Before, During and After a Cyber Attack: Key Lessons from the WBS Cyber Security Webinar
Before, During and After a Cyber Attack: Key Lessons from the WBS Cyber Security Webinar
What should your business actually do when a cyber attack happens?
That was the question at the centre of Wyvern Business Systems' latest cyber security webinar, Prepared by Design: What to Do Before, During and After a Cyber Attack, presented by WBS's Sean Harris.
Rather than concentrating solely on how businesses can prevent cyber attacks, Sean divided cyber resilience into three stages: before, during and after.
It is an important distinction. Businesses invest considerable time and money in preventing cyber attacks, but many have given far less thought to what happens in the first hour after an attack is discovered or how the business recovers afterwards.
Cyber Attacks Are Changing
Sean began by looking at how quickly the cyber threat facing UK businesses is evolving.
AI-enhanced phishing, deepfake social engineering, automated vulnerability scanning, AI-powered malware and large-scale credential attacks are making it easier and cheaper for criminals to launch increasingly convincing attacks.
At the same time, the basic methods used to gain access to businesses remain surprisingly familiar.
Phishing remains particularly important. The Cyber Security Breaches Survey 2025/26 found that 38% of businesses had experienced phishing, while 51% of businesses that had experienced a breach or attack experienced phishing and nothing else.
The practical lesson from Sean was straightforward: cyber security isn't simply a technology problem. People and processes remain an essential part of the defence.
Five Cyber Security Controls Every Business Should Consider
Sean highlighted five fundamental areas of protection:
- Firewalls and internet gateways
- Secure configuration
- User access control
- Malware protection
- Patch and update management
These are also the five technical areas covered by the UK government's Cyber Essentials scheme.
But technology is only one part of the answer. Businesses also need staff awareness, reliable and tested backups and, critically, a written incident response plan.
One of the statistics discussed during the webinar was that only 25% of UK businesses have a formal incident response plan.
Having that plan can make an enormous difference when an incident actually occurs.
What Should You Do in the First Hour of a Cyber Attack?
Sean set out five immediate actions businesses should remember:
1. Isolate affected devices. Disconnect compromised computers from wired and wireless networks to help prevent an attack spreading.
2. Don't immediately power everything down. Turning machines off can destroy useful evidence and potentially complicate the subsequent investigation.
3. Record what you can see. Keep screenshots, logs, times and a record of who discovered what and when.
4. Change compromised credentials. Do this from a clean device, prioritising email and financial systems.
5. Contact your IT provider. Get professional advice before attempting to clean up compromised systems yourself.
The wider message was that businesses should decide who is responsible for these actions before an incident occurs, rather than trying to work it out while systems are unavailable.
Cyber Security at Home: Are Personal Accounts at Risk Too?
One of the questions during the webinar moved the discussion away from the workplace and into the home.
What should individuals be doing to protect their own computers, accounts and personal information?
Sean recommended making sure security software and antivirus protection are kept up to date and using a password manager rather than relying on the same password across multiple accounts.
Password reuse is particularly important.
If the same password is used for several email accounts, websites or online services, the compromise of one service can potentially give an attacker the credentials they need to try accessing others.
Using strong, unique passwords for different services significantly reduces this risk. A password manager makes this much easier because users don't have to remember every individual password themselves.
Where available, two-factor authentication should provide another layer of protection.
The same basic principles therefore apply at home as they do in business: keep devices updated, protect accounts properly and don't allow the compromise of one account to become the key to several others.
Do All Cyber Attacks Have to Be Reported to the ICO Within 72 Hours?
Another question arrived following the webinar:
Does the 72-hour ICO reporting requirement apply to every cyber attack, including ransomware, malware and phishing?
The answer is no.
The 72-hour requirement isn't determined by the type of cyber attack. What matters is whether the incident has resulted in a personal data breach and the risk that breach creates for individuals.
For example, receiving a phishing email does not automatically create an obligation to report it to the ICO. Neither does detecting malware automatically make an incident reportable.
However, if a phishing attack results in an attacker gaining access to an employee's mailbox containing personal information, or ransomware results in personal data being accessed, lost, altered or made unavailable, the organisation needs to assess whether a personal data breach has occurred and the potential consequences for the people affected.
Where a personal data breach is likely to result in a risk to people's rights and freedoms, the organisation must notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
Where the risk to individuals is unlikely, the breach does not normally need to be reported to the ICO. The organisation should nevertheless document the breach and its decision.
Where there is a high risk to the affected individuals, there is an additional requirement to inform those people without undue delay.
Businesses also shouldn't assume they need to complete their entire investigation before contacting the ICO. An initial notification can be made within the required timeframe and further information supplied as the investigation develops.
The important point is therefore:
Ransomware, malware or phishing does not itself trigger the 72-hour rule. A potentially reportable personal data breach does.
What Happens After an Attack?
Containment is only part of incident response.
Sean described the next stage using three words: restore, report and review.
Systems should be restored from clean, recent and—importantly—tested backups. Any necessary notifications should be made, and the organisation should then establish how the attacker gained access and what needs to change.
Without that final review, a business risks restoring its systems while leaving the original weakness in place.
Your Suppliers Are Part of Your Cyber Security
The webinar also considered an area businesses can easily overlook: third-party suppliers.
If another organisation has legitimate access to your systems or data, that organisation effectively becomes part of your attack surface.
That relationship works in both directions. Your suppliers can introduce risk into your organisation, while your own cyber security can increasingly affect your ability to win work from larger customers.
This is one reason certifications such as Cyber Essentials are increasingly relevant when businesses are responding to tenders and supplier questionnaires.
Watch the Webinar on Catch-Up
If you missed Prepared by Design: What to Do Before, During and After a Cyber Attack, the complete webinar is available to watch on catch-up on our Events and Webinar page.
https://www.wbs.co.uk/events-webinars
Wyvern Business Systems provides managed IT and cyber security support to organisations across Herefordshire, Worcestershire, Shropshire, Gloucestershire and the West Midlands.
If the webinar has highlighted gaps in your own cyber security arrangements, WBS can provide a Cyber Essentials readiness review or a broader security audit covering controls, incident response, backups and supplier risk.
Contact the Wyvern team to discuss your cyber security and IT support requirements.
- October 2026 (1)
- September 2026 (9)
- August 2026 (8)
- July 2026 (10)
- June 2026 (9)
- May 2026 (8)
- February 2026 (3)
- January 2026 (3)
- December 2025 (2)
- November 2025 (2)
- October 2025 (6)
- September 2025 (6)
- August 2025 (3)
- July 2025 (3)
- October 2022 (1)
- August 2022 (1)
- July 2022 (2)
- June 2022 (1)
- May 2022 (3)
- April 2022 (2)
- March 2022 (3)


No Comments Yet
Let us know what you think