Cyber attack: what it is, what actually happens, and what your business should do about it

The essentials in 30 seconds
A cyberattack is an attempt to cause harm through IT systems: to steal, encrypt, alter data, or take a service offline. For small and medium businesses, the most important insight is an uncomfortable one. The overwhelming majority of attacks do not choose their victim at all. Automated programs sweep the internet around the clock for vulnerable systems, and whoever is reachable and poorly protected ends up caught in the net sooner or later, whether it is a workshop, an accounting firm or a manufacturer.
This article is a guide, not a news bulletin. It explains what a cyber attack actually is, how one typically unfolds, what to do in the first hours after an incident, and which measures realistically protect a company. No fear-mongering, just a clear plan that someone without deep IT knowledge can either implement or at least demand from whoever runs their systems.
The good news comes first: most successful attacks rely on no wizardry whatsoever, only on long-known weaknesses. And those you can actually do something about.
What is a cyber attack?
A cyberattack is any action, carried out through computers, networks or connected devices, that aims to undermine the normal, protected operation of a system. That might mean someone reads data they should not see, encrypts it and demands a ransom, brings a website to its knees, or quietly puts your computing power to work for themselves.
The term is deliberately broad. A cyberattack (often loosely called a hacker attack) covers the mass spam with the forged invoice attachment just as much as the months-long operation against a single corporation. For everyday life in an SME, the neat categories matter less than two questions underneath them: how does someone get in, and how much damage is a single mistake allowed to cause before it is stopped?
Three characteristics define today’s threat landscape:
Attacks are mostly automated. The romantic picture of a hacker hand-picking a company is the exception. The rule is a machine working through millions of addresses and flagging where a known flaw answers back. To such a scanner, your business is not a name but a reachable address, with or without an open door.
Attacks are a business. Behind ransomware sit organized structures with support desks, price lists and revenue sharing. That lowers the barrier to entry and explains why even small targets pay off: when an attack costs almost nothing and runs at scale, even a small share of paying victims turns a profit.
The damage is rarely the break-in itself. The expensive part is what follows: the halted operations, the replacement of every credential, the reporting duties, the loss of customer trust. Just how stark the mismatch between the attacker’s effort and the victim’s loss can be, we worked through with a real case in anatomy of a server takeover: a few euros of profit for the perpetrator, a multiple of that in damage for the company.
The most common types of cyber attack
“Cyberattack” is an umbrella term. So the rest of this article lands, here are the attack types that actually turn up in the daily life of an SME, each with its goal and a first pointer on what matters when it hits.
| Type of attack | How it works | Typical goal | First response |
|---|---|---|---|
| Phishing | Forged emails or pages coax out credentials or a click on malware | Credentials, initial foothold | Lock the affected account, change the password, check MFA, warn colleagues |
| Ransomware | Malware encrypts data and demands a ransom, often threatening publication | Extortion, direct payout | Isolate the system, do not pay, restore from a separated backup |
| DDoS (overload) | Floods of requests knock a website or service offline | Disruption, sometimes a distraction | Put protection in front of the service, involve your provider |
| Supply chain | The attack comes through a provider or an embedded component | Many victims through one lever | Identify the affected software, contact the vendor, rotate access |
| Business email compromise | Attackers pose as the boss or a supplier to trigger transfers | Direct financial fraud | Stop the payment, inform the bank, enforce four-eyes approval |
The list is not exhaustive, but it covers what most companies face. What stands out is how often the human is the first way in, not the technology: an unthinking click, a reused password, a convincingly faked invoice.

What happens during a cyber attack? The typical sequence
Many people picture an attack as one dramatic moment: black screen, ransom note, the end. In reality it is usually a process across several stages, and that sequence is exactly what decides where you can still stop it.
1. Reconnaissance and entry. Automated scanners look for a weakness: an outdated application, an administration interface reachable from the internet, an account with no second factor. Alongside runs the human variant through phishing. Entry rarely succeeds through high art, but through the cheapest open door.
2. Getting a foothold. Once inside, attackers set up a persistent backdoor, often disguised as a harmless system service, that survives a reboot. In the case we documented, this happened within seconds of the successful break-in.
3. Spreading out. From that first machine, the attackers reach further: they hunt for passwords in configuration files, SSH keys, access to more servers. The goal is to get from one compromised system to as many as possible. Missing network segmentation is the attacker’s best friend here.
4. Striking. Only at the end does the attack become visible. The data gets encrypted, the ransom note appears, or the stolen data shows up for sale. Days or weeks often sit between the break-in and this moment, spent quietly preparing everything unseen.
That delay is the real point. A cyber attack is seldom the loud bang people imagine. It is closer to a quiet, extended stay in the house, going on long before anyone notices the broken window. In our server takeover case, a fully compromised server went undetected for five days, and it only surfaced by accident, when the computing load crashed other services.
What your business should do in the first hours
If you suspect an attack is under way, the first hours decide the scale of the damage. The trouble is that anyone who starts thinking only once the emergency hits loses precisely the time that counts. That is why the following belongs in an incident plan you write calmly in advance, not in a panic at three in the morning.
| Time window | What to do | What to avoid |
|---|---|---|
| Immediately (0–1 h) | Disconnect affected systems from the network (pull the cable, turn off Wi-Fi), but do not power them down. Alert the response team. | Do not shut down (it wipes volatile evidence), do not delete files on your own. |
| First hours | Document the incident (what, when, which systems). Lock the credentials of affected accounts. Protect backups and take them offline. | Do not rush to pay, do not negotiate with attackers without a plan. |
| First day | Scope the damage: which data, which systems? Bring in external incident response. Check whether personal data is affected. | Do not pretend nothing happened. A concealed breach gets more expensive. |
| Within 72 h | If personal data is affected: notify the competent data protection authority (GDPR deadline). Inform affected individuals where required. | Do not let the deadline pass, missing it is a fineable offence in its own right. |
A few points deserve emphasis. Disconnect rather than power off: shutting a compromised machine down destroys evidence in memory that is valuable for the investigation. Do not pay: the BSI and most agencies consistently advise against ransom payments, because they neither reliably return your data nor prevent a copy from being published, and every payment keeps the business model alive. Protect backups at once: modern ransomware deliberately looks for reachable backups to encrypt them too. A backup sitting on the same network is often already lost when it matters.

Cyberattacks on companies: why SMEs in particular are in the crosshairs
The idea that small and medium firms are “too unimportant” to attack is stubborn, and dangerous, because it rests on a misunderstanding: it assumes someone has to choose your company first. With automated attacks, that choice does not happen.
In fact, SMEs are a preferred target for several concrete reasons:
- Less protection, the same attack surface. A small firm runs the same servers, mailboxes and remote-access tools as a large one, but rarely has its own security team. The ratio of attack surface to defense is unfavorable.
- An attractive stepping stone. Through a poorly secured supplier, attackers sometimes reach that supplier’s larger customers. The small firm is then not the final target but the springboard.
- Painful dependency. When IT fails at a small company, the whole operation often stops. That dependency makes extortion effective, because the pressure to get working again is enormous.
The conclusion is not alarm but level-headedness. An SME does not need to armor itself against an intelligence-grade operation. It needs to close the cheap open doors that the automated mass aims for. That is achievable, and far cheaper than any serious incident.

How to protect your business from a cyber attack: the SME playbook
Now the part that counts. The measures against the realistic threat are known, proven and workable in nearly any company. None of them require a large budget, but they do require commitment: a clear owner and a routine you can rely on.
1. Keep software up to date. The single most effective lever. The overwhelming majority of successful attacks exploit flaws for which a patch has long been available. A fixed update rhythm, with critical security updates expedited, closes exactly that entry point. How reliably a known but neglected flaw turns into damage worth millions, we lay out in our article on the IT security vulnerability through WannaCry, Log4Shell and MOVEit.
2. Multi-factor authentication everywhere. A stolen password is worthless if logging in still needs a second factor. MFA belongs on every remote access, every mailbox, every administrative account. This one measure absorbs a large share of phishing’s consequences, because the captured password alone no longer opens the door.
3. Train your people. Since many attacks begin with phishing, well-informed staff are a genuine line of defense. This is not about annual compliance videos but concrete examples: what does a forged invoice look like, how do you spot the fake-boss scam? Anyone who prefers to ask one time too many when in doubt is part of the defense.
4. Minimize privileges. No application needs full rights, no office machine needs access to everything. If an app runs as administrator and gets taken over, the attacker owns the whole server instantly. That very mistake, an application with full privileges, turned an app-level problem into a complete server takeover in the case we documented.
5. Segment your network. You have to assume that one system will eventually fall. Whether that stays a contained incident or paralyzes the whole company is decided by segmentation. If the compromised machine can reach accounting, the file shares and the backups, so can the attacker.
6. Monitor and keep backups. The difference between an incident spotted in minutes and one that runs for days is enormous. Basic monitoring, unusual load, unknown processes, unexpected outbound traffic, shortens that window dramatically. And tested backups, stored separated from the network, are the difference against ransomware between a restart and an existential question.
7. Get an outside look. Your own attack surface is hard to see from inside. A security audit answers the questions that matter: what is reachable from outside, which known flaws are open, and would a single mistake be enough to lose everything? Anyone who cannot or does not want to secure the running platform themselves can hand patching, hardening and monitoring to a managed hosting setup, where these tasks are part of operations rather than something someone has to remember.

Cyberattacks and national authorities: who warns, who helps
Germany has a central point of contact that too few SMEs make use of: the BSI (Federal Office for Information Security). Three of its offerings are directly useful for small and medium businesses.
- Advisories and CERT-Bund. The BSI continuously publishes warnings about current flaws and attack waves, free to subscribe to and written to be understood. Read them, and you often learn days before the first wave that a critical flaw affects your software.
- IT-Grundschutz. A freely available, field-tested framework for building your security systematically. To get started, nobody has to implement the whole thing, the basics already cover the most common gaps.
- Situation reports and recommendations. The annual report on the state of IT security gives a realistic picture of which threats actually matter, beyond the headlines.
The BSI does not replace your own security work, but it delivers exactly what many small firms lack: reliable, vendor-neutral information about what genuinely matters right now. Comparable bodies exist internationally, such as CISA in the United States, with its Known Exploited Vulnerabilities catalog, or the NCSC in the UK.
The bottom line: preparation beats perfection
For most companies, a cyberattack is not a distant disaster scenario but a constant background risk, as ordinary as the weather. Which is exactly why neither panic nor denial helps, only sober preparation.
The decisive insight runs through every serious incident we have seen: the difference between a scare and an existential crisis rarely lies in the attacker’s cleverness. It lies in whether the company was prepared, whether it knew its systems, kept its software current, demanded a second factor, limited its privileges, and had an incident plan in the drawer before it was needed. None of this is spectacular, all of it is achievable at SME scale, and together these measures catch by far the largest share of realistic attacks.
You do not have to become a security expert. But you should know where your doors are, and make sure none of them stands open. The most honest first step is a look from outside: what is reachable, what is vulnerable, and would a single mistake be enough? Those are precisely the questions a security audit answers, before an attacker answers them for you.
Frequently asked questions
What is a cyber attack?
A cyberattack is an attempt to cause harm through IT systems: stealing data, encrypting it, altering it, or knocking a service offline. It ranges from mass-scale phishing through ransomware to attacks on the supply chain. The key point for small and medium businesses: most attacks do not pick a specific company, they scan automatically for the next open door. If you are reachable and poorly secured, you get found, regardless of your size or industry.
What happens during a cyber attack?
Usually it runs in phases. First, automated scanners look for a weakness, an outdated piece of software or a weak password. Once inside, the attackers establish persistent access, move through the network, and hunt for valuable data and credentials. The visible damage comes last: encryption with a ransom demand, data theft, or abuse of your computing power. Days or even weeks often pass between the initial break-in and the moment the damage becomes obvious.
What should you do during a cyber attack?
First, disconnect affected systems from the network without powering them off, so volatile evidence is preserved. Then alert a pre-defined response team, document the incident, and lock the credentials of affected accounts. Do not rush to pay a ransom and do not start deleting things on your own. If personal data is affected, the GDPR sets a 72-hour deadline to notify the supervisory authority. The single most important factor is an incident plan written before the emergency, not during it.
How can I protect my company from a cyberattack?
With a handful of fundamentals that together stop the large majority of realistic attacks: patch software promptly, enable multi-factor authentication everywhere, train staff to spot phishing, minimize privileges, segment your network, monitor actively, and keep tested backups an attacker cannot encrypt along with everything else. An external security audit shows where your door is actually standing open.
Are small and medium businesses really targeted?
Yes, and more than many owners assume. Automated attacks do not select by company size, they select by exposure. A small firm runs the same servers, mailboxes and remote-access tools as a large one, but rarely has a dedicated security team. That imbalance, plus the role of small suppliers as a stepping stone into larger customers, makes SMEs a frequent and profitable target.
Should you pay the ransom in a ransomware attack?
Security agencies, including Germany's BSI, advise against it. Paying guarantees neither the return of your data nor that a copy will not be published, and it funds the next attack. If you hold tested, separated backups, you are not extortable in the first place. That is exactly why a solid backup strategy is the most valuable investment against ransomware.
What is the difference between a cyberattack and a data breach?
A cyberattack is the action, the attempt to break in or cause harm. A data breach is one possible outcome, where confidential data is actually accessed, stolen or exposed. Not every attack leads to a breach, and not every breach comes from a sophisticated attack, some are plain misconfiguration. For your reporting obligations, the breach is what usually triggers legal deadlines.
Ready for a security check?
Write to us and we will find out where your weak spots are. No sales pressure, just a straightforward conversation.
Write to us