Skip to content
Cyber SecurityAdvanced

What Should You Do First If You Suspect a Cyberattack? Should You Disconnect an Infected Computer from the Internet? – Complete Cyber Incident First-Response Guide

Cyberattacks do not always begin with an obvious ransomware message or a completely unusable computer. In many incidents, the first indication is something r...

BI
Bison Technical Team Enterprise IT specialists
Updated 25 Aug 2026 17 min read 0 total views

Cyberattacks do not always begin with an obvious ransomware message or a completely unusable computer. In many incidents, the first indication is something relatively small: an unexpected antivirus warning, unusual login notification, unexplained network traffic, disabled security software, unknown administrator account, suspicious email activity, unexpected file encryption, or a computer suddenly becoming unusually slow.

How an organization responds during the first few minutes can significantly affect the scale of the incident.

Advertisement

Two of the most important questions are:

  1. What should I do first if I suspect a cyberattack?
  2. Should I immediately disconnect the affected computer from the internet or network?

In most ordinary business environments, containing the suspected system is one of the highest priorities. However, containment should be performed carefully because immediately shutting down, restarting, deleting files, or running aggressive cleanup utilities can destroy information that may be useful during investigation.

This article explains a practical first-response procedure for workstations, laptops, servers, and business networks.


1. What Should I Do First If I Suspect a Cyberattack?

The first objective is containment, not cleanup.

When suspicious activity is discovered, avoid immediately trying random antivirus tools, deleting suspicious files, formatting the computer, or restarting repeatedly.

A useful incident-response sequence is:

Detect → Contain → Preserve → Investigate → Eradicate → Recover → Monitor

Each stage serves a different purpose.


2. Step 1: Determine What Triggered the Suspicion

Before changing anything, identify what made you suspect an attack.

Examples include:

  • Antivirus or EDR malware alerts
  • Ransomware messages
  • Files suddenly receiving unfamiliar extensions
  • Documents becoming unreadable
  • Unexpected administrator accounts
  • Unknown software appearing on the computer
  • Browser redirects
  • Repeated command windows appearing
  • Unexpected PowerShell activity
  • Security software becoming disabled
  • Unusual CPU or disk activity
  • Large amounts of unexplained network traffic
  • Unknown remote-access software
  • Unexpected Remote Desktop sessions
  • Suspicious login notifications
  • Password-change notifications you did not initiate
  • Emails being sent without authorization
  • MFA prompts you did not initiate
  • Firewall alerts
  • Unknown scheduled tasks or services

Do not assume every unusual behavior means the computer has been compromised. Software bugs, hardware failures, Windows updates, damaged profiles, and legitimate administrative tools can sometimes produce similar symptoms.

Treat credible indicators seriously until they have been investigated.


3. Step 2: Should You Disconnect the Infected Computer from the Internet?

Usually, yes.

If there is a reasonable suspicion that a workstation or laptop is actively compromised, isolating it from the network can prevent malware or an attacker from communicating with other systems.

Isolation can help stop:

  • Malware spreading to other computers
  • Ransomware reaching network shares
  • Credential theft
  • Command-and-control communication
  • Remote attacker access
  • Data exfiltration
  • Malware downloading additional payloads
  • Worm propagation
  • Attacks against servers
  • Access to NAS devices and shared folders
  • Attacks against backup repositories

However, disconnecting the network is not the same as turning the computer off.

That distinction is important.


4. How to Isolate a Suspected Computer

For an ordinary workstation, practical isolation methods include:

Wired computer

Disconnect the Ethernet/network cable.

Wi-Fi computer

Disable Wi-Fi or disconnect the wireless network.

Computer using both Ethernet and Wi-Fi

Disable or disconnect both connections.

Enterprise-managed endpoint

If your EDR or endpoint-management platform provides a network isolation feature, an administrator may be able to isolate the endpoint remotely while retaining limited communication with the security-management platform.

This can be preferable in managed environments because security administrators may still be able to investigate the computer remotely.


5. Do Not Forget Other Network Connections

Disconnecting Ethernet alone may not completely isolate a computer.

Check for:

  • Wi-Fi
  • Ethernet
  • Mobile hotspot
  • USB network adapter
  • Secondary network adapter
  • VPN connection
  • Bluetooth networking
  • Virtual network adapters where relevant

The objective is to prevent the compromised endpoint from freely communicating with production systems or the internet.


6. Why Network Isolation Is Important

Modern malware frequently does much more than infect a single computer.

Once an attacker compromises one endpoint, it may become a starting point for attacking the rest of the organization.

This process is often called lateral movement.

For example:

Internet → Employee PC → Stolen Credentials → File Server → Backup Server → Additional PCs

A single infected workstation can therefore become an entry point into a much larger environment.

Fast containment reduces this opportunity.


7. Should You Shut Down the Infected Computer?

Not automatically.

This is an important distinction:

Disconnecting the network may be appropriate while immediately shutting down the computer may not be.

A running computer contains volatile information in memory (RAM), potentially including:

  • Running processes
  • Active network connections
  • Logged-in sessions
  • Malware processes
  • Encryption activity
  • Command-line history
  • Decryption material in some circumstances
  • Process memory
  • Temporary attacker artifacts
  • Other forensic evidence

Turning off the computer destroys volatile memory.

For a serious corporate compromise, ransomware incident, suspected data theft, or incident that may require forensic investigation, contact the organization's IT/security or incident-response team before powering the machine off when practical.

For a home user without forensic capability, preventing further damage may take priority. The correct action depends on the severity and circumstances.


8. What About Active Ransomware?

Ransomware deserves special attention because minutes can matter.

Suppose you see files rapidly changing names or extensions, files becoming inaccessible, or ransom notes appearing.

Immediately isolating the machine from network resources can help prevent the ransomware from reaching:

  • Shared folders
  • Mapped drives
  • File servers
  • NAS storage
  • Other computers
  • Accessible backup locations

If multiple computers show similar symptoms, treat the situation as a network-wide security incident, not an individual PC problem.


9. Do Not Immediately Start Deleting Malware

One of the most common mistakes is immediately deleting everything identified as suspicious.

For example:

Antivirus detects Trojan → User deletes Trojan → User deletes temporary files → User runs registry cleaner → User restarts PC several times.

This may remove useful evidence without determining:

  • How the attacker entered
  • What credentials were compromised
  • Whether another payload exists
  • Whether persistence mechanisms remain
  • Whether other computers are infected
  • Whether data was stolen
  • Whether an administrator account was compromised

Contain first. Investigate second. Eradicate after understanding the incident.


10. Document What You See

Before making major changes, document the situation whenever it is safe to do so.

Record:

  • Computer name
  • Username
  • IP address, if known
  • Approximate time the problem started
  • Error messages
  • Antivirus detection names
  • Suspicious filenames
  • File locations
  • Ransomware note
  • Unusual processes
  • Suspicious email involved
  • Websites visited immediately before the event
  • Recent downloads
  • Unexpected login notifications
  • Actions already performed

Screenshots or photographs can also be valuable.

Create a simple timeline:

10:12 AM – User opened email attachment
10:14 AM – Antivirus warning appeared
10:15 AM – Files became inaccessible
10:16 AM – Ethernet cable disconnected
10:20 AM – IT administrator notified

A timeline can significantly simplify later investigation.


11. Preserve Logs

Logs may reveal what happened before and during the attack.

Depending on the environment, useful sources include:

  • Windows Event Logs
  • Antivirus logs
  • EDR alerts
  • Firewall logs
  • Router logs
  • VPN logs
  • Proxy logs
  • DNS logs
  • Microsoft 365 audit information
  • Google Workspace audit information
  • Email security logs
  • Active Directory logs
  • Remote Desktop logs
  • Server logs
  • Application logs

Avoid clearing logs during troubleshooting.


12. Protect Other Computers

Once the affected endpoint is isolated, determine whether other systems may also be affected.

Check for the same indicators across:

  • Employee workstations
  • Laptops
  • Servers
  • Domain controllers
  • File servers
  • Remote Desktop Servers
  • NAS devices
  • Backup servers
  • Cloud accounts
  • Email accounts

An attack that appears to involve one PC may already have reached other systems.


13. Check Network Shares

If ransomware or destructive malware is suspected, pay special attention to shared storage.

Examples include:

\\SERVER\Accounts

\\SERVER\Data

\\NAS\Backup

Mapped drives such as:

Z:\

Y:\

X:\

Determine whether files on these locations are also being changed or encrypted.

If necessary, administrators may temporarily restrict affected shares while investigating.


14. Protect Backup Systems

Backups are among the most valuable targets during ransomware attacks.

Modern attackers may attempt to delete or corrupt backups before encrypting production systems.

Check:

  • Backup server
  • NAS backup
  • Cloud backup
  • External drives
  • Backup administrator accounts
  • Backup management console
  • Replication systems
  • Snapshot systems

Do not connect clean offline backup drives to a potentially compromised computer.


15. Protect User Accounts and Credentials

If credential theft is possible, assume passwords used on the compromised computer may have been exposed.

Potentially affected credentials include:

  • Windows passwords
  • Domain credentials
  • Microsoft 365 accounts
  • Google Workspace accounts
  • VPN accounts
  • Banking credentials
  • Remote Desktop credentials
  • Accounting software credentials
  • Cloud portals
  • Administrator accounts

Password changes should preferably be performed from a known-clean device, not the suspected computer.


16. Revoke Active Sessions

Changing a password may not always terminate existing authenticated sessions.

Depending on the affected service, administrators may also need to:

  • Sign out active sessions
  • Revoke authentication tokens
  • Terminate suspicious sessions
  • Remove unknown trusted devices
  • Review application passwords
  • Review OAuth/application access
  • Reconfigure MFA if compromised

This is particularly important for cloud email compromises.


17. Enable or Verify Multi-Factor Authentication

After securing accounts, verify that MFA is enabled where supported.

MFA significantly improves account protection, although it does not eliminate every attack technique.

Review:

  • Registered mobile numbers
  • Authenticator applications
  • Security keys
  • Recovery email addresses
  • Backup codes
  • Trusted devices

Remove anything that is unfamiliar or unauthorized.


18. Check for Unauthorized Email Rules

After an email-account compromise, attackers sometimes create forwarding or mailbox rules.

For example:

Incoming invoice → Forward to attacker → Mark as read → Move to hidden folder

This allows an attacker to monitor financial conversations without immediately alerting the user.

Check for:

  • Automatic forwarding
  • Suspicious inbox rules
  • Deleted messages
  • Unknown delegates
  • Changed recovery information
  • Suspicious login locations
  • Unknown connected applications

This is particularly important in business email compromise incidents.


19. Do Not Trust the Computer Just Because Antivirus Says "Clean"

A completed antivirus scan is useful, but it should not automatically be interpreted as proof that a previously compromised computer is trustworthy.

Sophisticated attackers can establish persistence through:

  • Services
  • Scheduled tasks
  • Registry locations
  • Startup entries
  • Scripts
  • Remote-access software
  • User accounts
  • Browser extensions
  • PowerShell mechanisms
  • Stolen credentials

For a high-confidence compromise, rebuilding the system from a trusted source can sometimes be safer than attempting endless malware cleanup.


20. When Should the Computer Be Reinstalled?

A clean operating-system installation should be strongly considered when:

  • Ransomware executed
  • Administrator credentials may have been compromised
  • Remote-control malware was installed
  • Multiple malware components are discovered
  • System files were modified
  • Persistence mechanisms cannot be confidently removed
  • The attacker's activities are unknown
  • The computer handles highly sensitive information
  • There is insufficient confidence that remediation was complete

The principle is simple:

Recovery should restore trust, not merely make the computer appear normal again.


21. Use a Known-Good Installation Source

If rebuilding is required, use:

  • Trusted operating-system installation media
  • Fully updated software
  • Trusted drivers
  • Legitimate applications
  • Known-clean backups

Do not reinstall suspicious software packages recovered from the infected system without verification.


22. Be Careful When Restoring Backups

A backup is useful only if it predates the compromise and is trustworthy.

Before restoring, determine:

When did the compromise actually begin?

For example:

Attack discovered: August 25
Attacker initially entered: August 10
Malware installed: August 12
Backup created: August 20

The August 20 backup could potentially contain malicious artifacts.

Therefore, backup age alone does not guarantee safety.


23. Scan Restored Data

Before reconnecting restored systems to production networks:

  • Scan restored files
  • Apply security updates
  • Verify endpoint protection
  • Review user accounts
  • Change compromised credentials
  • Verify firewall configuration
  • Remove unauthorized software
  • Check startup items
  • Check scheduled tasks
  • Verify remote-access settings

Only reconnect systems after reasonable confidence has been established.


24. What If Only One Computer Appears Infected?

Do not automatically assume the incident is limited to that device.

Investigate whether:

  • The same account logged into other systems
  • The same malicious email reached other employees
  • The malware contacted other machines
  • Shared credentials were used
  • Files on servers were modified
  • Similar antivirus alerts exist elsewhere

The first detected computer may not necessarily be the first compromised computer.


25. What If a Server Is Suspected?

Server isolation requires additional care.

Disconnecting a production server can interrupt:

  • Accounting applications
  • Databases
  • Authentication
  • Remote Desktop sessions
  • File sharing
  • Email
  • Business applications
  • Backup operations

However, leaving a compromised server online can allow significantly greater damage.

For critical servers, containment should ideally be coordinated by experienced administrators or an incident-response team.

Possible strategies include:

  • Network segmentation
  • Firewall isolation
  • VLAN quarantine
  • Selective service blocking
  • EDR network isolation
  • Temporary access restrictions

This can provide containment without blindly shutting down critical infrastructure.


26. Special Considerations for Remote Desktop Servers

RDS servers deserve particular attention because many users may simultaneously access applications and business data.

If an RDS server is compromised, investigate:

  • Active sessions
  • Administrator logins
  • Failed login attempts
  • RDP source addresses
  • Newly created users
  • Group membership changes
  • Scheduled tasks
  • Services
  • Startup programs
  • PowerShell activity
  • Security logs
  • Installed remote-access tools
  • File-share activity

Do not assume disconnecting one employee's RDP session resolves a server-level compromise.


27. What Not to Do During a Suspected Cyberattack

Avoid these common mistakes:

  • Do not panic and randomly delete files.
  • Do not immediately format every affected computer.
  • Do not clear Windows Event Logs.
  • Do not repeatedly restart the computer.
  • Do not reconnect the computer merely because it appears normal.
  • Do not change sensitive passwords from the suspected device.
  • Do not connect backup drives to an infected computer.
  • Do not assume antivirus removal means the incident is completely resolved.
  • Do not ignore other computers on the same network.
  • Do not pay a ransomware demand impulsively.
  • Do not destroy evidence that may be needed for investigation, insurance, legal requirements, or law-enforcement reporting.

28. Practical Cyberattack First-Response Checklist

When a suspected compromise occurs, a practical sequence is:

Phase 1 – Identify

Determine what happened and which computer, account, or service appears affected.

Phase 2 – Isolate

Disconnect the suspected endpoint from network and internet access when appropriate.

Phase 3 – Preserve

Avoid unnecessary shutdowns, deletions, formatting, log clearing, and cleanup activities.

Phase 4 – Document

Record symptoms, alerts, times, screenshots, filenames, accounts, and actions taken.

Phase 5 – Protect Accounts

From a known-clean device, secure potentially compromised accounts and revoke suspicious sessions.

Phase 6 – Determine Scope

Investigate other computers, servers, cloud accounts, email accounts, shared folders, and backup infrastructure.

Phase 7 – Eradicate

Remove malicious software, persistence mechanisms, unauthorized accounts, and attacker access.

Phase 8 – Recover

Restore or rebuild systems from trusted sources.

Phase 9 – Reconnect

Reconnect systems only after appropriate validation.

Phase 10 – Monitor

Continue monitoring authentication, endpoints, network activity, email, and security alerts for signs of recurrence.


29. Example Scenario

Consider a small company with:

  • 20 Windows computers
  • One Windows Server
  • Shared accounting data
  • Microsoft 365 or Google Workspace
  • NAS storage
  • Cloud backup

An employee opens a malicious attachment.

Several minutes later, unusual file activity begins.

A sensible response would be:

Employee PC → Isolate immediately

Then:

Check server → Check shared files → Check other PCs → Check user account → Check email account → Protect backups → Investigate logs

If only the affected PC is cleaned while compromised credentials remain active, the attacker may simply return.

Cyber incident response therefore needs to consider the identity, endpoint, network, cloud, server, and backup environment together.


30. When Should Professional Incident Response Be Used?

Professional assistance should be strongly considered when:

  • Multiple computers are compromised
  • Ransomware is spreading
  • A domain controller is involved
  • A production server is compromised
  • Customer information may have been stolen
  • Financial information is involved
  • Administrator credentials are compromised
  • Backups have been deleted
  • Business email accounts have been hijacked
  • Attackers still appear to have access
  • Regulatory or contractual reporting obligations may exist
  • The organization cannot determine how the attacker entered

Larger incidents often require coordinated technical, management, legal, insurance, compliance, and communications responses.


31. Cyberattack Response Flow

A useful simplified workflow is:

Suspicious Activity Detected

Confirm Indicators

Isolate Affected Endpoint

Preserve Evidence

Notify IT/Security

Determine Scope

Protect Accounts and Backups

Investigate Entry Point

Remove Attacker Access

Rebuild or Remediate Systems

Restore Verified Data

Reconnect

Monitor

Post-Incident Review


32. The Most Important Principle

When a cyberattack is suspected, remember:

Do not focus only on removing the visible malware.

The real questions are:

  • How did the attacker get in?
  • What systems did they access?
  • What credentials did they obtain?
  • Did they establish persistence?
  • Did they reach other devices?
  • Was information stolen?
  • Are backups safe?
  • Can the attacker return?

A malware alert may be only one visible symptom of a much larger compromise.


Frequently Asked Questions (FAQ)

1. What should I do first if I suspect a cyberattack?

Contain the suspected system, document what you observe, and notify the appropriate IT or security personnel. Avoid unnecessary deletion, formatting, or restarting until the situation has been assessed.

2. Should I disconnect an infected computer from the internet?

Usually yes. Network isolation can prevent malware from communicating with attackers, spreading to other systems, accessing network shares, or exfiltrating information.

3. Should I disconnect the Ethernet cable?

For an ordinary workstation, physically disconnecting Ethernet is a simple method of isolation. Remember to disable Wi-Fi and other active network connections as well.

4. Should I turn off Wi-Fi?

Yes, if Wi-Fi provides network connectivity to the suspected device and you are trying to isolate it.

5. Should I immediately shut down an infected computer?

Not necessarily. Shutting down destroys volatile memory that can contain useful forensic information. In serious incidents, seek IT/security guidance before powering off when circumstances allow.

6. Should I restart an infected computer?

Avoid unnecessary restarts during initial investigation. Restarting changes system state and may destroy useful volatile evidence.

7. Can ransomware spread through a local network?

Yes. Some ransomware can access shared folders, network resources, or other systems, particularly when compromised credentials or vulnerable services are available.

8. Can ransomware encrypt mapped network drives?

Yes. If the infected user's account can write to a mapped drive or shared folder, ransomware may be able to modify or encrypt accessible files.

9. Should I disconnect my backup drive?

If ransomware is suspected and the backup drive is currently accessible to the compromised computer, protecting the backup is extremely important. Avoid connecting clean offline backups to the compromised machine.

10. Should I immediately run antivirus software?

A security scan may be appropriate, but containment and evidence preservation should be considered first, particularly for serious business incidents.

11. Should I delete malware detected by antivirus?

For an ordinary home infection, antivirus quarantine may be appropriate. For significant organizational incidents, preserve relevant evidence and investigate before indiscriminately deleting artifacts.

12. Should I change my passwords?

Yes if credential compromise is possible, but change them from a trusted, clean device rather than the suspected computer.

13. Which password should I change first?

Prioritize high-value accounts such as email, administrator, identity-provider, VPN, cloud, financial, and other accounts accessible from the compromised system.

14. Is changing my password enough?

Not always. Existing sessions or authentication tokens may remain active. Review and revoke suspicious sessions and trusted devices where supported.

15. Does MFA protect against cyberattacks?

MFA substantially strengthens account security but is not absolute protection. Phishing, session theft, MFA fatigue, malicious applications, and compromised endpoints can still create risks.

16. How do I know whether other computers are infected?

Review endpoint alerts, authentication activity, network logs, shared-file activity, security logs, and indicators discovered on the original computer.

17. Can an infected computer steal passwords?

Yes. Depending on the malware and privileges obtained, attackers may attempt to capture credentials, browser sessions, authentication tokens, or other sensitive information.

18. Should I format the infected computer?

For a confirmed serious compromise, rebuilding from trusted installation media may be the safest recovery approach. However, preserve required evidence before wiping the system.

19. Can I trust the computer after antivirus removes the malware?

Not automatically. You should determine whether persistence, additional malware, compromised accounts, or unauthorized changes remain.

20. Can I restore everything from backup?

Only after confirming the backup is trustworthy and appropriately predates malicious modifications. Restored data should also be checked before production use.

21. What if my email account was hacked instead of my computer?

Change credentials from a clean device, revoke active sessions, verify MFA and recovery information, inspect forwarding and inbox rules, review connected applications, and examine suspicious login activity.

22. What if ransomware is actively encrypting files?

Rapid containment is critical. Isolate affected systems and protect servers, shared storage, and backups. For a business network, involve experienced incident-response personnel immediately.

23. Should I disconnect the entire office from the internet?

Not automatically. The appropriate containment scope depends on the incident. A widespread compromise may justify broader network isolation, but indiscriminate disconnection can also disrupt investigation and essential operations.

24. How long should an infected computer remain disconnected?

Until the organization has reasonable confidence that the threat has been removed, compromised credentials have been addressed, the system has been remediated or rebuilt, and reconnecting it will not put other systems at risk.

25. What should businesses do after recovery?

Perform a post-incident review to identify the original entry point and improve security controls. This may include patching, MFA, endpoint protection, network segmentation, backup improvements, email security, least-privilege access, employee awareness training, and better monitoring.


Conclusion

If you suspect a cyberattack, containment should normally be one of your first priorities.

For a suspected infected workstation, disconnecting it from Ethernet, Wi-Fi, and other network connectivity can help prevent additional damage. However, avoid assuming that disconnecting the internet alone resolves the incident.

The safest overall approach is:

Isolate → Preserve → Investigate → Protect Credentials → Determine Scope → Eradicate → Recover → Monitor

Most importantly, distinguish between isolating a computer and immediately powering it off. Isolation can stop communication while preserving valuable information in memory for investigation.

For organizations, every significant incident should also lead to a broader question:

How did the attacker get in, what else did they reach, and what must change to prevent them from returning?

Disclaimer

This article is provided for general cybersecurity awareness, education, and technical guidance. The appropriate response to a cyber incident depends on the type of attack, affected infrastructure, business requirements, applicable laws, contractual obligations, and available forensic capabilities. Organizations handling a serious cyberattack, ransomware incident, data breach, or suspected theft of sensitive information should consult qualified cybersecurity, incident-response, legal, compliance, and other appropriate professionals before taking actions that could destroy evidence or affect reporting obligations.

#Tags

#CyberSecurity #CyberAttack #CyberAttackResponse #IncidentResponse #CyberIncident #CyberSecurityAwareness #Malware #MalwareAttack #Ransomware #RansomwareAttack #RansomwareResponse #ComputerSecurity #NetworkSecurity #EndpointSecurity #DataBreach #SecurityBreach #CyberThreat #CyberDefense #CyberProtection #ITSecurity #InformationSecurity #NetworkIsolation #EndpointIsolation #MalwareRemoval #VirusRemoval #HackedComputer #CompromisedComputer #DigitalForensics #Forensics #SecurityIncident #IncidentManagement #DataProtection #NetworkProtection #BusinessSecurity #SmallBusinessSecurity #EnterpriseSecurity #CyberResilience #DisasterRecovery #DataBackup #CloudBackup #MFA #MultiFactorAuthentication #PasswordSecurity #EmailSecurity #BusinessEmailCompromise #Phishing #SecurityMonitoring #ThreatDetection #ThreatResponse #CyberSafety

YOUR FEEDBACK

Was this guide useful?

Your answer helps us keep BISONKB accurate and practical.

BISON AI

Ask about “What Should You Do First If You Suspect a Cyberattack? Should You Disconnect an Infected Computer from the Internet? – Complete Cyber Incident First-Response Guide”

This interface is ready to connect to your preferred AI provider. No article or user data is sent until that service is configured.

THE BISON BRIEF

Practical IT knowledge, once a week.

New troubleshooting guides, scripts and infrastructure notes. No noise.

By subscribing, you agree to our privacy policy.