Back to all resources
guide

What to Do in an IT Emergency: A First-Hour Checklist for GTA Businesses

October 8, 2026
8 min read
IT Rapid Support Team
What to Do in an IT Emergency: A First-Hour Checklist for GTA Businesses

An IT emergency is any technology failure that stops your business from operating or puts its data or money at immediate risk: a server or network that is down for everyone, email that has stopped flowing, a ransomware infection, a hacked mailbox being used to send payment requests, or a payment that has just gone to a fraudster. The first hour decides how long it lasts. In that hour you need to do four things in order: confirm what is actually broken and how widely, stop it getting worse, get the right person working on it with the access they need, and keep a simple record of what happened.

This guide is a practical checklist for owners and office managers at small and mid-sized businesses. It covers how to tell an emergency from an urgent ticket, what to do in the first fifteen minutes for the most common scenarios, what to have ready before you call anyone, what not to do, and how to prepare a one-page emergency plan so the next one is shorter. It is written by IT Rapid Support, a managed IT provider at 7810 Keele St in Vaughan that takes emergency calls across the GTA, so read it with that in mind; the steps apply whoever you call.

Is It an Emergency or Just Urgent?

Treating every problem as an emergency burns time and goodwill, and treating a real one as a normal ticket can cost days. A simple test works for most businesses:

  • Emergency: a whole office, a whole team or a critical system cannot work, data is being encrypted or deleted, an account is actively being misused, or money is moving that should not be. Act now, including at night or on a weekend.
  • Urgent: one person or one device cannot work, or a system is degraded but still usable. It needs attention today, through your normal help desk.
  • Routine: an annoyance, a request or a question. Log it and let it be scheduled.

If you are unsure, ask two questions: is the problem spreading, and is it costing revenue, safety or data right now? A yes to either is an emergency.

The First 15 Minutes: Checklists by Scenario

Everyone has lost the internet or the network

  • Check whether the problem is your office or your provider. Try a phone on mobile data, and look at the internet provider's outage page or status line.
  • Look at the modem, firewall and main switch. Note which lights are on, off or flashing amber before touching anything, then power-cycle the modem only if your IT provider has told you that is safe.
  • If you have a backup internet connection or a mobile hotspot, move the people who must keep working onto it.
  • Have your internet account number and circuit ID ready, because the provider will ask for them.

A server or a critical application is down

  • Confirm the scope: is it one application, one server, or everything that depends on it?
  • Do not repeatedly restart the server or run disk repair tools. If storage is failing, each restart can make recovery harder.
  • Write down any error message exactly, or take a photo of the screen.
  • Find out when the last successful backup ran. Your IT provider will need to know before deciding between repair and restore.

Email is down or Microsoft 365 is not working

  • Check whether it is you or the service. Microsoft publishes service health in the Microsoft 365 admin center, and a wide outage there means the fix is on its side, not yours.
  • If only your company is affected, check whether your domain or DNS registration has expired, whether a licence has lapsed, and whether an administrator account has been locked or changed.
  • Tell staff how you will communicate in the meantime, such as by phone or a group text, so nobody starts using personal email for business.

Ransomware or a suspected breach

  • Disconnect affected computers from the network: unplug the network cable and turn off Wi-Fi. Do not power them off, because memory and logs can help the investigation.
  • Do not pay anything, reply to the attackers or delete the ransom note.
  • Disconnect or protect backups that are still clean, especially any USB or network drive that stays attached to a server.
  • Call your IT provider, and call your cyber insurer early, because many policies require you to report quickly and to use their approved response firm. Our ransomware protection guide explains how to reduce the chance of this happening at all.

A mailbox has been hacked or a payment has gone to a fraudster

  • Call your bank immediately and ask them to recall or freeze the transfer. Speed matters far more than anything else here.
  • Reset the password for the affected account from a different, clean device, sign out all sessions, and check that multi-factor authentication is still set up to the right phone.
  • Look for inbox rules and forwarding the attacker may have added. These are often used to hide replies from you.
  • Warn the clients or suppliers who may have received fraudulent messages, by phone rather than by replying to the email thread.
  • Report the fraud to the police and to the Canadian Anti-Fraud Centre. Our guide on stopping phishing attacks covers the controls that prevent the next one.

What to Have Ready Before You Call for Help

Whoever you call, the first half-hour often goes on finding access rather than fixing anything. Gather what you can:

  • A short description: what stopped working, when it started, who is affected, and anything that changed recently, such as an update, a power cut, a new device or a suspicious email.
  • Administrator access: the Microsoft 365 or Google Workspace global admin account, the firewall, the backup system, your domain registrar and DNS host, and the server or hypervisor.
  • Account details for your internet provider, phone provider and any line-of-business software vendor.
  • Your cyber insurance policy number and the insurer's incident line, if you have cover.
  • One decision-maker who can approve actions such as shutting systems down, restoring from backup or authorizing out-of-hours work.

If your current IT provider is not answering, another provider can usually still help, but only as fast as you can give them access. That is the strongest argument for keeping admin credentials and documentation in your own name. Our guide to switching IT providers lists what you should hold regardless of who supports you.

What Not to Do

  • Do not let several people try fixes at once. Pick one person to coordinate and keep a log.
  • Do not wipe, reinstall or restore over affected machines before someone has checked whether evidence or unsaved data is needed.
  • Do not reconnect a machine that was infected because it now seems to be working.
  • Do not announce a security incident on social media or by company-wide email from an account that may be compromised.
  • Do not assume the backups are fine. Confirm the date of the last good copy before relying on it.

Who Else May Need to Know

Most outages are internal matters. Security incidents can bring outside obligations, and it is worth knowing them before you need them:

  • Your cyber insurer, usually as early as possible and before you engage your own response firm.
  • Your bank, for any fraudulent payment.
  • The police and the Canadian Anti-Fraud Centre, for fraud and extortion.
  • The Canadian Centre for Cyber Security accepts reports of cyber incidents from Canadian organizations.
  • Under PIPEDA, a breach of security safeguards involving personal information that creates a real risk of significant harm must be reported to the Office of the Privacy Commissioner of Canada and to the affected individuals, and every breach must be recorded. Our PIPEDA compliance checklist covers what that record needs. Regulated professions may have their own reporting duties, so check with your regulator or lawyer.

After the Emergency

Once you are working again, the job is not finished. Ask for a written summary of what failed, what was done, what data or systems were affected, and what should change. Keep the timeline and any logs if an insurer, client or regulator may ask about it. Then fix the cause rather than the symptom: replace the failing hardware, add the missing backup copy, turn on multi-factor authentication where it was missing, or add a second internet connection if a single circuit took the whole office down.

Build a One-Page IT Emergency Plan

The businesses that recover fastest are usually the ones that wrote down the basics in advance. A single page, printed and also stored somewhere you can reach when your own systems are down, is enough for most small offices:

  • Who to call, in order: your IT provider's emergency line, your internet provider, your bank's fraud line and your insurer's incident line.
  • Who in the business can approve emergency work and decisions, with a backup person.
  • Where admin credentials are kept, such as a business password manager with at least two people who can open it.
  • What you would do without email or the network for a day: how staff will communicate, take payments and reach clients.
  • Where backups are, how often they run, and when a restore was last tested. Our disaster recovery plan guide goes further on recovery targets and testing.

Review the page once a year and whenever you change providers, move offices or add a critical system.

How IT Rapid Support Helps in an Emergency

IT Rapid Support answers emergency calls 24/7 for businesses across Vaughan, Toronto and the GTA, including businesses that are not existing clients. A technician starts diagnosing remotely on the call and, when hands-on work is the fastest fix, we dispatch on-site from our office at 7810 Keele St in Vaughan. Emergency work for businesses without an agreement is billed by the hour, and we tell you what we are doing before we do it. The details are on our emergency IT services page, and if you think you are dealing with a security incident right now, start with our cyber incident page.

For an emergency, call (289) 582-9930. To put a plan in place before you need one, contact us.

Frequently Asked Questions

What counts as an IT emergency for a business?

Any technology problem that stops a whole office, team or critical system from working, or that puts data or money at immediate risk. Examples are a network or server outage, email down for everyone, ransomware, a compromised account being used to send messages, or a fraudulent payment. One person with a broken laptop is urgent, not an emergency.

What should I do first if I think we have ransomware?

Disconnect the affected computers from the network by unplugging the cable and turning off Wi-Fi, but leave them powered on. Do not pay or contact the attackers. Protect any backups that are still clean, then call your IT provider and your cyber insurer.

Should I turn off a computer that has a virus?

Usually not. Disconnecting it from the network stops the spread while keeping memory and logs that help work out what happened. Turn it off only if your IT provider tells you to, or if it is visibly damaging data and you cannot disconnect it.

What information should I have ready when I call for emergency IT support?

What stopped working and when, who is affected, anything that changed recently, administrator access for your email, firewall, backups and domain, your internet provider account details, and the name of the person who can approve decisions. The more access you can give, the faster the fix.

Can a different IT company help if my current provider is not answering?

Yes, as long as you can give them access. Having the admin credentials for Microsoft 365 or Google Workspace, the firewall, the backup system and your domain in your own name makes this much faster. If you do not have them, recovering access becomes part of the job.

How is emergency IT support usually billed?

For businesses without a support agreement, emergency work is commonly billed by the hour. Under a managed IT agreement, emergencies are normally covered by the agreement itself. Either way, ask what is and is not included before work starts if time allows.

Share this resource

IT Rapid Support Team

IT Rapid Support Team

Managed IT & Cybersecurity, GTA

IT Rapid Support Team is a security expert with extensive experience in creating security guidelines.

More from this author

Related Resources

All Resources
What Are IT Professional Services? A Guide for GTA Businesses
guide
•
October 7, 2026

What Are IT Professional Services? A Guide for GTA Businesses

IT professional services are project work with an end date: migrations, network builds, server replacements, office moves. How they differ from managed IT and consulting, and what a statement of work should include.

Read more: What Are IT Professional Services? A Guide for GTA Businesses
What Does an IT Security Assessment Include? A Guide for GTA Businesses
guide
•
October 5, 2026

What Does an IT Security Assessment Include? A Guide for GTA Businesses

What an IT security assessment checks (MFA, email, patching, firewall, backups, access, monitoring), what the report should contain, free vs paid, and how to prepare.

Read more: What Does an IT Security Assessment Include? A Guide for GTA Businesses
Vaughan Business Email Security Study 2026: Only 17.9% Enforce DMARC
whitepaper
•
October 4, 2026

Vaughan Business Email Security Study 2026: Only 17.9% Enforce DMARC

Original research: we checked the public SPF and DMARC records of 290 mail-enabled Vaughan business domains on 4 October 2026. Only 17.9% enforce DMARC; 48.6% have no DMARC record at all.

Read more: Vaughan Business Email Security Study 2026: Only 17.9% Enforce DMARC

Need Expert Security Advice?

Our team of cybersecurity experts is ready to help you secure your organization. Schedule a free consultation today.

Get in Touch