The instinct after discovering a cyber incident is often to panic and try to fix everything simultaneously. A short, ordered sequence produces a better outcome and reduces the chance of missing something important in the confusion.
The first hour
- Change passwords on the affected account and any account sharing the same password
- Enable two-factor authentication if it was not already active
- Disconnect the affected device from the internet if malware is suspected
- Note what you know so far: what happened, when it was noticed, what data may be involved
The first few days
Check whether client or customer data was affected, since this may create a legal obligation to notify them or a regulator, depending on your country and the type of data involved. Contact your bank if payment details may be exposed. Report the incident to the relevant national reporting body where one exists.
Communicating with clients
If client data was affected, tell them directly and plainly rather than waiting to see if it becomes public knowledge. A prompt, honest message with what you know and what you are doing about it tends to preserve trust far better than silence followed by a later admission.
Afterwards
Once the immediate response is done, review how the incident happened and close the specific gap, whether that is a reused password, an outdated plugin, or a lack of two-factor authentication. Consider whether a qualified IT security professional should review your systems if the incident was significant.
Take these three things away
- Change passwords and enable two-factor authentication immediately
- Check whether client data was affected and whether you must notify anyone
- Communicate with affected clients directly rather than waiting
Frequently asked questions
Written for the Hayley Duster editorial project as general information for people running businesses alone. It is not medical, legal, financial or tax advice, and it is not a substitute for guidance from a qualified professional who knows your circumstances.
All articles