Been breached? Here's what to do right now.
Take a breath. Most incidents can be contained and cleaned up. These five steps protect you while we work out what happened.
Disconnect or lock it down
Unplug affected computers from the network or turn off their Wi-Fi, but leave them switched on if you can: what is in memory can show what happened. For accounts such as email or your website admin, lock or suspend them.
Don't delete anything
Don't wipe, reinstall or tidy up yet. Logs, emails and strange files are the evidence of how they got in and what they touched.
Change passwords from a clean device
Use a phone or computer you trust that hasn't been affected. Start with email, then admin and banking accounts. Turn on two-step login (a code from your phone as well as a password) wherever you can.
Write down what you've seen, and when
What you noticed, what time, and anything you've done since. Screenshots help. Times matter more than you would think.
Call me
Call or WhatsApp me on 07736 637990. If you have cyber insurance, call their helpline too: some policies need you to tell them first.
Get help
- Phone
- 07736 637990
- 07736 637990
- Hours
- Monday to Friday, 9am to 5:30pm
- Cost
- Charged by the hour, with a minimum of one hour. I'll tell you the rate when you call.
Out of hours, call or text any time. I answer when I can, but I can't promise. If I can't help quickly, I'll tell you, so you can find someone who can.
What I do
- Contain it. Stop it getting worse, without destroying the evidence.
- Investigate. Go through the logs to find out how they got in, when, and what they touched.
- Clean up. Remove what they left behind, close the way in, and get you running again.
- Change the keys. Replace every password, API key and login token they might have seen (the credentials that let people and software into your systems).
- Write it up. A plain-English account of what happened, what was affected and what has been fixed.
- Help you tell people. What to say to your clients and, if needed, to the ICO.
Do I need to tell the ICO?
If personal data was involved (names, email addresses, phone numbers, anything that identifies a person), UK GDPR says you must report the breach to the ICO (the Information Commission's Office, the UK's data protection regulator) within 72 hours of finding out about it. The only exception is when it is unlikely to put anyone at risk.
The 72 hours includes weekends. You don't need every answer before you report: you can tell the ICO what you know and add more later. If the breach is likely to put people at high risk, you need to tell them too, without delay.
I'll help you decide whether to report and what to say. The ICO has guidance and an online form.
Reporting the crime
In England, Wales and Northern Ireland, report cyber crime to Report Fraud (it used to be called Action Fraud), online or on 0300 123 2040. In Scotland, call Police Scotland on 101. I can help you with what to say.
When I bring in specialists
Some incidents need more than one person: a large ransomware attack, a case likely to end up in court, or one where evidence has to be preserved to a legal standard. I'll tell you as soon as I see that, and point you to an incident response firm assured by the National Cyber Security Centre (NCSC), the UK government's cyber security body.
If there are legal questions, such as contracts, liability or a regulator, I'll recommend you speak to a solicitor. I'm happy to work alongside both.
What it costs
Breach work is charged by the hour or by the day, with a minimum of one hour. I'll tell you the rate when you call, before any work starts. Out-of-hours work is by arrangement, and retainer clients get 10% off.
Call now
The sooner it's contained, the less damage it does. You don't need to know what happened before you call.
Monday to Friday, 9am to 5:30pm