Home > Blog > The Timeline of a Breach: What Actually Happens to a Small Business in the First 24 Hours

The Timeline of a Breach: What Actually Happens to a Small Business in the First 24 Hours

Key Takeaways

  • Most small businesses discover a breach after the attacker has already had time to map the network, identify what is worth taking, and, in many cases, compromise backup systems.
  • Ransomware is involved in 88% of confirmed small business security breaches, according to Verizon’s 2025 Data Breach Investigations Report, compared to 39% for larger enterprises.
  • The first costs after a breach arrive quickly and are often mandatory: emergency forensics, legal review, customer notification letters, credit monitoring, and call center support.
  • Paying the ransom does not guarantee recovery. According to Sophos research, fewer than half of businesses that paid a ransom in 2025 recovered their data.
  • Multi-factor authentication can block the majority of automated, credential-based account compromise attempts. It is the single highest-impact control that most small businesses have not enabled.
  • For Dallas-Fort Worth businesses, the question is whether the right controls, backups, response plan, and IT support are in place before it reaches customers, staff, or regulators.
  • Preparation made before a breach consistently costs a fraction of what recovery costs afterward.

The Breach You Don’t See Coming

Most small business owners picture a cyberattack as a dramatic moment: a pop-up, a phone call, a system going dark all at once. The reality is considerably quieter, and the damage is usually done by the time the visible event occurs.

By the time a breach announces itself, the attacker has often been inside the network for days. They have mapped systems, identified which files are worth taking, and in many cases, compromised backup storage before anyone noticed. The ransom note or frozen screen is usually the final step in a process that began much earlier.

This article walks through what actually happens to a small business during a cybersecurity breach: the first 24 hours, the costs that arrive first, the legal obligations that follow, and the decisions that separate businesses that recover from those that don’t. It draws on current research from IBM, Verizon, Sophos, and CISA, along with illustrative scenarios based on real incident patterns.

None of this is intended to alarm. It is intended to be useful. CCS Horizon works with businesses on small business cybersecurity before incidents occur, and the most consistent finding from that work is straightforward: preparation made in advance costs a fraction of what recovery costs afterward.

That preparation often includes practical cybersecurity services, tested IT backup and recovery planning, access control reviews, and day-to-day IT services that reduce the chance of a small mistake becoming a business-wide outage.

Find Your Cybersecurity Gaps Before an Incident

CCS Horizon offers a no-obligation IT and security health check for small and medium-sized businesses across Dallas-Fort Worth. We’ll identify what matters most and help you build a practical plan before you need it.

Before Hour Zero: The Attacker Is Already Inside

Attackers often gain initial access through routine vulnerabilities, and entry points are almost always mundane:

  • A phishing email opened two weeks prior
  • A password reused across a personal and business account
  • A remote access port left open
  • A contractor whose credentials were never deactivated

Automated scanning tools do not care how large your business is. They search continuously for exposed systems with weak credentials or unpatched vulnerabilities. For attackers using these tools, a 20-person business is as reachable as a 2,000-person one.

Human error accounts for the majority of small-business cyber incidents, and attackers do not need to be sophisticated. They simply need one person, in one moment, to make one ordinary mistake.

Once inside, a patient attacker will move stealthily through the network, mapping what is connected, locating valuable files, identifying backup storage, and in some cases disabling security tools, all before triggering anything that looks like an alert.

“What we see consistently is that the first 30 minutes of a breach response are the most consequential. Businesses that slow down, isolate systems without wiping them, and make the right calls early have materially better outcomes. The ones that try to fix it themselves before calling anyone almost always make things harder.” Senior Incident Response Consultant, CCS Horizon

Hours 1 to 3: The Discovery

For most small businesses, discovery of a breach comes from a customer who receives a strange email appearing to originate from the business’s domain, an employee who cannot log in with a password they’ve used for years, or a bank flagging unusual outgoing transactions.

The instinct in this window, to start investigating immediately, is understandable but usually counterproductive. Clicking around on a compromised machine can trigger ransomware that was waiting for a signal. 

Moving or deleting files destroys forensic evidence that will be needed later. The recommended first action is to disconnect affected systems from the network and contact a professional incident responder before taking any further action. Where possible, isolate systems from the network before powering them down; if disconnection is not possible, your incident responder or CISA guidance should inform next steps.

If you have a cyber insurance policy, that provider’s emergency line should be the first call. Many policies include 24/7 incident response support. The number should already be saved before an incident occurs.

Hours 3 to 6: The Cascade

While the initial assessment is underway, several things are happening simultaneously. If ransomware has been deployed, it is encrypting files not only on the infected machine but across every network drive and shared folder that the machine has access to. That can include accounting databases, client records, and email archives. By the time the ransom note appears on screen, the encryption is already complete.

If the breach was aimed at data theft rather than disruption, the attacker may already have left, having exfiltrated customer records, financial data, or employee payroll files before anything looked unusual. If email has been compromised, phishing messages may already have gone to every contact in the address book, bearing the business owner’s name.

Within these first few hours, a business is typically managing a security incident, a communications crisis, and legal liability simultaneously.

An Illustrative Scenario

Consider a 23-person business with limited operating cash and no existing incident response agreement. An office manager receives a convincing, AI-generated phishing email that appears to come from the company’s largest client. She clicks a link and enters her corporate login credentials into a fake Microsoft login page.

This is why Microsoft cloud services need more than basic account setup. MFA, conditional access, admin role control, and sign-in monitoring should be configured before a stolen password becomes a full network compromise.

Within minutes, a threat actor logs into the company’s cloud network from an IP address in another country. Because multi-factor authentication has not been enabled, the attacker enters without triggering a second verification step. That gap is common. According to cybersecurity research, 66% of small businesses lack multi-factor authentication entirely. One stolen password is now enough to access the company’s systems.

Over the next 40 hours, the attacker maps the network, locates backup files, and begins encrypting them. The backup drive is directly connected to the local network, with no segmentation or immutable write protection. The attacker also exfiltrates the customer database, QuickBooks financial files, and employee payroll records containing Social Security Numbers and banking details.

At 2:30 AM on the following Wednesday, the ransomware executes across all connected systems. The ransom demand is $45,000 in Bitcoin, with a 72-hour deadline. Samples of the stolen data are attached as proof. The business cannot pay the ransom without exceeding its available operating cash after payroll and rent obligations. Even if it could, current research suggests fewer than half of businesses that pay a ransom recover their data.

Hours 6 to 24: The Financial Reality Emerges

Within the first 24 hours of the scenario above, the business faces the following direct costs:

Cost Category Amount
Emergency forensics retainer (upfront, no existing agreement) $5,000 to $15,000
Attorney fees for breach notification compliance $2,000 to $5,000
Printing and certified mail postage for 1,847 notification letters Depends on affected record count
Credit monitoring services for affected customers (12-24 months) $15 to $20 per person per year
Dedicated notification call center $5,000 to $10,000

These figures do not include lost revenue from canceled contracts, customers who switched to competitors, or the operational cost of employees working at 30% productivity on manual paper-based systems for one to three weeks.

Downtime costs vary widely, but the impact can build quickly through lost productivity, missed work, delayed orders, customer communication, and recovery labor.

For a business operating on thin margins, the long tail of recovery costs is often more damaging than the immediate incident: only 47% of a breach’s total cost is incurred in the first year. The remaining 53% arrives in year two and beyond.

What the Law Requires: Notification Timelines

A data breach creates immediate legal obligations under state and federal law, and the window to meet those obligations is often shorter than most business owners expect.

The US does not have a single national breach notification law. Instead, businesses must comply with the notification rules of every state where affected customers or employees reside. For Dallas-Fort Worth businesses, Texas requirements matter first. But if your customer or employee records include people in other states, other notification rules may apply too.

  • Texas: Notify all affected individuals within 60 days. If 250 or more Texas residents are affected, file a separate notification with the Texas Attorney General within 30 days. That filing becomes a searchable public record on the Attorney General’s breach portal.
  • California (SB 446): Notify all affected California residents within 30 calendar days. If 500 or more are affected, send a copy to the California Attorney General within 15 days of notifying consumers.
  • HIPAA: Notify all affected individuals and the US Department of Health and Human Services within 60 calendar days. DFW healthcare businesses should verify obligations with a qualified attorney.

A practical point that often surprises business owners is that the notification clock typically starts when a business has reasonable certainty that a breach occurred, not when the investigation is complete. Waiting for full confirmation before notifying can create bigger legal exposure than the notification itself.

Meeting these obligations requires knowing exactly what data was accessed. If forensic evidence is wiped out during early remediation, businesses often cannot prove the scope of the breach. In that situation, regulators default to the worst-case assumption: treating the entire customer database as compromised, which dramatically increases notification obligations and legal exposure.

This is where IT compliance planning matters. A business needs to know what data it holds, where that data lives, who can access it, and which notification duties may apply if it is exposed.

“The notification clock starts when you have ‘reasonable certainty’ of a breach, not when the investigation is complete. We see businesses wait because they want more information before they notify, and that decision consistently creates bigger legal problems than it prevents.” Data Privacy Counsel, CCS Horizon

Before hour zero
Attacker gains access Phishing email opened. Credentials captured via fake login page.
Silent movement Network mapped. Backup storage located. No alerts triggered.
Hours 1 to 3
Discovery Employee locked out, or bank flags unusual outgoing transactions.
First response Isolate systems. Call cyber insurer. Do not touch or delete files.
Hours 3 to 6
Ransomware executes Encryption spreads across all connected drives. Backups compromised.
Data exfiltrated Customer records, financial files, and payroll data already removed.
Hours 6 to 24
Mandatory costs arrive Forensics, legal, notification, and credit monitoring before recovery begins.
Notification clock starts Texas: 60 days. California: 30 days. Clock runs from point of discovery.
Recovery
1 to 3 weeks To restore operations, depending on backup quality and insurer response.
53% of costs Arrive in year two and beyond through legal, attrition, and productivity loss.

Sources: Verizon 2025 DBIR; IBM Cost of a Data Breach 2024. Scenario based on illustrative real-world incident patterns.

The Evidence Problem: Why How You Respond Matters

One of the most consequential and least understood aspects of breach response is the tension between restoring operations quickly and preserving forensic evidence needed to limit legal liability.

IT administrators and managed IT service providers are trained to restore operations. When a system is down, the instinct is to reimage drives, run cleanup tools, and get the business back online. Each of these actions, taken before forensic investigation, destroys evidence.

If forensic evidence is wiped during early remediation, it may be impossible to determine precisely which data was accessed. In that situation, regulators typically default to the broadest possible assumption: treating the entire customer database as compromised, which significantly increases notification obligations and legal costs.

What About a Breach Coach?

A breach coach is a specialist attorney, often provided through a cyber insurance policy, who helps coordinate the legal side of a data breach response. Their main practical value is structuring the forensic investigation as privileged legal work, thereby protecting the investigation’s findings from use against the business in future litigation.

For most small businesses, the practical takeaway is this: know who to call before an incident occurs. Your incident response plan should include your cyber insurance contact, legal contact, IT provider, bank, and the internal decision-maker who holds authority during a crisis. CCS Horizon can help businesses prepare the technical side of that plan, including backups, access controls, monitoring, and recovery readiness.

What Actually Changes the Outcome for Small Business Cybersecurity

There are no guarantees in cybersecurity, and no business should assume it can be made impenetrable. What preparation does is change the severity of the outcome when something goes wrong, and in most cases, substantially reduce the cost of recovery. The following controls consistently make the most difference for small businesses:

Multi-Factor Authentication (MFA)

Multi-factor authentication (MFA) can block the majority of automated, credential-based account compromise attempts. Microsoft’s research indicates that 99.9% of compromised accounts don’t have MFA. It costs between nothing and a few dollars per user per month and requires no dedicated IT staff to implement. The scenario described earlier, where a phishing click triggered a 40-hour network intrusion, would not have occurred if MFA had been enabled on the office manager’s account.

Offline, Immutable Backups

Ransomware is substantially less damaging when a business can restore from a clean backup that was not connected to the infected network. A backup drive plugged into a compromised machine encrypts alongside everything else. Backups need to be stored separately from the main network, write-protected so they cannot be overwritten by an attacker, and tested regularly so the business knows restoration actually works.

Effective IT backup and recovery is simply about keeping recoverable data separated from the compromised environment and proving that restoration works before the business depends on it.

A Written Incident Response Plan

A written incident response plan should define who holds decision authority, include an offline copy of key contacts (IT provider, legal counsel, insurance broker, bank), and outline the containment steps the first responder should take. IBM research suggests that having a tested incident response plan reduces the average total cost of a breach by approximately $232,000.

Cyber Insurance

Cyber insurance matched to actual risk provides access to specialist incident response support, pre-approved forensic investigators, and legal guidance without the upfront cost of finding those resources during a crisis. The insurer’s emergency number should be saved before an incident occurs, not searched for at 3 AM.

Security Awareness Training

Security awareness training is most useful when it is continuous, practical, and paired with technical controls such as MFA, email filtering, access management, and reporting workflows. Training alone will not stop every phishing attempt, but it can reduce avoidable mistakes and help employees report suspicious activity sooner. 

The most common entry point into a small business network is not a technical vulnerability, but an untrained employee who clicks a convincing link.

Annual prevention costs for a standard small business typically range from $5,000 to $15,000. The typical recovery cost range is $120,000 to $1.24 million. The cost-benefit ratio of proactive security investment is clear.

Don’t Wait for the Call at 3 AM

CCS Horizon helps small and medium-sized businesses build practical, affordable cybersecurity programs that reduce risk before incidents occur. Our team has worked on breach response, incident planning, and security assessments across multiple industries.

Frequently Asked Questions: Small Business Cybersecurity Breach

The questions below reflect the most common inquiries we receive about small business cybersecurity breaches.

Any unauthorized access to your systems, data, or accounts counts as a breach, whether files were stolen, encrypted, or simply viewed. This includes captured login credentials, ransomware, unrevoked access by a former employee, and unauthorized access to customer or financial records. If you are unsure whether an incident qualifies, treat it as a breach and seek professional advice.

Disconnect affected systems from the internet without powering them off. Powering off a compromised machine destroys volatile memory evidence that forensic investigators need. Do not run cleanup tools or delete files. Contact a professional incident responder or your cyber insurance provider’s emergency line. Notify your attorney and your bank if financial credentials may have been exposed. Document everything from this point forward.

Forensic investigation and initial containment typically take between 24 and 72 hours for a small business. Full system restoration can take one to three weeks, depending on the extent of the damage and the quality of backup systems. Legal notification obligations begin running from the point of reasonable certainty of a breach, often before the investigation is complete. The full financial and operational impact of a breach typically extends across 12 to 24 months.

Ransomware is the most prevalent threat: 88% of confirmed small-business security breaches involve ransomware, compared to 39% for larger enterprises. Phishing, credential stuffing, and business email compromise are the most common entry points.

Paying the ransom does not guarantee recovery. 2025 research found that fewer than half of businesses that paid a ransom successfully recovered their encrypted data. Any decision to pay should be made with your cyber insurance provider and a breach coach attorney, who can assess whether payment would trigger sanctions compliance issues or affect your insurance coverage. Businesses with clean, offline backups rarely face a situation where ransom payment is the only viable option.

Article Sources

The following sources informed this article. Readers are encouraged to verify current requirements directly, as regulations and statistics are subject to change.

  1. IBM Security. Cost of a Data Breach Report 2025. Accessed June 17th, 2026
  2. Verizon. (2025). Data Breach Investigations Report 2025. Accessed June 17th, 2026
  3. Federal Trade Commission. Cybersecurity for Small Business. Accessed June 17th, 2026
  4. US Department of Health and Human Services. HIPAA Breach Notification Rule. Accessed June 17th, 2026
  5. National Institute of Standards and Technology. Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile. Accessed June 17th, 2026
  6. Coggno. Data Breach Notification Laws: State-by-State Reporting Timelines US Employers Must Follow. Accessed June 17th, 2026
  7. Microsoft Learn. Security at your organization: Multifactor authentication statistics
  8. Insurance Training Center. What Is a Breach Coach? Accessed June 18th, 2026
  9. Sophos. The State of Ransomware 2025. Accessed June 18th, 2026

Note: US state breach notification laws, HIPAA requirements, FTC rules, and sector-specific regulations are subject to change. This article provides general information only and does not constitute legal or security advice. Readers should consult a qualified attorney and cybersecurity professional for guidance specific to their business and jurisdiction.