Most of us grew up learning basic first aid; how to clean a wound, stop a bleed, what to do while waiting for the ambulance to arrive etc. everyone saw the need to learn first aid because we very well understood that in cases of emergency, it could help manage the situation before expert medical care arrives.
Cybersecurity has its own version of first aid, and just like the physical kind, it is imperative to know what to do in cases of security emergencies, for example, a hacking of your business systems and operations. You need to know what to do in such an emergency before the professionals step in so you do not accidentally make things worse
So, this blog article is your guide on what to do immediately when you discover you have been hacked. Let’s get into it.
First things first, the moment you discover that your business has been hacked, panic is probably going to be your first reaction. You may start wondering what the hackers accessed, whether they stole customer information, whether your files are still safe, or how much this is going to cost your business.
Those are all valid questions, but this is not the time to start looking for all the answers. Your first priority at the moment should be containment.
Think about it this way; if you discovered a pipe had burst in your office, you would definitely not bother with cleaning up the water immediately. You would first concern yourself with stopping the flow first. This same principle applies to a cyberattack; your goal when you identify a hack isn’t to figure out how it happened, it is to prevent the situation from getting worse while preserving the information needed for investigation and recovery, and here’s how to do that.
- Don’t Panic and Don’t Start Clicking Around
This sounds obvious, but it is one of the most important things you need to take note of. When something unusual happens, our natural instinct is to start clicking, but you shouldn’t do that because you might open harmful files in an attempt to “fix” whatever looks wrong.
If you suspect your systems have been compromised, every action you take could potentially affect evidence that security professionals need to investigate and correct the incident.
So, what should you do instead? Stop and take a deep breath. Then proceed to step 2.
- Disconnect the Affected Device: If you know which computer or device has been compromised, disconnect it from the network. This could mean unplugging the network cable or disconnecting it from Wi-Fi, depending on the situation.
The reason you need to disconnect the affected device is to limit the attacker’s ability to move from one compromised device to another. This is particularly important because a cyberattack rarely stays neatly contained to one computer. If an attacker gains access to one employee’s device or account, they may attempt to use that access to reach other systems, accounts, or sensitive information.
However, disconnecting the device from wifi is not the same as shutting it down. DO NOT shut down the device until your cybersecurity professional tells you to. A powered-on device may contain valuable information about what happened, and turning it off can cause some of that information to disappear from memory.
- Call Your IT or Cybersecurity Team Immediately: Now, this is not the moment to Google, “How to remove a hacker from my computer” and start experimenting with solutions. Reach out to your cybersecurity professional alerting them on what’s happened to you. If you have no cybersecurity professional, reach out to us so we can assist you with setting up a professional account immediately. You can contact us via info@stonepointtech.com or call us at (727) 478-7355. The sooner a professional can assess the situation, the better your chances of containing the damage.
The cybersecurity team will let you know the steps to take to protect and recover your systems. Listen to them and cooperate with them so the process is easier and faster.
- Document as much as you see and remember: Take note of what happened and when you first noticed it. Take photos and screenshots of suspicious messages, ransom notes or unusual activity displayed on the screen. Write down the time you noticed the problem, keep all suspicious emails and messages, record which devices and accounts appear to be affected. Other things to take note of include:
- Did employees suddenly lose access to their files?
- Did someone receive a password-reset notification they did not request?
- Did you notice unusual transactions?
- Did a computer display a ransom message?
- Did someone receive an email that appeared to come from your company but was actually sent by an attacker?
Document what you see without interacting unnecessarily with the suspicious system.
- Don’t Communicate With the Attacker on Your Own: If you receive a ransom demand or a message from someone claiming to have hacked your business, don’t respond, and that includes not threatening them, clicking any link or negotiating with them. Do not send them any additional information, credentials, personal information, payment details etc. do not give them anything! Payment is never the right first move because payment does not guarantee your files will be returned, or that the attacker will not return.
Engaging can reveal information that makes your position worse, so keep the message and share it with your cybersecurity and legal teams; it may come in handy in cases of regulatory, insurance and legal obligations.
- Notify the Right People: This is the step most business owners delay because it is uncomfortable, however several regions have enacted legislation requiring notification of security breaches involving personal information. Depending on your industry, there may be specific timeframes within which certain parties must be notified. In healthcare, for example, HIPAA has clear breach notification requirements. Waiting too long to notify the right people can add regulatory consequences on top of everything else you are already dealing with. Beyond legal requirements, your legal advisor, your insurance provider, and potentially your bank may all need to know what has happened and when. Notify law enforcement, call your local police department and report the situation and the potential risk for identity theft. The sooner law enforcement learns about the theft, the more effective they can be.
As for your clients, if their data was involved, they deserve to know. Handled with care and transparency, that conversation can actually reinforce trust rather than destroy it. What damages trust most is finding out later that something happened and nobody told them.
All of these points mentioned above are things that can help you contain a cyber attack within the first 60 minutes of you noticing it, and on that basis, it is advisable for every business to have a basic incident response plan that answers questions like:
- Who do we call first?
- Who has authority to make decisions?
- Where are our backups?
- Who is our IT or cybersecurity provider?
- Who is our cyber insurance carrier?
- How do we contact them if our email systems are compromised?
- What systems are considered critical to our business?
Because when a crisis happens, you don’t want your team standing around asking these questions for the first time; you want them to know exactly what to do. So prepare yourself and your team now so that if an emergency happens, everyone is equipped with the knowledge to contain it in the first 60 minutes.
At StonePoint Technology Partners, we help small and mid-sized businesses prepare for the unexpected, respond to incidents quickly, and build the kind of security foundation that makes those incidents far less likely in the first place. So, whether you want to run through your current incident response readiness, strengthen your backup strategy, or simply know that there is a qualified team on standby when you need them, we are here for that conversation. Send us an email at Info@stonepointtech.com or call us at (727) 478-7355. We are here to help!
