ACTIVE INCIDENT RIGHT NOW? Gridisys 24/7 emergency triage — £0 first 15 minutes.
24/7 EMERGENCY INCIDENT RESPONSE · UK

My Business Has Been Hacked. Now what?

You've just discovered unusual activity — locked files, suspicious emails, a ransom note, unknown logins. The next 4 hours decide how bad this gets. Here's exactly what to do.

We respond to incident triage requests within 60 minutes during UK business hours, and on-call within 4 hours overnight and weekends.

YOU MAY HAVE SEARCHED

"my business has been hacked what do I do""my Outlook account has been hacked business""I think my company got breached""this looks like ransomware""my files have been encrypted""someone has logged in as me from another country""is my M365 compromised"

Do these 4 things in the next 10 minutes

  1. 1

    Don't power off the affected device. Powering down can destroy evidence (RAM, volatile logs, the ransomware process itself) that your responders need. Disconnect it from the network instead — pull the network cable or disable Wi-Fi.

  2. 2

    If your Microsoft 365 / Entra is involved, block the compromised account from the admin console immediately. Don't reset the password yet — a reset creates evidence storms. Disable the sign-in, then notify your admin that the account is frozen.

  3. 3

    Disconnect any backups from the network. If your backup is reachable from the compromised machine, the attacker can reach it too. Cloud backups in a separate M365 tenant or immutable storage are usually safer.

  4. 4

    Write down what you saw, when, and who told you. The first 30 minutes of information are the most reliable. Timestamps matter to the ICO clock and to your incident response partner.

UK SMBs are hit with hundreds of cyber attacks every day. Most don't make the news. Most are survivable. What kills firms isn't the breach — it's the silence, the guessing, and the lost hours.

What we do — the Gridisys incident timeline

From the moment you engage, within fixed-price limits.

First 4 hours

Triage (Hours 0-4)

  • Confirm the incident is real — characteristics, scope, blast radius.
  • Preserve evidence: sign-in logs, mailbox audit logs, file share timestamps, EDR telemetry.
  • Identify the entry vector (phishing, exposed admin, third-party app, password spray).
  • Contain: disable compromised accounts, isolate hosts, block malicious indicators in Entra / Defender.
  • Document the ICO 'awareness' moment — the Article 33 clock often starts here.
Day 1

Containment & scoping (Hours 4-24)

  • Full scoping of what was actually accessed vs simply present.
  • Identify categories of data potentially exposed (personal data, financial, IP).
  • Hunt for persistence (backdoor accounts, malicious Inbox rules, OAuth grants, scheduled tasks).
  • Coordinate with insurer if applicable — preserve coverage by notifying in line with policy.
  • Initial risk assessment — does this need ICO notification?
Days to weeks

Eradication & recovery (Day 2 to Week 4)

  • Remove all persistence — one survived backdoor and you're back here in 8 weeks.
  • Restore from known-clean backups or rebuild systems from gold images.
  • Reset all credentials — not just the ones we identified as compromised.
  • Harden the entry vector (MFA, conditional access, app consent, mailbox rules) so the same route is closed.
Weeks 2-6

Regulatory close-out

  • Final ICO submission (the 1-month update is expected after the initial 72-hour notification).
  • Incident post-mortem report — lessons learned, control updates, board reporting.
  • Breach register entry finalised. Insurer claim documents filed. Optional: client/comms where the breach was high-risk.

What it costs

A focused Gridisys incident triage is fixed-price — risk assessment, scoping, and the ICO decision. Full incident response engagements (containment, eradication, recovery, regulatory close-out) are scoped to your situation. The initial 15-minute triage call is free. Contact us for a tailored quote.

Full pricing breakdown

What we cover

Microsoft 365 / Entra ID compromise — mailbox takeover, malicious Inbox rules, OAuth grants
Windows endpoint ransomware — LockBit, Cl0p, Akira, Black Basta, Rhysida variants
Business email compromise (BEC) — supplier bank detail changes, director impersonation
Google Workspace compromise — Gmail, Workspace admin, OAuth app abuse
Azure / cloud account compromise — privileged role abuse, storage tampering
Supply-chain compromise — a vendor of yours has been breached and the attacker is now in your network
ICO / GDPR notification decision and drafting — within the 72-hour Article 33 window
Cyber-insurer coordination — early notification to preserve coverage, panel-vendor coordination

Frequently asked questions

Talk to us now

The first 15-minute triage call is free. We'll tell you whether it's a real incident, what's at risk, and what to do next — no obligation, no commitment.

Gridisys

AI-powered cybersecurity and app development. Protecting and building for businesses worldwide.

© 2026 Gridisys. All rights reserved.Gridisys Ltd — Company No. 15780405 — Registered in England & WalesRegistered Office: 128 City Road, London, United Kingdom, EC1V 2NX

We use cookies to improve your experience and analyse site traffic. By clicking "Accept", you consent to our use of cookies. Learn more.