What To Do When You’Ve Been Hacked: A Step-by-Step Guide
Realizing your business has fallen victim to a cyberattack is a stressful experience. The sudden loss of control, the fear of compromised data, and the potential disruption to your daily operations can cause immediate panic. However, panic is the enemy of a swift and effective response. If you are currently dealing with a breach, the most important thing you can do is stay calm and act systematically.
Since 1980, CTS Companies has helped businesses figure out which technology they need to solve business problems in a simple and reliable way. We understand that security runs through nearly every decision an IT manager makes. When a breach occurs, you need a straightforward plan to stop the damage, assess the situation, and restore your operations. Here is a clear, actionable guide on exactly what to do when you’ve been hacked.
Step 1: Isolate Your IT Infrastructure
Disconnect from the Network Immediately
The very first action you must take is containment. Once a hacker gains access to one device, they will actively try to move to other computers and servers within your network. To stop this spread, you need to isolate the compromised hardware. Disconnect the affected computers from the internet by unplugging their ethernet cables and turning off their Wi-Fi connections.
Protect the Rest of Your Hardware
Do not simply power down the machines completely unless instructed to do so by a security professional. Turning off a computer can erase temporary memory that might hold valuable clues about how the attackers got in. By disconnecting the device from the network instead of shutting it down, you protect your broader IT infrastructure while preserving evidence. Once the compromised machines are isolated, you can safely evaluate the rest of your network to ensure the threat has not spread.
Step 2: Secure Your Accounts and Update Passwords
Change Credentials on a Clean Device
Hackers often gain entry by stealing usernames and passwords. If they are in your system, you must assume all your current passwords are compromised. Find a separate, clean device that is not connected to your business network—like a personal smartphone on a cellular connection—and immediately change the passwords for your critical business accounts. This includes email accounts, financial portals, and administrative access panels.
Implement Strict Password Policies
At CTS Companies, we look at security through the lens of six distinct categories, and password policies & procedures is one of the most critical. Moving forward, you must enforce a company-wide rule that requires complex, unique passwords for every account. Furthermore, mandate multi-factor authentication (MFA) across your entire organization. MFA requires a secondary piece of evidence, like a text message code or authenticator app prompt, making it incredibly difficult for hackers to log in even if they manage to steal a password.
Step 3: Assess the Damage and Strengthen Cybersecurity
Identify the Source of the Hack
You cannot fix a problem if you do not know how it started. Work with your technical team to trace the origin of the attack. Did an employee accidentally click a malicious link in a phishing email? Was there a vulnerability in your remote access setup? Understanding the entry point dictates your next steps and helps you close the door the hackers used to get in.
Review Security Logs and Protocols
A thorough assessment involves checking your antimalware logs and reviewing your web filtering settings. These are key components of proper cybersecurity. By examining these logs, you can see exactly what files were accessed, modified, or stolen. If you discover that critical files are locked and the attackers are demanding payment, you will need to implement your ransomware protection strategies. Never pay a ransom without first consulting with legal and technical professionals, as paying does not guarantee you will get your data back.
Step 4: Execute Data Backup and Recovery
The Importance of Clean Data Restores
If a hack results in corrupted, deleted, or encrypted files, your best path forward is to wipe the infected machines clean and restore your files from a safe backup. This is why having a reliable data backup and recovery plan is a non-negotiable part of running a modern business. You need to verify that your backup files are clean and were created before the infection occurred.
Rely on Proven Backup Solutions
Whether you decide to implement on-site backups, off-site storage, or a mix of both, having a redundant system ensures you can survive a disaster. CTS has specialized in data backup and business continuity since the late 90s, including operating data centers on the east and west sides of Michigan. By keeping your backup strategy simple and reliable, you ensure that your business can bounce back from an attack with minimal downtime.
Step 5: Communicate with Your Team and Customers
Inform Internal Staff
Transparency is required during a security incident. Inform your employees about the breach as soon as possible. Tell them exactly what happened and provide clear instructions on what they need to do. They may need to watch out for suspicious emails, change their own passwords, or temporarily stop using certain software applications while you clean the system.
Notify External Parties and Authorities
Depending on your industry and the type of data that was exposed, you may have legal obligations to report the breach. If customer data, credit card information, or personal health records were compromised, you must notify the affected individuals and the relevant regulatory authorities. Handling this communication honestly and promptly helps maintain the trust you have built with your clients over the years.
Step 6: Partner with a Trusted IT Service Provider
Evaluate Your Long-Term Technology Strategy
Recovering from a hack is only half the battle; preventing the next one is just as important. Security requires constant attention, and managing it alone can overwhelm a business. Partnering with a dedicated IT service provider allows you to hand off the heavy lifting to experts. We view security comprehensively, encompassing physical security, remote access, antimalware, and other vital policies & procedures to keep your business safe.
Utilize Professional Support Systems
While some companies force you into one type of partnership, we deliver across a spectrum from one-off projects to a full IT department. If you simply need more reactive support or prefer a set amount of hours, our help desk solutions offer a mix of options, including full on-site members and bulk rates. Choose the option that best suits your business. We also apply this same reliable approach to your communication needs, offering secure Managed Voice solutions and traditional PBX systems for businesses looking to purchase an on-premise voice system up front without a monthly cost.
Experiencing a hack is a difficult challenge, but following these practical steps will help you regain control. By isolating the threat, securing your accounts, utilizing strong backups, and partnering with experienced professionals, you can navigate the crisis and build a more resilient business for the future.