Been breached? Here's what to do right now.

Take a breath. Most incidents can be contained and cleaned up. These five steps protect you while we work out what happened.

  1. Disconnect or lock it down

    Unplug affected computers from the network or turn off their Wi-Fi, but leave them switched on if you can: what is in memory can show what happened. For accounts such as email or your website admin, lock or suspend them.

  2. Don't delete anything

    Don't wipe, reinstall or tidy up yet. Logs, emails and strange files are the evidence of how they got in and what they touched.

  3. Change passwords from a clean device

    Use a phone or computer you trust that hasn't been affected. Start with email, then admin and banking accounts. Turn on two-step login (a code from your phone as well as a password) wherever you can.

  4. Write down what you've seen, and when

    What you noticed, what time, and anything you've done since. Screenshots help. Times matter more than you would think.

  5. Call me

    Call or WhatsApp me on 07736 637990. If you have cyber insurance, call their helpline too: some policies need you to tell them first.

Get help

WhatsApp
07736 637990
Hours
Monday to Friday, 9am to 5:30pm
Cost
Charged by the hour, with a minimum of one hour. I'll tell you the rate when you call.

Out of hours, call or text any time. I answer when I can, but I can't promise. If I can't help quickly, I'll tell you, so you can find someone who can.

What I do

Do I need to tell the ICO?

If personal data was involved (names, email addresses, phone numbers, anything that identifies a person), UK GDPR says you must report the breach to the ICO (the Information Commission's Office, the UK's data protection regulator) within 72 hours of finding out about it. The only exception is when it is unlikely to put anyone at risk.

The 72 hours includes weekends. You don't need every answer before you report: you can tell the ICO what you know and add more later. If the breach is likely to put people at high risk, you need to tell them too, without delay.

I'll help you decide whether to report and what to say. The ICO has guidance and an online form.

Reporting the crime

In England, Wales and Northern Ireland, report cyber crime to Report Fraud (it used to be called Action Fraud), online or on 0300 123 2040. In Scotland, call Police Scotland on 101. I can help you with what to say.

When I bring in specialists

Some incidents need more than one person: a large ransomware attack, a case likely to end up in court, or one where evidence has to be preserved to a legal standard. I'll tell you as soon as I see that, and point you to an incident response firm assured by the National Cyber Security Centre (NCSC), the UK government's cyber security body.

If there are legal questions, such as contracts, liability or a regulator, I'll recommend you speak to a solicitor. I'm happy to work alongside both.

What it costs

Breach work is charged by the hour or by the day, with a minimum of one hour. I'll tell you the rate when you call, before any work starts. Out-of-hours work is by arrangement, and retainer clients get 10% off.

Call now

The sooner it's contained, the less damage it does. You don't need to know what happened before you call.

07736 637990

Monday to Friday, 9am to 5:30pm