My Business Has Been Hacked. Now what?
You've just discovered unusual activity — locked files, suspicious emails, a ransom note, unknown logins. The next 4 hours decide how bad this gets. Here's exactly what to do.
We respond to incident triage requests within 60 minutes during UK business hours, and on-call within 4 hours overnight and weekends.
YOU MAY HAVE SEARCHED
Do these 4 things in the next 10 minutes
- 1
Don't power off the affected device. Powering down can destroy evidence (RAM, volatile logs, the ransomware process itself) that your responders need. Disconnect it from the network instead — pull the network cable or disable Wi-Fi.
- 2
If your Microsoft 365 / Entra is involved, block the compromised account from the admin console immediately. Don't reset the password yet — a reset creates evidence storms. Disable the sign-in, then notify your admin that the account is frozen.
- 3
Disconnect any backups from the network. If your backup is reachable from the compromised machine, the attacker can reach it too. Cloud backups in a separate M365 tenant or immutable storage are usually safer.
- 4
Write down what you saw, when, and who told you. The first 30 minutes of information are the most reliable. Timestamps matter to the ICO clock and to your incident response partner.
What we do — the Gridisys incident timeline
From the moment you engage, within fixed-price limits.
Triage (Hours 0-4)
- ▸Confirm the incident is real — characteristics, scope, blast radius.
- ▸Preserve evidence: sign-in logs, mailbox audit logs, file share timestamps, EDR telemetry.
- ▸Identify the entry vector (phishing, exposed admin, third-party app, password spray).
- ▸Contain: disable compromised accounts, isolate hosts, block malicious indicators in Entra / Defender.
- ▸Document the ICO 'awareness' moment — the Article 33 clock often starts here.
Containment & scoping (Hours 4-24)
- ▸Full scoping of what was actually accessed vs simply present.
- ▸Identify categories of data potentially exposed (personal data, financial, IP).
- ▸Hunt for persistence (backdoor accounts, malicious Inbox rules, OAuth grants, scheduled tasks).
- ▸Coordinate with insurer if applicable — preserve coverage by notifying in line with policy.
- ▸Initial risk assessment — does this need ICO notification?
Eradication & recovery (Day 2 to Week 4)
- ▸Remove all persistence — one survived backdoor and you're back here in 8 weeks.
- ▸Restore from known-clean backups or rebuild systems from gold images.
- ▸Reset all credentials — not just the ones we identified as compromised.
- ▸Harden the entry vector (MFA, conditional access, app consent, mailbox rules) so the same route is closed.
Regulatory close-out
- ▸Final ICO submission (the 1-month update is expected after the initial 72-hour notification).
- ▸Incident post-mortem report — lessons learned, control updates, board reporting.
- ▸Breach register entry finalised. Insurer claim documents filed. Optional: client/comms where the breach was high-risk.
What it costs
A focused Gridisys incident triage is fixed-price — risk assessment, scoping, and the ICO decision. Full incident response engagements (containment, eradication, recovery, regulatory close-out) are scoped to your situation. The initial 15-minute triage call is free. Contact us for a tailored quote.
Full pricing breakdownWhat we cover
RELATED INCIDENT RESPONSE GUIDES
Frequently asked questions
Talk to us now
The first 15-minute triage call is free. We'll tell you whether it's a real incident, what's at risk, and what to do next — no obligation, no commitment.