The moment a business owner realises something is wrong, a locked screen demanding payment, a bank account flagged for suspicious transfers, or a supplier calling to ask about an invoice nobody sent, panic is the natural first reaction. Yet the decisions made in the first hour after discovering a cyber incident often matter more than anything done afterward, and small South African businesses are frequently targeted precisely because attackers expect a chaotic, disorganised response.
Having a clear, calm sequence of steps ready in advance turns a potential disaster into a manageable, contained incident. None of the steps below require deep technical expertise, though a few are far easier with help from an IT provider on standby.
Contain the Incident Immediately
The first priority is stopping the incident from spreading further, not fixing it completely. Disconnect the affected computer or server from the network, either by unplugging the network cable or turning off Wi-Fi, rather than switching it off completely, since a full shutdown can sometimes destroy evidence needed later.
- Isolate affected devices from the network immediately, but avoid switching them off unless instructed by an IT professional
- Change passwords for any accounts that may have been compromised, starting with email, banking and admin accounts
- Alert staff to stop using shared systems until the scope of the incident is understood
If ransomware is suspected, where files are encrypted and a ransom note appears, do not pay before getting professional advice, since payment does not guarantee file recovery and can mark the business as a repeat target.
Preserve Evidence Before Cleaning Anything Up
It is tempting to immediately reinstall software or wipe an infected machine to get back to work, but doing so before documenting what happened can destroy information needed for insurance claims, law enforcement reports, or understanding how the attacker got in.
Take photos or screenshots of any ransom notes, suspicious emails, or error messages before taking action. Keep a simple written timeline noting when the problem was first noticed, what was observed, and what actions were taken and when, since this record becomes important later for both your cyber insurance provider and any formal reporting.
Notify the Right People, Internally and Externally
Staff need to know quickly if a shared system has been compromised, both to stop further spread and to watch for follow-up attacks like phishing emails impersonating the business. Customers or suppliers whose data may have been affected also deserve prompt, honest communication, even if all the details are not yet known.
- Inform your bank immediately if financial accounts or payment systems may be compromised
- Contact your IT provider or a cybersecurity specialist for hands-on containment and investigation
- Notify your cyber insurance provider if you hold a policy, since many require early notification as a condition of cover
Reporting Obligations Under POPIA
Under South Africa's Protection of Personal Information Act (POPIA), businesses that experience a security compromise involving personal information, whether customer, employee or supplier data, are legally required to notify the Information Regulator and the affected individuals as soon as reasonably possible.
This applies to businesses of every size, not just large corporations. The notification should describe what happened, what data was likely affected, and what steps are being taken in response. Failing to report a qualifying incident can result in penalties on top of the damage already caused by the attack itself.
Recovering and Preventing a Repeat
Once the immediate incident is contained, focus shifts to safely restoring systems, ideally from a clean, tested backup rather than the compromised environment. A post-incident review, even an informal one, helps identify how the attacker got in, whether through a phishing email, a weak password, or an outdated system, so the same gap can be closed.
- Restore from a verified clean backup rather than the affected system directly
- Reset all passwords, not just those believed to be compromised
- Enable multi-factor authentication across every system if it was not already active
- Brief staff on what happened and what to watch for, without assigning blame, since most incidents start with an honest mistake
Frequently Asked Questions
Should we pay a ransomware demand?
Generally no, without professional advice first. Payment does not guarantee recovery of files, funds attackers, and can mark a business as willing to pay for future attacks. Contact an IT security specialist and consider reporting to the police first.
Are small businesses legally required to report a data breach in South Africa?
Yes. Under POPIA, any business that suffers a security compromise involving personal information must notify the Information Regulator and affected individuals, regardless of the business's size.
How quickly must a business report an incident under POPIA?
As soon as reasonably possible after becoming aware of the compromise. There is no fixed number of days specified, but unreasonable delay can itself be treated as a failure to comply.
Should we shut down an infected computer immediately?
Disconnect it from the network rather than switching it off completely where possible, since a full shutdown can sometimes erase evidence useful for understanding what happened. Isolating the device is usually the safer first step.
Do we need cyber insurance as a small business?
It is worth considering, since incident response, legal costs and system recovery can be expensive even for a small operation. Many policies also provide access to specialist responders, which can be valuable during an active incident.
Conclusion
A cyber incident is stressful for any business, but small South African companies that respond with a calm, ordered process, containing the problem, preserving evidence, notifying the right people and meeting POPIA reporting obligations, come through in far better shape than those that panic or try to quietly clean up and move on. Preparing a simple written response plan before an incident happens, rather than during one, is one of the most valuable things a small business can do for very little cost.
Want to write a guest post for E-LibraryGlobe?
We welcome well-researched, original guest contributions from writers and businesses across South Africa and beyond. Reach out with your topic idea and we will get back to you.
Explore more practical, problem-solving guides on the E-LibraryGlobe homepage, or browse every article we have published for South Africa.