Don’t Panic! What Every ITSP Should Do in the First Hour of a Cyberattack

By Christine Horton

May 19, 2026

Share this post

group of professionals working together to solve a problem

⚡ QUICK ANSWER

When a cyberattack hits, your first hour is critical. Immediately isolate affected machines and disable compromised accounts. Activate your incident response plan—notify staff, insurers and regulators. Then begin restoring from clean, verified backups. Speed and order matter more than perfection.

"You can have the best security in the world. You can have multiple layers of security, twenty different security products protecting your network. At some point, something will get through. It's just a matter of time," said Kieron Moore, European enterprise sales manager – cloud at Acronis during a ChannelCon EMEA session.

And that window is shrinking fast. With half a million new malware variants generated daily and a 115% surge in AI-generated ransomware, no defense is airtight. For ITSPs, the message is clear: A breach isn't a question of if—it's when. What separates good providers from great ones is what happens next.

Why Do MSPs Need an AI Governance Policy Now?

Your clients' data is already at risk

80% of companies experienced a cyber incident in 2025—ranging from lost data to full-scale breaches. Large enterprises may absorb the costs, but small businesses with 25–30 staff cannot afford two or three days of downtime.

That's where ITSPs play a critical role. As Moore put it: "You are their cyber staff. You are the guys that are protecting their organizations, stopping them from incurring around £31,000 to £1.3 million in costs every single day their organization is down."

What Is Cyber Resilience?

Cyber resilience is defined by NIST as: "The ability to anticipate, withstand, recover from and adapt to adverse conditions, stresses, attacks or compromises on systems."

In practice, resilience isn't about avoiding every breach—it's about recovering to an impact-less state as fast as possible. "You want that cyber response to be hours rather than days," Moore said.

To achieve that, Moore outlined a three-part response model:

    • Proactive protection
    • Best practice and compliance
    • People and communication

The Three-Part Cyber Response Model

1. Proactive Protection

Proactive protection means finding vulnerabilities before attackers do—and layering defenses so that when something gets through, the damage is contained.

Key components:

    • Robust EDR, XDR and MDR tooling
    • Network security and segmentation
    • Off-site, immutable backups
    • Tested disaster recovery capabilities

Moore flagged a common gap: "It's all well and good having cloud backups, but that 24-hour SLA you've promised might not be possible if you've got to wait three days for a new piece of hardware to be delivered."

For clients in finance or insurance who can't work remotely, he advised preparing emergency office contingencies—and testing them proactively. "Talk about those fifty staff that can't work from home and make plans for them."

2. Best Practice and Compliance

Technology alone isn't enough. Clients need to be training, testing, and auditing on a regular cadence.

Align to a recognized framework:

    • ISO standards
    • Cyber Essentials Plus
    • NIST

Test regularly with:

    • Penetration tests
    • Backup validation
    • Full disaster-recovery drills

On cyber insurance: 40% of cyber insurance claims are rejected due to poor audit trails. Coverage is only effective when it's backed by documented best practice. Moore's advice: Notify your insurer immediately when an incident occurs—they should be the first call after the police. Early notification gives them the opportunity to advise and ensures you stay compliant with your policy.

3. People and Communication

When systems go dark, communication is often the first casualty. If your CRM, work emails and staff contact information are encrypted, you lose the ability to coordinate at exactly the moment you need it most.

Moore's practical fixes:

    • Keep a USB stick (or offline document) with personal email addresses and phone numbers for all staff
    • Maintain offline records for customers, suppliers, regulators and insurers
    • Notify suppliers whose systems are connected to your network—they may be at risk too

And test everything—not just backups, but full-scenario simulations. "We're talking about full-scenario testing—your CRM going down, a full ransomware attack. These things need to be tested regularly," Moore said.

What Should You Do in the First Hour of a Cyberattack?

When a breach hits, follow this sequence:

Step 1: Contain >> Isolate affected machines. Apply network segregation. Disable compromised accounts. Most EDR and XDR tools support all of these actions.

Step 2: Activate >> Trigger your incident response plan immediately. Communicate with staff, suppliers and regulators. Notify your cyber insurer—early.

Step 3: Recover >> Restore from verified, stable backups. Confirm systems are clean before reconnecting. Validate that business functions are operational.

Step 4: Monitor >> Don't assume recovery means safety. Dormant ransomware can sit undetected in backups for months. Post-incident monitoring is critical to prevent reinfection.

Frequently Asked Questions

Do I need a cyber insurance policy as an ITSP? Yes—but coverage is only as strong as your documentation. 40% of claims are rejected due to poor audit trails. Align to a recognized framework and keep records of every action taken during an incident.

How long does it take to recover from a cyberattack? Recovery time varies, but the goal should always be hours rather than days. ITSPs with tested incident response plans, immutable backups, and clear communication protocols recover significantly faster than those without.

Should I inform my clients' suppliers during a cyberattack? Yes. If a supplier has software connected to your client's network, they may also be at risk. Notification should be part of your standard incident response communications.

What is the NIST definition of cyber resilience? NIST defines cyber resilience as "the ability to anticipate, withstand, recover from and adapt to adverse conditions, stresses, attacks or compromises on systems."

What documentation should I keep during a cyberattack? Document everything—and start immediately. Whether it's a notepad, a notes app or a full EDR/XDR platform, a complete audit trail supports insurance claims, regulatory compliance, and post-incident review.

Turning Chaos into Calm

Attacks are going to happen. But preparation is what turns panic into process. ITSPs who invest in proactive protection, tested response plans and clear communication frameworks will recover faster—and protect their clients better—when the inevitable occurs. Because when the breach hits, it's not panic you need. It's a playbook.

ChannelCon EMEA │ 9-10 November │ London  │ Register Now

GTIA Members: Check out the Cyber Resource Hub on the Member Portal.

Not a member yet? Join now!

Related Posts:

Rewst accepts the GTIA Spotlight Award
By GTIA / May 1, 2026

5 Questions with Rewst: 2026 GTIA Innovative Vendor Award Winner

Innovation in the channel doesn’t just come from building new technology—it comes from redefining what’s possible for the partners who rely on it. That’s exactly what Rewst, the 2026 GTIA Innovative Vendor Award Winner, has done. Known for transforming how MSPs think about automation, Rewst has shifted the conversation from “what can we automate?” to “how far can automation take us?”
Sentry Technology Solutions accepts the GTIA Spotlight Award
By GTIA / May 15, 2026

5 Questions with Sentry Technology Solutions: 2026 GTIA IT Service Provider Award Winner

Each year, GTIA recognizes an IT service provider (ITSP) member organization that exemplifies leadership, innovation and a forward-looking approach to delivering real business value through technology. In 2026, that distinction was awarded to Sentry Technology Solutions, a company redefining what it means to be a modern IT partner in a rapidly evolving channel.