First aid after a hacker attack is a decisive step in limiting the damage and regaining control over the situation and the affected systems. The focus is on a few aspects that should be addressed promptly after the discovery of an attack.
This includes disconnecting all compromised systems from the network in order to prevent the attack from spreading further. Immediately informing the IT security team for a quick analysis is essential. In addition, all actions, anomalies and changes should be logged for further legal steps. Identify which data and systems are affected. This helps to prioritise the next steps correctly.