Cyber AssessValydex™by iFeelTech
Implementation Guide

Business Cyberattack Recovery Checklist (2026)

A structured first-hour to full-recovery playbook for SMB teams

Step-by-step guide for containing breaches, coordinating response, restoring operations safely, and hardening controls after an incident.

Last updated: September 24, 2026
4 minute read

If this is happening now

  • Contact your incident lead or IT responder using a trusted channel.
  • Isolate known affected systems and accounts with the responder; preserve evidence and a timeline.
  • Contact the bank immediately if transfers or payment details may be affected.
  • Restore only after scope, credentials and backup integrity have been checked.

Last updated: September 24, 2026

A breach may involve a stolen mailbox, ransomware, an exposed cloud share or fraudulent payment. The exact order and reporting duties depend on the facts. NIST SP 800-61 Rev. 3 treats response and recovery as part of wider risk management. CISA's ransomware guide calls for prompt isolation of affected systems. Use a qualified responder and legal/insurance advice where appropriate; this checklist does not determine whether you must notify a regulator or customer.

Keep the printable recovery checklist available offline. It is a browser print/save page, so confirm it prints correctly in your own browser before relying on it during an incident.

1. Stabilize and record

Name an incident lead and one person to keep a timeline. Record the first alert, affected systems, accounts, messages and actions taken. Isolate known affected devices or network segments without erasing them. Revoke sessions or reset credentials through a clean administrator path if accounts are compromised; the responder should coordinate this so evidence and containment are not lost. Tell staff how to report related signs and which communication channel is trusted if business email is affected.

For suspected ransomware, the first-30-minutes page focuses on immediate containment. A fixed “first hour” milestone is a planning prompt, not a promised resolution time.

2. Protect money, access and backups

If payment instructions changed or money moved, contact the originating bank promptly and request its fraud process. FBI IC3's BEC guidance also directs victims to file a detailed complaint. Review administrator accounts, MFA methods, forwarding rules, vendor access and backup consoles. Do not restore production from a backup that may be contaminated or accessible to the attacker. Decide with the responder whether insurer, legal counsel, customers or law enforcement must be contacted and who may speak publicly.

DecisionOwnerEvidence or question
What is affected?Technical responderDevice/account list, logs and timeline
Can the attacker still enter?Identity/network ownerSession, credential and remote-access review
Is recovery data trustworthy?Backup ownerLast known-good copy and isolated test restore
Who needs notification?Business lead with counselAffected data, contracts and applicable rules
What work resumes first?Operations leadCritical workflow and dependency order

3. Restore in stages

Prioritize the business services identified in the 90-day roadmap. Rebuild or clean affected systems under the responder's plan, rotate credentials and verify that the route of entry is closed. Restore one service in a controlled environment, confirm the data and user workflow, then reconnect in phases while watching for recurrence. Record gaps, downtime and manual workarounds. A “backup completed” notification is not a restore test.

4. Close the loop

Within the following weeks, review what happened, where detection or escalation failed, and which control changes would have prevented or limited the incident. Give each action an owner, due date and verification test. Update the incident-response runbook, payment verification procedure, backup scope and staff training. Verify the changes rather than declaring the incident closed when systems simply return online.

Avoid irreversible improvisation

Do not wipe devices, pay a ransom, publish a statement or delete accounts on the basis of a generic checklist alone. Coordinate those decisions with the incident lead, insurer and advisers who know the case.

Sources checked September 24, 2026: NIST SP 800-61r3, CISA StopRansomware Guide, and FBI IC3 BEC guidance. This page is general response guidance, not case-specific legal or forensic advice.