Basic Steps to Take After a Suspected Data Breach
If you suspect your business has been compromised, the first hour matters. Here's a basic response outline.
If you suspect a breach — unusual account activity, a ransom note, or a report from a client that their data has been exposed — the first priority is containment. Disconnect affected systems from the network to stop further spread, but avoid powering them off completely if possible, since that can destroy evidence useful for investigation.
Change passwords for any accounts you believe may be compromised, starting with anything with administrative access, and enable MFA anywhere it isn't already active. Document what you're observing and when, which will help both your IT team and, if needed, any legal or insurance process that follows.
Contact your IT provider or incident response team immediately rather than trying to fully resolve a serious incident alone — and if client or personal data may have been exposed, get legal advice on your notification obligations under Canadian privacy law.
Related Articles
May 10, 2014
What to Do About the Heartbleed Bug
A plain-English explanation of the Heartbleed OpenSSL vulnerability and the steps small businesses should take.
March 12, 2015
Protecting Your Business From CryptoLocker-Style Ransomware
Ransomware that encrypts your files and demands payment is on the rise. Here's how to reduce your risk.
December 6, 2016
What Is Ransomware and How Locky Spread So Fast
A look at how one of this year's most widespread ransomware campaigns tricked so many businesses.
Prefer to have this handled for you?
Our team can take care of this and everything else on your IT plate — no obligation to find out how.