Cyber Incident Response: What to Do First.

A practical guide for South African businesses in the first 24–72 hours after discovering ransomware or a data breach.

Published: 16 September 2026  |  By AOLC

The moment you realise something is wrong — encrypted files, a ransom note on screen, a client calling to say their data appeared online — is not the moment to start figuring out what to do. Yet that is exactly where most South African businesses find themselves. The IT person is on leave, the backup status is uncertain, and nobody is sure whether to reboot the server or call the police.

This guide covers the first 24 to 72 hours after a cyber incident is discovered. It is not a substitute for a full incident response plan, but it will help you avoid the mistakes that turn a recoverable incident into a business-ending one. A skilled partner can help you make the best of a bad situation — but the actions you take before they arrive matter enormously.

Active ransomware right now? Call AOLC on +27 87 55 00 555 and see Ransomware Remediation. Do not reboot affected systems until you have spoken to someone who understands forensic preservation.

The First Hour.

Speed matters, but panic-driven actions cause more damage than the attack itself. In the first 60 minutes, your goal is to stop the bleeding without destroying evidence.

Our POPIA Breach Playbook walks through these steps in checklist form — useful to print and keep off-network before you need it.

Hours 1–24: Containment and Preservation.

Once immediate isolation is done, the focus shifts to understanding what happened and preventing recurrence while preserving evidence for investigation and compliance.

Containment means stopping the attack from spreading further. This includes disabling compromised user accounts, blocking known malicious IP addresses at the firewall, and ensuring backups are disconnected from the production network so they cannot be encrypted too. If you use managed security monitoring, your SOC should already be engaged — confirm they have isolated affected endpoints.

Forensic preservation is the step most businesses skip — and the one they regret most. Before anyone reinstalls Windows or "cleans up" infected machines, a digital forensics engagement captures disk images, memory dumps, and log files with documented chain of custody. This evidence supports POPIA breach notification, cyber insurance claims, and potential legal action. Well-meaning staff who wipe machines to "fix" the problem often destroy the only proof of what data was accessed.

Backup assessment — Identify your most recent clean backup. When was it taken? Is it offline or immutable? Can you actually restore from it? Many businesses discover during an incident that their backups have been failing silently for months. Test a restore to an isolated environment before committing to recovery.

Hours 24–72: POPIA and Recovery.

Under the Protection of Personal Information Act (POPIA), if personal information of data subjects has been accessed or disclosed without authorisation, you must notify the Information Regulator and affected individuals as soon as reasonably possible after discovery. The Regulator expects notification within 72 hours where feasible — and demonstrating that you followed a documented process matters when they review your report.

During this window you should:

72h

The Information Regulator expects POPIA breach notification within 72 hours where feasible. Starting your forensic investigation early gives you the evidence you need to meet that deadline with confidence.

Forensics vs Remediation: What You Need.

These are related but distinct services. Understanding the difference helps you engage the right help quickly.

Digital forensics answers "what happened?" — who accessed what, when, and how. The output is an evidence-backed timeline for regulators, insurers, and your board. You need this when personal data may have been breached, when you might claim insurance, or when you need to understand the attack path to prevent recurrence.

Ransomware remediation answers "how do we get back to work?" — containment, malware removal, backup restoration, and hardening. You need this when systems are encrypted or offline and the business cannot operate.

Most serious incidents require both, in sequence: preserve and investigate first, then remediate and recover. AOLC delivers both services and can coordinate with your existing IT provider, legal counsel, and insurer so you are not managing five vendors during a crisis.

After Recovery: Don't Stop at Restored.

Getting systems back online is not the finish line. Within two weeks of recovery, conduct a post-incident review:

South African businesses face rising ransomware and breach rates — but the organisations that recover fastest are not necessarily the ones with the biggest budgets. They are the ones that isolate calmly, preserve evidence, engage expert help early, and treat POPIA notification as a process rather than a panic.

Need Forensics?

Evidence preservation, breach analysis, and POPIA-ready reporting.

Digital Forensics

Active Ransomware?

Containment, recovery, and compliance support — call now.

Ransomware Remediation

← Back to Blog