Skip to main content
株式会社オブライト
Business DX2026-07-225 min read

IT Emergency First Response: The First 30 Minutes

What to do — and not do — in the first 30 minutes of a company IT emergency: three principles of initial response, a symptom-based triage table, and how to route contacts (IPA, police, vendors). A guide non-IT staff can actually use.


What To Do in the First 30 Minutes (Bottom Line)

When trouble strikes your company's systems or website, how you act in the first 30 minutes largely determines how much damage results. Rushing to touch equipment or restarting before confirming the cause can delay recovery or destroy information you'll need later as evidence. Start by following these three principles.

- Contain the damage: Disconnect any PC or server behaving suspiciously from the network (unplug the LAN cable or turn off Wi-Fi). Do not turn off the power
- Record what's happening: Note the time, symptoms, and any error messages, and save screenshots
- Don't restart carelessly: If unauthorized access or ransomware is suspected, restarting can erase evidence needed for the investigation

Symptom-Based Triage Table: What to Do First

The right first move and urgency level depend on the symptoms you're seeing. Find the situation closest to yours in the table below, and follow the linked article for detailed steps.

SymptomUrgencyFirst ActionDetailed Guide
Business system or server is downMedium–HighCheck the scope of impact (everyone or just some)See the steps
Suspected ransomware or ransom demandCriticalDisconnect the infected device from the network (do not power it off)See the steps
Website defaced or unreachableHighTake the site offline temporarily and change admin panel passwordsSee the steps
Email can't be sent or receivedMediumDetermine whether it's isolated to your company or affects partners tooSee the steps
Office PCs or network are downMediumDetermine whether it's the router/line or an individual PC issueSee the steps

Things You Should Never Do

- Immediately power off a device suspected of infection or unauthorized access (this erases evidence stored in memory)
- Contact or send money to a suspected attacker on your own judgment (see ransomware basics for SMBs)
- Restart or reset a system without first checking logs and the current screen state
- Overwrite an existing backup based on an individual's own judgment
- Handle everything internally and delay consulting outside experts

What You Need to Record

It's tempting to focus entirely on finding the cause, but if you put off recording details, you'll struggle to explain the incident later during root-cause investigation or when consulting your insurer or the police — and that delay slows your response. Be sure to record the following.

- The date/time it occurred and how you first noticed it
- Any error messages or screens that appeared (screenshots)
- The scope of impact (number of people, locations, systems affected)
- Any actions already taken (who did what, and when)

Organize Your Contact List Ahead of Time

So you're not scrambling to find contact information during an incident, keep a list of the following contacts ready in advance — it makes your initial response far faster.

ContactMain Use
Internet/line providerInternet line outages or slowdowns
Hardware maker / support deskRouter, server, or other hardware failures
System maintenance vendorBusiness system failures. If unreachable, see how to find alternative contacts
IPA (Information-technology Promotion Agency)Consultation and reporting for ransomware and other cyberattacks
Police (prefectural cybercrime consultation desk)When unauthorized access or data theft with criminal intent is suspected

Preparation in Peacetime Matters Most

The best way to reduce the burden of emergency response is to prepare before anything happens. Review the basics of business continuity planning (BCP) and an overview of IT risk management for SMBs to identify your weak points. Also, if only one person understands how your systems work internally, diagnosing problems during an emergency will be slower. See how to prevent your systems from becoming a black box as well.

We don't have a maintenance contract — who should we contact first?

Contact the vendor or system company that originally built or set up your system. If you can't reach them or don't know who to call, reach out to IPA's consultation desk or a local IT support organization.

If a restart seems like it would fix the problem, should we just restart right away?

If it's a simple freeze with no sign of unauthorized access, that's fine. But if ransomware or suspicious behavior is present, hold off on restarting and wait for expert guidance so evidence isn't lost.

Is it okay to handle everything in-house, or should we always consult outside experts?

For minor issues, handling it internally is fine. But if data leakage or financial loss is possible, consult experts, the police, or IPA early — delayed decisions tend to let damage grow.

If we have backups, are we safe?

Having a backup isn't enough — you need to confirm it can actually be restored. Backups themselves can sometimes be infected or encrypted too, so check whether yours is stored in a location isolated from the network.

Feel free to contact us

Contact Us