It’s Monday, 7:40 am. An employee can’t open their files. An unusual message appears on the server screen. Or a client calls to report a strange e-mail sent from your address.

What happens in the hours that follow determines a large part of the final bill. Not because you need to move fast, but because certain instinctive reactions, taken in a panic, destroy information that will later prove essential.

This article should be read in order. It is designed to be followed as the situation unfolds. If you are reading it calmly, ahead of time, the next step is to turn this procedure into a document specific to your company, with your own names and numbers: that is the subject of our article on the incident response plan.

The first minutes: isolate without destroying

The first objective is to stop the attack from spreading. The second, just as important, is to preserve the state of the affected machines.

In practice, on every affected computer or server: unplug the network cable, turn off Wi-Fi, disconnect external drives and shared folders. The machine stays on, but it no longer talks to anything.

Do not shut down, do not reformat

This is the most counter-intuitive reflex in this article, and the most important one. Some traces of an attack exist only in RAM, the computer's working memory: running processes, open connections to the outside, sometimes even decryption keys. All of this disappears when the machine is switched off. By shutting down "to stop the damage", you erase what would have helped you understand how the attacker got in and how far they went. Isolate from the network, leave it powered on.

The same logic applies to everything else. Do not reinstall anything, do not reformat anything, do not delete the suspicious file, do not empty the recycle bin. What looks like cleaning up to you is, to someone whose job this is, a piece of evidence.

If the attack appears to be spreading widely, isolating the entire network from the internet, at router or firewall level, is a legitimate decision. It comes at a high cost in terms of business activity, but it stops any data exfiltration in progress.

Who to notify in the first hour, and in what order?

An SME does not have a crisis unit. It has a handful of people who need to learn within minutes that they are caught up in it. The order matters.

WhoWhenWhy
ManagementImmediatelyThe only ones who can halt operations, commit expenses, and decide on communication
IT providerWithin the following minutesThey know your infrastructure and can take technical action
InsurerWithin the hourMany cyber policies require prompt notification and impose their own experts
NCSCThe same dayA voluntary, free report that feeds the national monitoring effort
Cantonal policeThe same day if extortion, fraud, or data theft is involvedInsurers often require a police report, and these are criminal offences

Two clarifications about the authorities. Reporting to the National Cyber Security Centre (NCSC) is voluntary for an ordinary SME: the reporting obligation that came into force in 2025 only applies to operators of critical infrastructure. It remains useful, and it is free.

Insurance is the line most often forgotten, and it is the one that is most costly to neglect: many policies require the insurer to be notified before any technical intervention, and a late declaration can void coverage. What cyber insurance actually covers, and what it leaves you to bear, is best read calmly, ahead of time, not on that particular morning.

As for the police, filing a report is far from a mere formality. Ransomware amounts to extortion, CEO fraud to fraud in the criminal sense. These are criminal offences, and your insurer will very likely ask for the receipt.

The scale of the phenomenon is anything but marginal: the NCSC received 64,733 voluntary cyber-incident reports in 2025, up from 62,954 the year before. You are neither the first nor an isolated case.

The first hours: documenting and regaining control of access

While the technical response is being set up, someone needs to write things down. This role is hard to delegate and is systematically forgotten.

Open a logbook, on paper

A sheet of paper, a pen, and the time written before every line. What was observed, at what moment, by whom. What was done, and who decided it. Screenshots of the messages displayed. The people notified. This document is what your insurer will ask for, and what the technical analysis will rely on. On paper, because your usual tools may be compromised, and because a notebook never breaks down.

Next comes the question of passwords. They need to be changed, starting with the most sensitive accounts: e-mail, e-banking, website administration, remote access, administrator accounts.

One absolute condition, though: do this from a machine you trust. A personal computer not connected to the company network, a mobile phone. Changing a password from an infected computer amounts to handing the new one straight to the attacker, who may well be recording your keystrokes.

While you’re at it, enable two-factor authentication everywhere it is not yet in place. This is the moment when the argument for it is no longer up for debate.

What to do if your e-mail is compromised?

This case deserves separate treatment, because it changes the way the entire crisis must be managed.

If your business e-mail is compromised, the attacker is reading your e-mails in real time. That means they can see your discussions about the incident: what you have discovered, which machines you are isolating, when you plan to restore.

Never coordinate a crisis through potentially compromised channels

As long as you do not know the extent of the intrusion, treat the company's e-mail and instant messaging as being read by the attacker. Switch to the phone, or to a personal messaging app on clean devices. Also check the automatic forwarding rules on your mailboxes: creating one to discreetly receive a copy of everything is a classic move, detailed in our article on e-mail compromise.

Personal data: what does Swiss law require?

If the incident has exposed personal data belonging to customers, employees, or suppliers, a notification obligation may also apply. The Swiss regime is often misunderstood, because it gets confused with the European one.

The Federal Act on Data Protection (FADP) provides for a notification to the Federal Data Protection and Information Commissioner (FDPIC) when the breach is likely to result in a high risk to the personality or fundamental rights of the persons concerned. Three points to remember.

The notification must be made as soon as possible. Swiss law sets no specific numerical deadline. The 72 hours you hear about everywhere are a rule from the European regulation, which only applies here if your company otherwise falls within its scope.

It is only owed in the event of high risk, not for every incident. Encrypted computers without any data theft do not automatically trigger the obligation. This assessment requires knowing what actually left the system, which is not obvious in the first few hours.

Finally, reporting does not expose you to criminal liability: the law states that the notification cannot be used in criminal proceedings against the person who made it, without their consent. Fear of sanctions is therefore no reason to stay silent. The details of the procedure and the form are covered in our article on reporting a data breach.

As a rule, any doubt about the qualification should be resolved with a lawyer, not alone on a Monday morning.

Can backups be restored on day one?

Once the initial shock has passed, the pressure becomes economic. The business is at a standstill, and everyone wants to get going again. This is where the second costly mistake happens.

Restoring a backup without knowing how the attacker got in is like rebuilding the house without having closed the door. If the flaw is still there, or if an access point has been left in place, the restored environment gets compromised again, sometimes within less than twenty-four hours. Some companies end up experiencing two attacks in a single week this way.

You can, however, prepare the ground without any risk: check that your backups exist, that they are clean, and how far back they go. If this check worries you, our article on the 3-2-1 backup rule explains what should have been in place.

The same caution applies to public communication. A statement written in the heat of the moment, based on facts that are still unclear, will need to be corrected, and it is the correction that people will remember. Inform the people directly concerned, factually, once you know. The choice of timing, channel, and wording is covered in detail in our article on communicating during a cyberattack, which offers a short message template to prepare ahead of any crisis.

Where professional help stops being a matter of comfort

Everything above is within your reach. Isolating, notifying, documenting, securing access: these actions genuinely limit the damage, and they require no particular technical skill.

But they answer none of the three questions that determine what happens next. How did the attacker get in? Are they still present somewhere in your system? What did they take?

Answering them requires reading technical logs, analysing the memory of the machines, reconstructing a timeline of the intrusion. This is not a matter of goodwill or budget, it is a profession. An SME that resumes operations without these answers is not really restarting: it is waiting for the second attack, this time from an attacker who already knows the place.

These reflexes are therefore a useful foundation, not a cure. The rest of the Responding to an attack pillar details the relevant Swiss contacts and common mistakes, and the cyber check-up lets you, once the crisis has passed, measure what was missing beforehand.