Cyber Incident Response in Social Care: What to Do in the First 24 Hours
When a cyber incident affects an adult social care provider, the first 24 hours are critical. A problem that initially appears technical can quickly disrupt care records, medication administration, staff deployment, safeguarding communication and contact with commissioners. The immediate priority is therefore not simply to restore technology, but to protect people, maintain essential support and stabilise the organisation.
Providers developing digital transformation, cyber resilience and secure care systems in adult social care must prepare for incidents before they occur. The first-day response should be structured, calm and operationally led, with technical specialists, care leaders, safeguarding leads and senior decision-makers working within one coordinated framework.
Cyber incident response connects directly with effective business continuity in tenders and practical service disruption response. Commissioners will judge providers not only on whether they attempted to prevent an incident, but on how quickly they recognised the risk, protected people, maintained services and recorded their decisions.
Why the first 24 hours matter
Cyber incidents can develop rapidly. A compromised account may provide access to several systems. A supplier outage may affect multiple locations. Ransomware may prevent staff from accessing records while also disrupting email, rostering and payroll.
During the first day, providers may need to manage:
- uncertainty about the cause and scale of the incident;
- loss of access to care and medication records;
- concerns about exposed or altered information;
- staff confusion and competing instructions;
- pressure from people, families and commissioners;
- technical containment decisions;
- activation of manual continuity processes;
- safeguarding and data-protection assessments;
- supplier and specialist involvement; and
- planning for prolonged disruption.
A strong first-day response protects people first, limits further damage and creates a reliable basis for recovery.
Recognise and declare the incident early
One of the most common response failures is hesitation. Teams may wait for technical confirmation before escalating, even though care systems are already unavailable or suspicious activity is continuing.
Providers should establish practical thresholds for declaring a suspected cyber incident. Warning signs may include:
- loss of access affecting several users or services;
- unexpected password-reset activity;
- multiple locked accounts;
- emails sent without the account holder’s knowledge;
- unusual administrator activity;
- files becoming inaccessible or renamed;
- ransom or encryption messages;
- disabled antivirus or monitoring tools;
- unexpected supplier warnings;
- unexplained changes to care records; and
- significant slowing or failure across connected systems.
Declaring an incident does not determine blame or confirm the technical cause. It activates a controlled process and gives authorised leaders permission to begin containment and continuity action.
Establish immediate command and control
The duty manager or on-call lead should have clear authority to activate the response plan. An incident lead and deputy should be appointed as early as possible to reduce confusion and prevent dependency on one person.
Initial command arrangements should identify:
- the overall incident lead;
- the operational continuity lead;
- the technical or supplier lead;
- the safeguarding lead;
- the information-governance or data-protection lead;
- the communications lead;
- the senior executive responsible for oversight; and
- administrative support for the incident log.
Technical recovery and care continuity should remain connected but distinct. IT specialists may lead containment, while operational managers retain responsibility for safe care.
Operational example 1: suspicious rostering activity
Context: A homecare provider identifies unusual logins and unexplained changes within its digital rostering platform during the early morning period.
Step 1: The on-call manager declares a suspected cyber incident and instructs staff not to rely on the affected platform.
Step 2: External access is suspended while technical specialists review account activity and reset higher-risk credentials.
Step 3: The provider activates its current paper rota pack and prioritises medication calls, double-handed visits and people at greater risk.
Step 4: Office staff introduce enhanced telephone confirmation so that visit completion and emerging concerns remain visible.
Step 5: The incident lead records decisions, service impact and actions while preparing an initial commissioner update.
This response contains the potential compromise without allowing technical investigation to interrupt essential homecare delivery.
Containment: prevent further spread
The immediate technical objective is to prevent the incident from affecting additional devices, accounts or systems. Containment decisions should follow specialist guidance and reflect the nature of the suspected event.
Potential actions include:
- disconnecting affected devices from networks;
- isolating systems or service locations;
- disabling compromised accounts;
- terminating active sessions;
- resetting privileged credentials;
- blocking suspicious emails or domains;
- temporarily stopping system integrations;
- restricting remote access;
- preserving logs and forensic evidence; and
- contacting critical technology suppliers.
Staff should not delete suspicious messages, wipe devices or attempt unauthorised technical repairs. Well-intended action may destroy evidence, spread malware or make recovery more difficult.
Containment without creating additional care risk
Containment decisions must consider operational consequences. Disabling a care-record platform may reduce technical exposure but remove access to medication, safeguarding or risk information.
Before restricting a critical system, leaders should consider:
- which services depend upon it;
- which people may be placed at greater risk;
- whether approved alternative information is available;
- how staff will receive instructions;
- whether medication processes can continue safely;
- how safeguarding concerns will be escalated;
- how temporary records will be maintained; and
- when the containment decision will be reviewed.
The rationale should be documented clearly, including the balance between preventing further compromise and maintaining safe care.
Move services into safe-mode working
Where normal systems cannot be trusted or accessed, services should move into a predefined safe mode. This means using the minimum reliable processes required to maintain essential, person-centred support.
Safe-mode arrangements may include:
- controlled offline care summaries;
- emergency medication records;
- manual visit schedules;
- temporary care-note forms;
- enhanced shift handovers;
- approved telephone trees;
- manual incident reporting;
- local safeguarding contact lists;
- additional management checks; and
- temporary restrictions on non-essential digital activity.
Safe mode should not mean uncontrolled improvisation. Staff need approved documents, clear responsibilities and secure information-handling arrangements.
Identify priority people and services
Providers should quickly identify where digital disruption could cause the greatest harm. Resources and management attention should be prioritised accordingly.
Higher-priority situations may include:
- time-critical medication;
- delegated healthcare tasks;
- active safeguarding concerns;
- people at risk of deterioration;
- complex communication needs;
- high-risk moving and handling;
- behaviour-support requirements;
- people living alone;
- double-handed homecare visits;
- end-of-life support; and
- services with limited on-site management.
A temporary risk-prioritisation list can help leaders allocate calls, visits, staff and management oversight during the disruption.
Operational example 2: loss of supported-living records
Context: A supported living provider loses access to digital care records overnight following a suspected system compromise.
Step 1: The on-call lead activates the secure critical-information pack held for each person.
Step 2: Staff verify medication, communication, safeguarding, behaviour-support and emergency information at handover.
Step 3: Additional verbal handover checks are introduced at every shift change while digital records remain unavailable.
Step 4: Significant events and changes are documented on controlled temporary forms and escalated centrally.
Step 5: Managers review the highest-risk services throughout the night and prepare records for later reconciliation.
This preserves essential care information while maintaining confidentiality, oversight and an auditable record.
Protect medication continuity
Medication safety may become an immediate concern where electronic MAR systems or connected pharmacy information are unavailable. Providers should activate their approved medication-downtime procedures rather than create local alternatives during the incident.
Immediate controls may include:
- retrieving current authorised emergency MAR information;
- checking allergies and recent medication changes;
- identifying time-critical medicines;
- introducing controlled manual recording;
- using additional checks for higher-risk medication;
- confirming pharmacy and clinical contact routes;
- recording new instructions carefully;
- escalating any uncertainty rather than assuming; and
- preserving records for later reconciliation.
Leaders should confirm which services have successfully activated the process rather than assuming that written instructions have been followed everywhere.
Maintain safeguarding processes
Cyber disruption can create safeguarding risks where staff lose access to protection plans, contact restrictions, known allegations or communication information.
Within the first hours, the safeguarding lead should assess whether the incident affects:
- active safeguarding concerns;
- immediate protection measures;
- known sources of abuse or exploitation;
- contact restrictions;
- financial information;
- addresses and personal contact details;
- mental capacity or best-interests information;
- communication and advocacy needs;
- referral routes; and
- the organisation’s ability to contact statutory partners.
Where sensitive information may have been exposed, the provider should assess the additional individual risk and consider whether immediate protective action is required.
Start a time-stamped incident log
The first 24 hours must create a clear evidence trail. Commissioners, regulators, insurers and investigators may later need to understand what was known, what decisions were made and why.
The incident log should record:
- the time the concern was first identified;
- who reported it;
- systems, locations and services affected;
- decisions made and by whom;
- the rationale for significant actions;
- technical containment measures;
- continuity arrangements activated;
- safeguarding and data assessments;
- communications issued;
- supplier and specialist advice;
- outstanding risks; and
- planned review points.
The log should distinguish confirmed facts, reasonable assumptions and information still awaiting verification.
Record the reason behind decisions
Documenting what happened is not enough. Providers should record why proportionate decisions were made.
Examples include:
- remote access disabled to prevent further unauthorised activity;
- manual visit confirmation introduced because electronic call monitoring was unavailable;
- non-essential admissions paused because critical care information could not be verified;
- additional management cover introduced for higher-risk services;
- commissioner notified early because service continuity was materially affected; and
- system restoration delayed until data integrity could be confirmed.
This creates defensible assurance that leaders considered safety, proportionality and available evidence.
Establish a structured meeting rhythm
Incident teams should hold short, structured check-ins. Early meetings may occur hourly before moving to longer intervals as the situation stabilises.
Each check-in should cover:
- current technical position;
- services and people affected;
- medication and safeguarding risks;
- staffing and operational continuity;
- new incidents or concerns;
- communications completed;
- commissioner and supplier updates;
- decisions required;
- actions, owners and deadlines; and
- the timing of the next review.
Meetings should remain decision-focused. Excessive discussion without clear ownership can delay essential action.
Engage technical and specialist support
Providers should contact their IT supplier, internal technical team or specialist cyber support promptly. Critical contact details should already be available within the response plan.
Technical teams may need to:
- preserve and review system logs;
- identify affected accounts or devices;
- isolate compromised systems;
- analyse suspicious traffic;
- secure administrator access;
- assess backup integrity;
- identify the likely route of compromise;
- advise on evidence preservation;
- estimate recovery requirements; and
- support safe restoration planning.
Operational leaders should request clear explanations of likely care impact rather than relying solely on technical descriptions.
Assess the data-protection implications
A cyber incident may involve the unauthorised access, disclosure, alteration, loss or unavailability of personal information. The data-protection lead should begin a structured assessment without waiting for every technical detail.
The initial assessment should consider:
- which information may be affected;
- the sensitivity of the data;
- the number of people involved;
- whether information was encrypted;
- whether records may have been altered;
- the potential effect on individuals;
- whether care or safeguarding has been disrupted;
- whether containment has been achieved;
- whether regulatory reporting may be required; and
- whether affected people may need to be informed.
The assessment should be updated as evidence develops. Decisions and rationale should be recorded throughout.
Notify senior leadership
Senior leadership should be informed early where the incident affects multiple services, critical systems, sensitive information or care continuity.
The initial briefing should cover:
- what is currently known;
- when the issue began;
- which systems and services are affected;
- current care and safeguarding impact;
- containment actions;
- continuity arrangements;
- commissioner or regulatory implications;
- specialist support engaged;
- key decisions required; and
- the next planned update.
Leaders should receive regular concise updates rather than incomplete streams of technical information.
Notify commissioners where service risk exists
Commissioners generally expect early notification where care delivery, safeguarding, system access or contractual performance is materially affected. Providers should not wait for complete technical certainty before reporting significant operational risk.
An initial commissioner update should explain:
- the nature of the suspected incident;
- the time it was identified;
- services and people potentially affected;
- the current impact on care;
- continuity measures activated;
- known safeguarding or data concerns;
- technical and supplier involvement;
- support or coordination required; and
- when the next update will be provided.
Communication should remain factual and avoid speculation about cause, scale or recovery times.
Communicate clearly with staff
Staff need one reliable source of instructions. Conflicting messages can lead to unsafe workarounds, unnecessary alarm or accidental compromise.
Staff updates should explain:
- which systems must not be used;
- which alternative processes are active;
- where essential information is available;
- how care and medication should be recorded;
- how concerns should be escalated;
- which communication channels are approved;
- what staff must not do;
- how frequently updates will be issued; and
- where urgent support is available.
Instructions should be accessible to night, community, agency and temporary staff as well as office-based teams.
Communicate with people and families proportionately
Where care delivery or personal information may be affected, people receiving services and families may require timely, accessible information.
Communication should focus on:
- the known impact on their support;
- what the provider is doing to maintain safety;
- any temporary changes to normal arrangements;
- who they should contact with concerns;
- whether any immediate action is required from them; and
- when further information will be available.
Providers should avoid unnecessary technical language and should adapt communication for people with different accessibility and communication needs.
Operational example 3: mobile care-application outage
Context: A homecare provider loses access to mobile care applications across all field teams following a cyber incident.
Step 1: Paper run sheets and critical-information summaries are issued through the approved contingency process.
Step 2: Office staff increase telephone monitoring to confirm attendance, medication visits and emerging concerns.
Step 3: Care workers record delivery and significant events on controlled temporary documents.
Step 4: A daily incident huddle reviews missed visits, staffing, safeguarding, commissioner communication and restoration progress.
Step 5: Once systems return, temporary records are reconciled before normal mobile reporting resumes.
This maintains operational visibility and commissioner assurance throughout an extended outage.
Control unapproved workarounds
Staff may attempt to maintain services by using personal email, informal messaging, screenshots or locally saved files. These actions may feel practical but can increase confidentiality and record-integrity risks.
Incident leaders should clearly identify:
- which alternative tools are authorised;
- which systems and applications must not be used;
- how temporary information will be secured;
- who may approve exceptional arrangements;
- how exceptions will be documented;
- how information will later be reconciled; and
- when temporary processes will end.
Where no safe alternative exists, leaders should escalate the risk rather than allow uncontrolled local practice.
Consider temporary capacity restrictions
Where the provider cannot reliably access essential information or maintain adequate oversight, it may be necessary to restrict admissions, new packages or non-essential activity temporarily.
Decisions should consider:
- the availability of current care information;
- medication and safeguarding risk;
- staffing capacity;
- the reliability of manual processes;
- the expected duration of disruption;
- management oversight;
- commissioner involvement;
- the needs of people awaiting support; and
- the potential consequences of continuing normal capacity.
Restrictions should be proportionate, documented and reviewed regularly rather than imposed indefinitely.
Protect staff wellbeing and decision quality
Cyber incidents create significant pressure. Managers may work extended hours while coordinating technical, care, regulatory and communication demands.
Leadership should consider:
- relief and deputy arrangements;
- clear shift handovers;
- rest breaks;
- administrative support;
- access to specialist advice;
- decision escalation where uncertainty remains;
- support for staff affected by mistakes or account compromise; and
- avoiding dependency on one individual.
Fatigue can increase errors and weaken judgement. Effective incident governance includes sustainable staffing for the response itself.
Begin planning for safe recovery
Recovery planning should begin during the first day, but systems should not be restored before the threat is contained and data integrity can be checked.
Early recovery planning should consider:
- which systems require priority restoration;
- whether backups are clean and accessible;
- which credentials must be reset;
- whether devices require rebuilding;
- how restored data will be validated;
- how integrations will be tested;
- how temporary records will be transferred;
- who will authorise return to normal operations;
- how staff will be notified; and
- what enhanced monitoring will continue.
Medication, safeguarding, current care plans and workforce deployment will usually require priority over historical or administrative information.
Do not rush restoration
Pressure to restore normal systems can be intense, but premature restoration may reintroduce malware, overwrite evidence or expose inaccurate records.
Before approving restoration, leaders should seek assurance that:
- the affected environment has been contained;
- the likely compromise route has been addressed;
- backups have been checked;
- restored systems have been tested;
- user access is appropriate;
- critical data is accurate;
- connected platforms are functioning safely;
- temporary records can be reconciled; and
- continued monitoring is in place.
Where uncertainty remains, controlled partial restoration may be safer than organisation-wide reopening.
Prepare for record reconciliation
Care, medication and incident information recorded during downtime must eventually be transferred into the main systems. Providers should plan this before the volume of temporary records becomes unmanageable.
Reconciliation should cover:
- care delivered;
- medication administered;
- missed or delayed visits;
- incidents and accidents;
- safeguarding concerns;
- changes in health or risk;
- professional advice received;
- staffing changes;
- family and commissioner communication; and
- decisions made during disruption.
Named staff should be responsible for entry, checking and confirmation that no information has been omitted or duplicated.
Review insurance, contractual and legal obligations
During the first day, providers should identify whether the incident triggers notification or evidence-preservation requirements under insurance, supplier contracts or commissioned service agreements.
This may involve:
- cyber-insurance notification;
- IT supplier escalation;
- commissioner reporting;
- data-protection assessment;
- regulatory reporting;
- safeguarding notification;
- preservation of system logs;
- legal advice; and
- documentation of expenditure and operational impact.
Relevant requirements should be available within the incident plan rather than located for the first time during the event.
Commissioner and inspector expectations
Commissioners and inspectors may later examine whether the response was prompt, proportionate and focused on people’s safety.
Providers should be able to demonstrate:
- early declaration and escalation;
- clear incident leadership;
- effective technical containment;
- safe-mode care processes;
- medication and safeguarding continuity;
- current contingency information;
- timely commissioner communication;
- documented decision-making;
- appropriate data and regulatory assessment;
- controlled restoration planning; and
- learning translated into improvement.
The strongest assurance will come from contemporaneous evidence created during the incident rather than explanations reconstructed later.
What should be achieved by the end of day one?
By the end of the first 24 hours, the provider should aim to have:
- declared and categorised the incident;
- appointed an incident lead and deputy;
- implemented proportionate containment;
- activated safe-mode delivery;
- prioritised higher-risk people and services;
- protected medication and safeguarding processes;
- established a time-stamped decision log;
- notified senior leadership;
- engaged technical and specialist support;
- assessed commissioner and regulatory reporting;
- issued clear staff communications;
- planned the next operational period; and
- created an initial recovery strategy.
Not every technical question will be resolved. The objective is to stabilise the position and ensure that the organisation enters day two with clear control, priorities and accountability.
Preparing priorities for day two
Day-two planning should identify the next decisions and resources required.
Priorities may include:
- continued containment and investigation;
- expanded data and safeguarding assessment;
- testing of clean backups;
- restoration sequencing;
- continued service-level risk monitoring;
- additional staffing or management support;
- updated commissioner communication;
- communication with affected individuals;
- supplier and insurance action;
- record-reconciliation planning; and
- preparation for a structured learning review.
Each action should have a named owner, deadline and escalation route.
Learning from the first 24 hours
Once the immediate position is stable, the provider should preserve learning about how effectively the first-day response operated.
Early review questions include:
- Was the incident recognised quickly?
- Did staff know how to report it?
- Was authority to declare the incident clear?
- Did containment decisions consider care impact?
- Were essential records available?
- Did medication and safeguarding processes work?
- Were commissioners notified appropriately?
- Was the decision log complete?
- Did suppliers respond effectively?
- What unsafe workarounds emerged?
- What immediate improvement is required?
These findings should later inform a fuller post-incident review, but urgent weaknesses should be addressed immediately rather than waiting for formal closure.
Common first-day mistakes
A common mistake is allowing the technical investigation to dominate while care continuity receives insufficient attention.
Other weaknesses include:
- waiting too long to declare an incident;
- unclear command arrangements;
- failing to appoint a deputy;
- staff receiving conflicting instructions;
- using outdated contingency records;
- allowing unapproved communication tools;
- failing to prioritise medication and safeguarding;
- poor decision logging;
- delayed commissioner notification;
- making speculative external statements;
- restoring systems before they are safe;
- failing to plan record reconciliation;
- overworking a small number of leaders; and
- failing to prepare clear priorities for the next day.
Providers should use exercises and previous incidents to identify these weaknesses before a real event occurs.
Building a reliable first-24-hour response
Strong providers prepare for cyber incidents through clear plans, current information, trained staff and realistic exercises. Their first-day response brings together technical containment, operational continuity, safeguarding, communication and governance.
A reliable framework includes:
- clear declaration thresholds;
- named incident leadership;
- rapid containment arrangements;
- safe-mode service procedures;
- critical care and medication information;
- safeguarding continuity;
- time-stamped decision logging;
- commissioner and regulatory escalation;
- controlled communications;
- specialist technical support;
- safe recovery planning; and
- structured learning.
A strong first 24-hour response does not require every question to be answered immediately. It requires disciplined action, clear accountability and a sustained focus on protecting people while the organisation stabilises.
Providers that can contain disruption, maintain essential care and evidence proportionate decision-making will be better positioned to reassure commissioners, support regulatory confidence and recover from cyber incidents without losing control of service quality.
Latest from the knowledge hub
- Digital Rights and Restriction Monitoring in Learning Disability Services: Evidencing Proportionate, Least-Restrictive Support
- Digital Self-Advocacy and Voice Monitoring in Learning Disability Services: Turning Communication into Real Influence
- Digital Choice and Decision-Making Support in Learning Disability Services: Evidencing Understanding, Control and Informed Decisions
- Digital Daily Routine Monitoring in Learning Disability Services: Strengthening Planning, Choice and Everyday Independence