All Resources
Cybersecurity

What to Do if Your Business Has Been Hacked

If you're reading this during an active incident, take a breath. Panicked action makes incidents worse. This article walks through the correct response order for a suspected or confirmed cyber incident at a small or mid-sized business — what to do immediately, what to avoid, and who to involve, in what order.

July 10, 2026 9 min read Greater Sudbury & Ontario

First 15 minutes: contain, don't destroy

  • Disconnect affected devices from the network — unplug ethernet, disable Wi-Fi. Do NOT power off.
  • Disable affected user accounts in Microsoft 365 and revoke sessions
  • Change passwords for compromised accounts from a clean device (not the compromised one)
  • Stop outbound wire transfers and payments in progress
  • Take screenshots of ransom notes, suspicious emails, and unusual behaviour

First hour: get the right people involved

  • Contact your IT provider or incident response team
  • Contact your cyber insurance provider — most policies require notification before you engage third parties
  • Alert internal leadership, but limit knowledge to a small circle initially
  • Do NOT tell staff or clients until you understand the scope
  • Do NOT pay any ransom or respond to attackers without professional guidance

First 24 hours: investigate and stabilize

  • Preserve logs from Microsoft 365, firewall, EDR, and email — before they age out
  • Identify the initial access point (phished credentials? unpatched server? malicious download?)
  • Reset passwords for anyone with elevated access, then all users if warranted
  • Rebuild affected endpoints from clean images, not just 'clean' the malware
  • Restore from backups only after root cause is understood — otherwise you re-infect

What NOT to do

  • Don't power off encrypted machines — you lose forensic evidence
  • Don't pay the ransom without legal and insurance guidance
  • Don't communicate with attackers directly
  • Don't restore backups on top of a compromised environment
  • Don't announce publicly before you know what happened and what to say
  • Don't skip notifying your insurer — it can void coverage

Disclosure and legal obligations

In Ontario, PIPEDA requires notification to affected individuals and the Privacy Commissioner for breaches involving personal information that create a real risk of significant harm. PHIPA has its own obligations for personal health information. Regulated professionals (legal, medical, dental, financial) have additional requirements. Involve legal counsel — your cyber insurer typically provides breach counsel as part of the policy.

After the fire is out

Every incident is a chance to close the underlying gap. A proper post-incident review identifies what allowed the attack, what stopped it (or didn't), and what to change so it doesn't happen again. That includes reviewing MFA coverage, EDR alerts that were missed, backup design, and staff training.

Frequently asked questions

Do you take on incident response for non-clients?

Yes, when capacity allows. Containment, credential resets, forensic preservation, and coordination with your cyber insurer's breach counsel. We can then hand you a remediation plan or perform it, depending on what you prefer.

How long does incident recovery usually take?

Business-email-compromise: hours to days. Ransomware with immutable backups: days. Ransomware without proper backups: weeks and often permanent data loss.

Should we tell clients right away?

Not before you know what actually happened. Premature communication with incomplete facts causes more damage than a short, planned delay. Legal counsel guides this — your cyber insurer typically provides it.

Will our cyber insurance cover the response cost?

Modern policies typically cover breach counsel, forensics, notification, and often ransom negotiation — subject to policy limits and provided you had required controls in place.

Need incident response now?

Call us directly for suspected active incidents. For everyone else, an incident response plan built in advance is far cheaper than one written under pressure.

Keep exploring

Related services, locations, and resources

Related services

Related resources