What to Do if Your Business Has Been Hacked
If you're reading this during an active incident, take a breath. Panicked action makes incidents worse. This article walks through the correct response order for a suspected or confirmed cyber incident at a small or mid-sized business — what to do immediately, what to avoid, and who to involve, in what order.
First 15 minutes: contain, don't destroy
- Disconnect affected devices from the network — unplug ethernet, disable Wi-Fi. Do NOT power off.
- Disable affected user accounts in Microsoft 365 and revoke sessions
- Change passwords for compromised accounts from a clean device (not the compromised one)
- Stop outbound wire transfers and payments in progress
- Take screenshots of ransom notes, suspicious emails, and unusual behaviour
First hour: get the right people involved
- Contact your IT provider or incident response team
- Contact your cyber insurance provider — most policies require notification before you engage third parties
- Alert internal leadership, but limit knowledge to a small circle initially
- Do NOT tell staff or clients until you understand the scope
- Do NOT pay any ransom or respond to attackers without professional guidance
First 24 hours: investigate and stabilize
- Preserve logs from Microsoft 365, firewall, EDR, and email — before they age out
- Identify the initial access point (phished credentials? unpatched server? malicious download?)
- Reset passwords for anyone with elevated access, then all users if warranted
- Rebuild affected endpoints from clean images, not just 'clean' the malware
- Restore from backups only after root cause is understood — otherwise you re-infect
What NOT to do
- Don't power off encrypted machines — you lose forensic evidence
- Don't pay the ransom without legal and insurance guidance
- Don't communicate with attackers directly
- Don't restore backups on top of a compromised environment
- Don't announce publicly before you know what happened and what to say
- Don't skip notifying your insurer — it can void coverage
Disclosure and legal obligations
In Ontario, PIPEDA requires notification to affected individuals and the Privacy Commissioner for breaches involving personal information that create a real risk of significant harm. PHIPA has its own obligations for personal health information. Regulated professionals (legal, medical, dental, financial) have additional requirements. Involve legal counsel — your cyber insurer typically provides breach counsel as part of the policy.
After the fire is out
Every incident is a chance to close the underlying gap. A proper post-incident review identifies what allowed the attack, what stopped it (or didn't), and what to change so it doesn't happen again. That includes reviewing MFA coverage, EDR alerts that were missed, backup design, and staff training.
Frequently asked questions
Do you take on incident response for non-clients?
Yes, when capacity allows. Containment, credential resets, forensic preservation, and coordination with your cyber insurer's breach counsel. We can then hand you a remediation plan or perform it, depending on what you prefer.
How long does incident recovery usually take?
Business-email-compromise: hours to days. Ransomware with immutable backups: days. Ransomware without proper backups: weeks and often permanent data loss.
Should we tell clients right away?
Not before you know what actually happened. Premature communication with incomplete facts causes more damage than a short, planned delay. Legal counsel guides this — your cyber insurer typically provides it.
Will our cyber insurance cover the response cost?
Modern policies typically cover breach counsel, forensics, notification, and often ransom negotiation — subject to policy limits and provided you had required controls in place.
Need incident response now?
Call us directly for suspected active incidents. For everyone else, an incident response plan built in advance is far cheaper than one written under pressure.
Related services, locations, and resources
Related services
- Cybersecurity Services
Endpoint protection, MFA, email filtering, and M365 hardening.
- Managed IT Services
Proactive monitoring, patching, and predictable monthly support.
- Microsoft 365 Support
Exchange, Teams, SharePoint, OneDrive, and licensing.
- Backup & Disaster Recovery
Backup strategy, monitoring, and recovery testing.
Related service areas
Related resources
- How to Protect Your Business from Ransomware
Ransomware isn't a Fortune-500 problem. Here's how small and mid-sized businesses in Greater Sudbury and No…
- The Most Common Cybersecurity Threats Facing Small Businesses
Forget nation-state hackers. Here are the threats actually hitting Northern Ontario SMBs today — and the pr…
- Why Every Business Needs Multi-Factor Authentication
If you do only one security thing this year, do this. MFA blocks the vast majority of account-takeover atta…
- Business Antivirus vs Consumer Antivirus: What's the Difference?
Consumer antivirus was designed for one person and one PC. Business endpoint protection is a different prod…
