A calm, step-by-step cyber attack response plan based on official NCSC guidance, covering ransomware, BEC, malware and more.
The moment you realise your systems have been compromised is one of the most disorienting a business owner can face. This guide exists so you don’t have to think from scratch in that moment, just follow the steps.
40% of Irish businesses reported suffering at least one cyber attack in the past 12 months, according to the Hiscox Cyber Readiness Report 2025. The same report found that of those who paid a ransom, 29% still had their data leaked anyway. The threat is real, persistent, and increasingly automated.
What separates businesses that recover quickly from those that don’t often isn’t the size of their security budget, it’s having a clear plan they can execute under pressure. The National Cyber Security Centre (NCSC) of Ireland has published a practical Cyber Attack SOS framework specifically for SMEs. This post turns that framework into a cyber attack response plan you can follow under pressure, adds the legal obligations you need to know, and tells you where Newtec can step in when you need expert hands.
Sources: Hiscox Cyber Readiness Report 2025; Microsoft Ireland Work Trend Index 2025; GDPR Article 33.
The framework in this post is based on the official Cyber Attack SOS resource published by the National Cyber Security Centre (NCSC), operating under the Department of Justice, Home Affairs and Migration, Ireland. All guidance credited to the NCSC is reproduced in summary form only. For the full resource, visit sme.ncsc.gov.ie.
First: Identify what you’re dealing with
Not every incident is the same, and the right immediate action depends on what type of attack has occurred, which is why identifying the attack type is the first move in any cyber attack response plan. The NCSC identifies five common cyber incidents affecting Irish SMEs:
Ransomware
An attacker encrypts your files so you can no longer access them, then demands payment. It is designed to spread across all devices on your network.
Business Email Compromise (BEC)
A targeted phishing attack aimed at people who can authorise financial transactions. Unlike mass phishing, BEC is crafted for one specific person and may continue an existing email thread.
Account Compromise
An attacker has stolen your username and password. Without multi-factor authentication (MFA), they can now log in as you.
Malware
Malicious software used to gain unauthorised access to your systems. It can arrive via email attachments, compromised websites or infected USB drives.
Man-in-the-Middle (MitM)
Your data is intercepted by a third party while it travels over a network, often on unsecured Wi-Fi. Attackers can read or alter data in transit.
If you’re unsure which type of incident you’re facing, that’s normal, and it’s reason enough to call in a cybersecurity professional immediately rather than guess.
Step 1 — Act: Contain the damage now
Your first instinct may be to switch everything off. In some cases that’s the right call; in others (particularly ransomware) it can make things worse. Here’s what the NCSC advises for the most common scenarios as part of your cyber attack response plan.
Don’t pay, isolate infected devices without switching them off
- Do not engage with or respond to on-screen messages from attackers. The ransomware spreads automatically, the attacker may not yet know your network is compromised.
- Disconnect infected devices from the network: unplug network cables, disable Wi-Fi and Bluetooth. Disable Wi-Fi on your router if necessary.
- Do not switch infected devices off, doing so may corrupt your data.
- Notify your company’s designated cybersecurity contact.
- Run virus and malware scans on all other devices. Isolate any further affected machines.
Stop the bleeding, secure accounts and contact your bank immediately
- If money has already been transferred, contact your financial institution immediately using their official phone number or website, not contact details from the suspicious email.
- Secure your email account: reset passwords, enable MFA, check account recovery details in case attackers have changed them.
- Sign your email out of all other active sessions and devices.
- Check sent and deleted items to understand what actions were taken by the attacker.
- Notify any contacts or third parties who may have been targeted using your identity.
The Hiscox Cyber Readiness Report 2025 found that 70% of Irish businesses that suffered a ransomware attack paid a ransom, yet 35% still had to rebuild their systems, and 29% had their data leaked anyway. Payment does not guarantee recovery. The NCSC advises against paying.
Step 2 — Consult: Get expert help
Once you’ve contained the immediate threat, you need to understand what actually happened. The NCSC is clear: it is often necessary to engage a trusted cybersecurity expert to identify the type of incident and determine how it can be fully resolved.
Two things your expert must establish for you:
- Root cause: the vulnerability that allowed the attacker in.
- Full extent of damage: what systems and data the attacker accessed, and for how long.
Don’t skip this step or assume your IT generalist can handle it without specialist input. An incomplete picture of the breach creates regulatory and liability exposure, and leaves the root cause in place for a repeat attack.
Step 3 — Recover: Get back on your feet
Recovery is the third pillar of your cyber attack response plan, and it’s about more than restoring files. It involves communicating clearly with your team, customers and suppliers, and building the business back in a way that is safer than before. The NCSC outlines six concrete recovery actions for Irish SMEs:
- Communicate quickly with staff. Give clear instructions about which systems and data they can and cannot access until further notice.
- Restore critical data from backups. Prioritise the data your business absolutely cannot operate without.
- Review backups for signs of corruption or compromise before using them. If you’re unsure whether a backup is clean, have a cybersecurity expert verify it first.
- Identify workarounds. Determine which parts of the business can continue manually or through alternative systems while critical systems are restored.
- Communicate with customers and suppliers. Withholding information often causes more reputational damage than the breach itself.
- Conduct a lessons-learned review. Document what went right and wrong, and implement changes to prevent recurrence.
The NCSC specifically recommends using air-gapped or immutable storage for backups so that ransomware cannot infect your backup copies, making this the single most important pre-attack investment an SME can make.
Step 4 — Report: Know your legal obligations
This is the step Irish businesses most commonly get wrong, either by not reporting at all, or by missing a deadline. After a cyber incident, you may have legal obligations to multiple parties.
Your reporting obligations at a glance
- An Garda Síochána. Report cyber-crime to your local Garda station. Local Gardaí will guide how the criminal investigation proceeds.
- Data Protection Commission (DPC). If the incident resulted in a personal data breach, you must notify the DPC within 72 hours of becoming aware of the breach under GDPR Article 33. This is a hard legal deadline, not a guideline. The DPC fined Bank of Ireland €463,000 in March 2022 specifically for failures including Article 33 breach notification obligations.
- Affected data subjects. Where the breach poses a high risk to individuals, you may also be required to notify them directly.
- Third parties. Check your customer and supplier contracts, many include notification clauses triggered by a data breach.
- The NCSC. If the incident may have national impact, contact the NCSC at CORE_Support@ncsc.gov.ie.
- NIS2 obligations. If your business qualifies as an Operator of an Essential Service, additional incident reporting requirements apply. See ncsc.gov.ie/oes.
In 2024, the DPC received 7,781 breach notifications from Irish organisations. Late notification remains one of the most common, and most preventable, GDPR enforcement triggers.
The DPC interprets ‘awareness’ broadly. Waiting to complete your investigation before deciding to notify is itself a compliance risk. If there is a reasonable degree of certainty that a breach has occurred and personal data may be involved, the 72-hour clock is running. Document your awareness time and decision-making process from the moment you suspect a breach.
Build Your Cyber Attack Response Plan Before an Attack Happens
The best outcome after a cyber attack is a fast, controlled recovery, and that requires preparation that happened before the incident. The NCSC’s SME CORE platform offers free, practical cybersecurity resources for Irish businesses. In the meantime, the most impactful actions for an Irish SME to take right now are:
- Enable multi-factor authentication (MFA) on all email, cloud and business accounts, this single step blocks the majority of account compromise attacks.
- Maintain regular, tested backups using air-gapped or immutable storage that cannot be encrypted by ransomware.
- Keep a written cyber attack response plan, even a single page, that lists who to call, what to isolate, and your reporting obligations.
- Know your GDPR breach notification process in advance: who in your organisation decides whether to notify, and who submits the notification to the DPC.
- Ensure staff receive regular cybersecurity training. Only 19% of employees in Irish SMEs receive regular training, compared to 48% in larger organisations.
- Review third-party contracts for breach notification clauses so you’re not discovering obligations in the middle of an incident.
Further Reading & Sources
All sources used to build this cyber attack response plan are verifiable and publicly available.
Official guidance
- NCSC Ireland — SME CORE: Cyber Attack SOS — sme.ncsc.gov.ie/cyber-attack-sos
- NCSC Ireland — Ransomware guidance for SMEs — sme.ncsc.gov.ie/ransomware
- NCSC Ireland — Business Email Compromise guidance — sme.ncsc.gov.ie/bec
- NCSC Ireland — Account Compromise guidance — sme.ncsc.gov.ie/account-compromise
- Data Protection Commission — Breach Notification obligations under GDPR — dataprotection.ie
- NCSC Ireland — Operators of Essential Services obligations — ncsc.gov.ie/oes
Research & reports
- Hiscox Ireland — Cyber Readiness Report 2025 (40% attacked; 70% paid ransom; 29% leaked) — hiscox.ie/crr2025
- Hiscox Ireland — Cyber Readiness Report 2024 (74% increase; avg 58 attacks/year) — hiscox.ie/cyber-readiness-report-2024
- RTÉ / Microsoft Ireland — Work Trend Index 2025 (19% SME training rate) — rte.ie
- DPC — Inquiry into Bank of Ireland Group plc (€463,000 fine including Article 33 breach notification failure, March 2022) — dataprotection.ie
- DPC — Final Decision: Permanent TSB (total fine €277,500 including €27,500 for Article 33(1) breach notification failure, May 2026) — dataprotection.ie
- DPC — Annual Report 2024 (7,781 valid breach notifications received; 11% increase on 2023) — dataprotection.ie
Don’t wait for an incident to have a plan.
Newtec works with Irish SMEs to build a cyber attack response plan, implement the controls that stop attacks, and provide expert support when something goes wrong. We know the NCSC framework, GDPR obligations, and the Irish threat landscape.
Talk to our team →This article is for information purposes only and does not constitute legal advice. For GDPR obligations, consult a qualified data protection professional or the Data Protection Commission (dataprotection.ie).


