My Business Was Hacked: Immediate Response Guide
Your business was just hacked. Panic is normal, but you have 24 critical hours. Here's exactly what to do in the first steps.
Your phone rings. Your computer freezes. A message appears on screen: "Your files have been encrypted. Pay or lose everything."
Or worse: You discover someone accessed your customers' information.
Panic is understandable. But in the next minutes and hours, every action you take matters. Here's the step-by-step guide to survive an attack.
Minutes 1-15: Stop the Spread
Step 1: Disconnect Everything
If you see a ransomware message or suspect compromise:
1. Unplug the computer from the network — literally. Shut it down or disconnect ethernet/wifi
2. Do it on ALL affected machines — Don't wait, don't investigate, disconnect now
3. If it's a server, physically disconnect the machine from the network switch
4. Don't reboot — A reboot can activate dormant malware
Why? Attackers often install secondary malware that spreads automatically to other machines on your network. Every minute connected is another compromised device.
Step 2: Isolate the Problem
- If only one person sees the malware, it might be their machine
- If multiple people report the same thing, it's a network infection
- If there's a suspicious file (.exe, .zip, .scr), who received or downloaded it
Document everything: Exact time, who saw what, what happened before (suspicious email, weird install, etc.)
Step 3: Call the Experts
NOW, not tomorrow. Call:
- Your IT provider (if you have one)
- An incident response specialist
- In Mexico: Simiriki or a certified forensic lab
They need to see the machine ASAP, while malware is still active in memory.
Hours 1-4: Preserve Evidence and Communicate
Step 4: Preserve the Crime Scene
While waiting for experts:
- DON'T touch the affected machines — If you were, stop. Power them down and wait
- Take notes: What exactly did you see, what time, who was at the machine, what emails or files looked odd
- Collect visual evidence: Take photos of any message, screen grab, obvious changes
- Check backups: When were your last backups? Are they accessible? (Don't touch them yet, just confirm they exist)
Step 5: Notify Your Leadership Team
Meet (in person or secure video call, NOT over compromised email) with:
- Your CEO/owner
- Your accountant or finance person
- Your legal contact (if you have one)
What to say: "We detected [type of problem: malware/unauthorized access/data theft]. We've isolated the systems. Specialists are investigating. Here's what we know and what we'll do."
What NOT to say: Speculation, unconfirmed victim numbers, or promises you can't keep.
Step 6: Notify Your Customers (If Necessary)
Was customer information compromised (names, emails, phone numbers, addresses)?
- Yes: You must notify. Mexican law LFPDPPP requires it
- No: Still, prepare in case investigation reveals otherwise
Effective notification:
- Be honest
- Explain what happened in simple terms
- State what specific information was compromised
- Explain what you're doing
- Offer support (hotline, credit monitoring if necessary)
Don't wait weeks. Notify within 72 hours if personal data was affected.
Hours 4-24: Assessment and Containment
Step 7: Let the Experts Do Their Work
Forensic investigation takes time. They will:
1. Image hard drives of affected machines (before making any changes)
2. Review logs: When the attacker entered, what they accessed, how they moved through your network
3. Seek back doors: Methods left to return
4. Collect evidence: For police, if you report it
Your job: Answer questions. Who had access to this machine? What data is here? When was the last backup?
Step 8: Assess Real Damage
With experts, determine:
- What data was accessed (even if not encrypted)
- If there's evidence of data theft
- The scope: One machine? Entire network?
- Attack type: Ransomware? Data theft? Both?
Step 9: Decide About Payment (If Ransomware)
If attackers demand money:
Recommendation: DON'T PAY
Reasons:
- 43% of companies that pay still don't recover their data
- It reinforces attackers to keep attacking
- It may be illegal if the attackers are on sanctions lists
Better:
- Recover from backups (if you have them)
- Accept data loss and rebuild
- Report to police (Fiscal Especializada en Ciberdelitos in Mexico)
If you absolutely must pay (sole critical client, no backup data):
- Negotiate with experts
- Involve police/insurance
- Follow attacker instructions exactly
Hours 24-72: Recovery Plan
Step 10: Rebuild Safely
With experts:
1. Clean all machines from clean backup or fresh install
2. Change ALL passwords (start with administrator)
3. Review access permissions: Who has what? Reduce to minimum necessary
4. Implement MFA: On all critical access (email, admin, VPN)
5. Reinstall systems one by one, testing in isolation
Step 11: Close the Doors
Now that you know how they got in:
- Critical patches: Update Windows and software immediately
- Firewall: Configure rules to block unauthorized access
- Antivirus/EDR: Install protection on all endpoints
- Monitoring: Consider a managed 24/7 SOC (Security Operations Center)
This isn't just about fixing damage. It's about preventing this from happening again.
Step 12: Report Formally
- Police: File a report with Fiscal Especializada en Ciberdelitos
- Insurance: If you have cyber insurance, notify formally
- Key clients/vendors: Some will have notification requirements
Having a forensic report is crucial here.
What You Learned (Even Though It Hurts)
A cyberattack isn't a "technical error." It's a breach in your defenses.
In the coming months:
- Full security audit
- Employee training on phishing
- Automated backup policy
- MFA everywhere
- 24/7 monitoring
At Simiriki, we help companies like yours respond quickly to attacks and, more importantly, prevent them. We conduct specialized incident response audits to find exactly how someone would have gotten in, and we close those doors.
If your business was hacked, you're not alone. Contact us for an incident response audit — we'll help ensure this never happens again.
Is your business protected?
A free Microsoft 365 audit—the automated scan delivers a preview in 90 seconds. Find risks before they become incidents.