How Businesses Can Prepare and Respond When an Attack Happens
Many business leaders still view cybersecurity as primarily an IT concern. The reality is that cyberattacks are business continuity events. When systems go offline, employees cannot work, customers cannot access services, communications break down, and revenue-generating operations can grind to a halt.
A recent cyberattack against Suisun City demonstrates just how disruptive these incidents can be. The attack impacted critical systems and forced the city to take parts of its technology infrastructure offline while investigators worked to contain the threat and determine the extent of the damage. Despite the disruption, emergency services continued operating because contingency plans were activated and outside resources were engaged quickly.
For businesses, the lesson is clear: preparation before an attack determines how effectively you can respond after one begins.
Why Cyberattack Readiness Matters
Cybercriminals no longer focus exclusively on large enterprises. Mid-sized organizations have become attractive targets because they often possess valuable data but may lack the security resources of larger organizations.
Modern cyberattacks do more than encrypt files or expose data. They interrupt the systems that keep the business running: email, phones, production platforms, financial applications, customer portals, and the operational workflows employees depend on every day. That is why cyber risk has to be managed as business risk. A ransomware event can quickly become a revenue, compliance, customer trust, and leadership credibility issue.
The organizations that recover fastest are rarely improvising. They have already identified their highest-risk systems, reduced unnecessary exposure, tested recovery assumptions, and established executive-level decision paths. If you are not sure where your organization stands, start with a practical cybersecurity assessment and use the results to prioritize the controls that would matter most during a real incident. A stronger approach to cybersecurity risk management helps leadership connect technical controls to business exposure.
How to Prepare Before an Attack
Build an Incident Response Plan Leaders Can Actually Use
An incident response plan should not be a binder that sits untouched until something goes wrong. It should be a concise operating guide that tells leadership who has authority, which systems matter most, how decisions get escalated, when legal or insurance partners are engaged, and how the organization communicates when normal tools are unavailable.
The goal is to reduce confusion in the first hour. Teams should know which actions can be taken immediately, which require executive approval, and how to coordinate across IT, legal, compliance, HR, finance, operations, and communications. Organizations that need help turning cyber risk into a practical roadmap can benefit from IT consulting that connects incident planning with business priorities.
Make Recovery a Tested Business Capability
Backups matter because they create options. But a backup strategy is only useful if restored systems come back within the time the business can tolerate and if attackers cannot delete, encrypt, or corrupt the recovery copies during the attack.
That means backup and recovery planning should define recovery time objectives, recovery point objectives, restoration order, ownership, and validation procedures. It should also include routine restore testing, because many organizations discover backup gaps only when they are already under pressure.
Recovery planning should also reflect the difference between data backups and replication, as well as the operational requirements of a practical business continuity plan.
Watch Continuously, Not Occasionally
Organizations cannot respond to threats they cannot see, and many damaging incidents begin with signals that look small in isolation: unusual logins, repeated authentication failures, suspicious mailbox rules, unexpected endpoint behavior, or activity outside normal working hours.
Continuous monitoring helps connect those signals before they become a full outage. Managed detection and response, endpoint detection and response, and security operations expertise can shorten the time between compromise and containment. This is where managed security and proactive monitoring become especially important: they give organizations visibility and response capacity when internal teams may be stretched thin. In high-risk environments, 24/7 security operations and a disciplined response during the critical first hour can materially reduce business disruption.
Train Employees to Escalate Early
Human error remains one of the most common causes of successful cyberattacks.
Training should make employees faster at recognizing and reporting suspicious activity, not just better at passing an annual quiz. Phishing simulations, short refreshers, and clear reporting channels help users understand what to do when they see a questionable message, login prompt, file share, or request for sensitive information.
The most useful awareness programs also remove friction. Employees should know that reporting something suspicious is encouraged, easy, and never treated as an inconvenience. Fast reporting can be the difference between a contained account compromise and a company-wide incident.
Plan for Operations, Not Just Systems
The Suisun City response highlights an important reality: critical services must continue even when technology systems are disrupted. The city maintained emergency response capabilities while working through the incident.
Businesses should define the functions that must continue during a disruption, the people who own them, the manual workarounds available, and the vendors or outside partners that may be needed. This is where business continuity and disaster recovery come together: disaster recovery restores systems, while business continuity keeps the organization operating while recovery is underway.
The goal is not just to restore systems. It is to maintain operations while recovery takes place.
What to Do When a Cyberattack Begins
The first hours of a cyberattack are critical because decisions made early can either limit the blast radius or make recovery harder. Leaders should resist the urge to solve everything at once. The immediate priorities are to contain the threat, preserve evidence, coordinate decisions, communicate carefully, and begin recovery from a trusted position.
Contain the Threat Without Destroying Evidence
Containment should begin as soon as credible malicious activity is detected. That may mean isolating affected endpoints, disabling compromised accounts, blocking suspicious traffic, or disconnecting specific systems from the network. The purpose is to stop spread while avoiding unnecessary changes that could destroy forensic evidence.
Document what was observed, what was changed, who approved the action, and when it happened. That record may matter for forensics, insurance, regulator discussions, legal review, and the post-incident improvement plan.
Activate the Right Decision Makers
A cyberattack is not only a technical event. It can affect legal obligations, customer commitments, employee communications, finance operations, insurance requirements, and public reputation. The incident response team should include the people who can make decisions across those areas quickly.
Cyberattacks require coordinated business decisions, not just technical fixes.
Bring in Outside Expertise Early
Many organizations wait too long to involve outside support. During an active incident, experienced responders can help determine scope, guide containment, coordinate forensic preservation, and advise on recovery sequencing. They can also help internal teams avoid well-intentioned actions that make investigation or restoration harder.
This may include:
If the organization relies on a managed security provider, cyber insurer, legal counsel, or incident response partner, those relationships should already be documented in the plan so response support can be activated without delay.
Preserve Evidence
Avoid making changes that could destroy critical forensic evidence.
Collect logs, document actions taken, and maintain records of events. These materials may be necessary for investigations, insurance claims, compliance requirements, or legal proceedings.
Communicate with Discipline
Communication during a cyberattack should be timely, accurate, and carefully scoped. Employees need to know what tools or processes to use. Customers and partners may need reassurance or action steps. Leadership needs consistent updates that separate confirmed facts from open questions.
Communication plans should address:
Good communication does not require over-disclosure before the facts are known. It requires a clear cadence, approved messages, and a shared understanding of who can speak for the organization. That discipline helps maintain trust while the investigation continues.
Recover Cleanly and Improve the Program
Recovery should not simply bring systems back online as quickly as possible. It should restore them from trusted sources, validate that the attacker’s access has been removed, confirm that backup data is usable, and prioritize systems based on business impact.
Examine:
After normal operations resume, the organization should conduct a post-incident review that identifies root causes, control gaps, response delays, communication issues, and investment priorities. The best reviews are direct but constructive: they turn a painful event into a stronger security and resilience program, especially when leaders use lessons from a devastating malware attack to pressure-test their own assumptions.
Resilience Is the Ultimate Goal
A successful cybersecurity strategy is not built on the assumption that attacks will never happen. It is built on the understanding that organizations must be prepared to detect, contain, respond to, and recover from them.
The recent cyberattack affecting Suisun City serves as a reminder that even essential public services can be disrupted by cyber threats. The organizations that fare best are those that invest in preparedness before a crisis ever occurs.
Organizations can strengthen their cybersecurity posture through proactive monitoring, incident response planning, backup and recovery, IT consulting, and managed security capabilities that reduce risk and improve resilience.
Are your cybersecurity and business continuity plans ready for a real-world attack? If not, now is the time to prepare.

