope are considered. Reformatting can destroy useful forensic information.
Who should businesses report cybercrime to?
Depending on the incident, reporting may involve the PNP Anti-Cybercrime Group, NBI Cybercrime Division, CICC or other authorities. Use the Cybercrime Reporting Directory.
