If Your Business Gets Hit by a Cyberattack: What to Do in the First Hour (Singapore Guide)
If your business suffers a cyberattack, what you do in the first hour matters.
It is also when people tend to make costly mistakes.
Someone switches off the affected computer. Someone starts deleting suspicious files. Someone replies to the attacker using a compromised email account. Or everyone starts messaging one another while nobody is actually coordinating the incident.
For a Singapore SME, you don’t need to be a cybersecurity expert to take the right first steps.
You just need to know what not to do, and who to call.
Before anything else: don’t make it worse
Don’t immediately power off the affected computer if you can safely isolate it instead.
Disconnect the affected device from the network by unplugging the network cable or disabling Wi-Fi. Powering down a compromised system may destroy volatile evidence that your incident response team could need later.
Don’t delete anything.
Leave suspicious emails, ransom notes, alerts, files and system messages where they are. Take screenshots if useful, but preserve the originals.
Don’t pay a ransom immediately.
A ransom payment does not guarantee that your data will be restored or that stolen information will be deleted.
Don’t discuss the incident using a potentially compromised account.
If an attacker has access to your Microsoft 365, Google Workspace or email environment, assume they may be able to see what you are sending.
Use a phone call or another trusted communication channel.
What to do, step by step
1. Isolate affected devices
Disconnect affected computers, servers or other devices from the network where practical.
The objective is containment: stop the attacker or malware from moving into other systems, shared drives and backups.
Don’t start wiping or rebuilding systems yet.
2. Call your IT or cybersecurity provider immediately
Use the phone rather than the potentially compromised corporate email system.
Tell them what happened, when it started and what you have observed.
If you have cyber insurance, notify your insurer early as well. Your policy may specify particular incident response, forensic or legal providers that must be engaged.
3. Preserve the evidence
Do not reformat, reinstall or “clean up” affected systems before your incident response team has assessed them.
Keep suspicious emails, screenshots, ransom notes, transaction details, system alerts and relevant logs.
Good evidence can make a big difference when determining what happened, how the attacker got in and what information may have been accessed.
4. If money was transferred to a scammer, call your bank immediately
Don’t wait until tomorrow.
Contact the bank’s fraud department and ask whether the transaction can be stopped, frozen or recalled.
For scam-related cases in Singapore, you should also consider making a police report promptly. Scam victims can also contact the ScamShield Helpline at 1799 for guidance.
Speed matters when money has already moved.
5. Secure compromised accounts from a clean device
Once your IT or incident response team advises you to proceed, reset passwords using a device believed to be clean.
Prioritise:
- Email accounts
- Administrator accounts
- Microsoft 365 or Google Workspace
- Remote-access accounts
- Cloud services
- Financial and payment systems
Enable multi-factor authentication (MFA/2FA) wherever possible.
Also check whether the attacker created new accounts, changed MFA settings, configured email forwarding rules or retained another way back into the environment.
6. Determine whether personal data was affected
This is where a cyber incident can become a PDPA issue .
If customer, employee or other personal data was accessed, copied, encrypted, disclosed or lost, your organisation should assess whether the incident constitutes a notifiable data breach under Singapore’s Personal Data Protection Act (PDPA).
Don’t automatically assume that every cyberattack must be reported to the PDPC — but don’t assume it doesn’t need reporting either.
The breach needs to be assessed properly.
Where a data breach is determined to be notifiable, organisations are generally required to notify the Personal Data Protection Commission (PDPC) as soon as practicable and no later than three calendar days after determining that the breach is notifiable.
Affected individuals may also need to be notified where the applicable notification criteria are met.
Get your Data Protection Officer (DPO), cybersecurity adviser and appropriate professional advisers involved early.
Where should a Singapore business report a cyberattack?
Depending on what happened, there may be several parties to contact.
For cybersecurity incidents, organisations can report incidents to SingCERT , which is part of the Cyber Security Agency of Singapore (CSA).
For scams, fraud or criminal activity, contact the Singapore Police Force (SPF) and your bank where financial transactions are involved.
For a notifiable personal data breach, notify the Personal Data Protection Commission (PDPC) .
You may therefore have several parallel workstreams:
Cyber incident → SingCERT / cybersecurity response
Fraud or scam → Bank + Police
Personal data breach → PDPC assessment and notification
And if you have cyber insurance, notify your insurer according to your policy requirements.
Should you pay a ransomware demand?
Don’t make that decision during the first panicked hour.
Paying a ransom does not guarantee that your systems will be restored, your information will be returned, or copies of stolen data will actually be deleted.
It can also create legal, financial and operational complications.
A ransomware decision should involve senior management together with your cybersecurity incident response team, insurer and appropriate legal or professional advisers.
First establish:
What systems are affected?
Do we have clean, recoverable backups?
Was data stolen as well as encrypted?
Can operations be restored without paying?
What regulatory and contractual obligations have been triggered?
The ransom demand is only one part of the problem.
The best time to prepare for a cyberattack is before one happens
When ransomware appears on the screen at 9:03am on Monday morning, that is not the ideal time to search Google for “what to do after cyberattack Singapore”.
Prepare beforehand.
At minimum, every SME should know:
- Who has authority to declare a cybersecurity incident
- Who calls the IT or cybersecurity provider
- Who contacts the cyber insurer
- Who handles management and customer communications
- Who assesses PDPA implications
- Where critical backups are stored
- Whether those backups have actually been tested
- Which systems must be restored first
- How staff communicate if corporate email is compromised
- Where emergency contact numbers are stored offline
You don’t need a 100-page incident response manual.
For many SMEs, a practical incident response plan, clear responsibilities and a tested contact list are already a very good start.
Frequently Asked Questions
What’s the first thing I should do during a cyberattack?
Contain the incident. Where practical, disconnect affected devices from the network and contact your IT or cybersecurity provider using a trusted communication channel.
Should I switch off a computer infected with ransomware?
Where possible, isolate it from the network first rather than immediately powering it down. Your incident response team may need information from the running system for investigation.
We transferred money to a scammer. What should we do?
Contact your bank immediately and ask whether the transaction can be stopped, frozen or recalled. Consider making a police report promptly and contact the ScamShield Helpline at 1799 for scam-related guidance.
Do we need to report a cyberattack to PDPC?
Not necessarily. PDPC notification requirements relate to notifiable personal data breaches. If personal data may have been compromised, assess the breach promptly against the PDPA notification criteria.
Who handles cybersecurity incidents in Singapore?
SingCERT, under the Cyber Security Agency of Singapore (CSA), handles cybersecurity incident reporting and assistance. Depending on the incident, you may also need to involve SPF, your bank, your cyber insurer and PDPC.
One final point
Cybersecurity isn’t only about preventing attacks.
It is also about whether your business can detect, respond and recover when prevention fails .
That is why incident response planning, tested backups, employee awareness and clear responsibilities matter.
Because during a real incident, you don’t want your management team debating what to do.
You want them executing a plan.











