What to Do if Your Business Has Been Hacked
If you're reading this during an active incident, take a breath. Panicked action makes incidents worse. This article walks through the correct response order for a suspected or confirmed cyber incident at a small or mid-sized business: what to do immediately, what to avoid, and who to involve, in what order.
First 15 minutes: contain, don't destroy
- Disconnect affected devices from the network: unplug ethernet, disable Wi-Fi. Do NOT power off.
- Disable affected user accounts in Microsoft 365 and revoke sessions
- Change passwords for compromised accounts from a clean device (not the compromised one)
- Stop outbound wire transfers and payments in progress
- Take screenshots of ransom notes, suspicious emails, and unusual behaviour
First hour: get the right people involved
- Contact your IT provider or incident response team
- Contact your cyber insurance provider, since most policies require notification before you engage third parties
- Alert internal leadership, but limit knowledge to a small circle initially
- Do NOT tell staff or clients until you understand the scope
- Do NOT pay any ransom or respond to attackers without professional guidance
First 24 hours: investigate and stabilize
- Preserve logs from Microsoft 365, firewall, EDR, and email before they age out
- Identify the initial access point (phished credentials? unpatched server? malicious download?)
- Reset passwords for anyone with elevated access, then all users if warranted
- Rebuild affected endpoints from clean images, not just 'clean' the malware
- Restore from backups only after root cause is understood, otherwise you re-infect
Not sure where your security gaps are?
Our free cybersecurity risk assessment scores your posture across MFA, backup, endpoint protection, and email security, then hands you a prioritized fix list.
Talk to a Security SpecialistWhat NOT to do
- Don't power off encrypted machines: you lose forensic evidence
- Don't pay the ransom without legal and insurance guidance
- Don't communicate with attackers directly
- Don't restore backups on top of a compromised environment
- Don't announce publicly before you know what happened and what to say
- Don't skip notifying your insurer: it can void coverage
Disclosure and legal obligations
In Ontario, PIPEDA requires notification to affected individuals and the Privacy Commissioner for breaches involving personal information that create a real risk of significant harm. PHIPA has its own obligations for personal health information. Regulated professionals (legal, medical, dental, financial) have additional requirements. Involve legal counsel: your cyber insurer typically provides breach counsel as part of the policy.
After the fire is out
Every incident is a chance to close the underlying gap. A proper post-incident review identifies what allowed the attack, what stopped it (or didn't), and what to change so it doesn't happen again. That includes reviewing MFA coverage, EDR alerts that were missed, backup design, and staff training.
Frequently asked questions
Do you take on incident response for non-clients?
Yes, when capacity allows. Containment, credential resets, forensic preservation, and coordination with your cyber insurer's breach counsel. We can then hand you a remediation plan or perform it, depending on what you prefer.
How long does incident recovery usually take?
Business-email-compromise: hours to days. Ransomware with immutable backups: days. Ransomware without proper backups: weeks and often permanent data loss.
Should we tell clients right away?
Not before you know what actually happened. Premature communication with incomplete facts causes more damage than a short, planned delay. Legal counsel guides this, and your cyber insurer typically provides it.
Will our cyber insurance cover the response cost?
Modern policies typically cover breach counsel, forensics, notification, and often ransom negotiation, subject to policy limits and provided you had required controls in place.
Joshua Arimoro
Joshua Arimoro is the Principal Consultant at Nickel City Tech Solutions, a managed IT and cybersecurity provider based in Lively, Ontario, serving businesses across Greater Sudbury and Northern Ontario. He works hands-on with Microsoft 365, server and network infrastructure, endpoint management, and backup and recovery for small and mid-sized organisations.
More about our teamNeed incident response now?
Call us directly for suspected active incidents. For everyone else, an incident response plan built in advance is far cheaper than one written under pressure.
Related services, locations, and resources
Related services
- Cybersecurity Services
Endpoint protection, MFA, email filtering, and M365 hardening.
- Managed IT Services
Proactive monitoring, patching, and predictable monthly support.
- Microsoft 365 Support
Exchange, Teams, SharePoint, OneDrive, and licensing.
- Backup & Disaster Recovery
Backup strategy, monitoring, and recovery testing.
Related service areas
Related resources
- Ransomware Preparedness for Small Clinics
Small clinics are attractive ransomware targets precisely because downtime is so costly. A patient schedule…
- Backing Up Primafact Case Files Properly
Case files in Primafact represent years of litigation work that can't be recreated. Here's what a proper ba…
- PCLaw Support for Ontario Law Firms: The IT Side of Running PCLaw
PCLaw handles billing, trust accounting, and time tracking for many Ontario firms. Here's what keeps it run…
- Protecting PCLaw Trust Accounting Data
Trust accounting data inside PCLaw deserves a distinct layer of protection. General infrastructure guidance…
