Someone clicks something. An invoice gets paid to the wrong account. A client says they’ve had a strange email from you. Whatever the trigger, the next hour matters more than the rest of the week.

This is the order we work in, and why.

Disconnect, don’t shut down

Take the affected computer off the network: unplug the cable, turn off its Wi-Fi. That stops anything spreading or being sent out.

Don’t power it off. Shutting down destroys what’s in memory, which is often where the useful evidence lives. If something serious has happened, that evidence may be the only way to find out what was taken.

Leave it on, off the network, and don’t start “having a look around” on it.

Change passwords from a clean device

Don’t use the computer you suspect. If something is capturing keystrokes, you’re handing it the new passwords too. Use a phone or a different machine.

Order matters here as well:

  1. Email first. Password resets for everything else land there.
  2. Banking and anything that moves money.
  3. Anything that shares the compromised password including anywhere else you reused it.

Then sign out all active sessions, not just change the password. A changed password does not eject someone already signed in.

The step almost everyone skips

Check the mailbox for rules the attacker left behind.

It’s the most common thing we find, and the step most often missed. Someone who gets into a mailbox will often create a rule that forwards mail to an outside address, or moves anything containing “invoice” or “payment” straight to a folder nobody reads. They then keep reading your mail long after the password has been changed.

Look for forwarding rules, unfamiliar filters, and any new “connected apps” or granted permissions on the account. Remove anything you don’t recognise.

Work out what they could reach

Before you can decide what to tell anyone, you need a rough answer to one question: what was that account able to see?

An email account with nothing much in it is a very different problem from one holding client files, invoices with bank details, or staff records. Check the sign-in history. Most systems will show you when and roughly where an account was accessed from, and that usually tells you how long they had.

Write down what you find as you go, because you won’t remember the details later.

Who to tell

Tell your bank straight away if any money or bank details were involved — the sooner they know, the better the chance of getting the money back.

Tell anyone whose information may have been exposed. If a client’s details were in that mailbox, they need to know, because they may now be targeted using it.

Depending on the size of your business and the kind of information involved, you may also have a formal obligation to report the breach. Find out whether that applies to you before anything happens, rather than trying to work it out during a bad week. We can point you at the right guidance.

Then fix the reason

Once it’s contained, the useful question is how they got in. Almost always it’s a password without a second factor, or a mailbox nobody was watching.

Fix that as well, or the same thing is likely to happen again within months. The first hour limits the damage, and the week after is when you stop it recurring.