March 24, 2026

The First Hour After You Suspect a Breach

Something is wrong. A ransom note on a screen, a vendor saying they got a strange email from you, money that moved without approval. The next hour matters more than the next week, and most of the damage in small business incidents comes from improvised reactions.

Do these things

  • Call for help immediately. Your IT partner, before anything else. Every minute of qualified eyes on the problem is worth ten of guessing.
  • Disconnect, do not power off. Pull the network cable or disable Wi-Fi on affected machines. Powering off can destroy evidence in memory that responders need, and with ransomware it can sometimes make things worse.
  • Preserve everything. The weird email, the screenshot, the timeline of who noticed what and when. Write it down while it is fresh.
  • Change the passwords that matter, from a clean device. Start with email and financial accounts, and assume the compromised machine is watching anything typed on it.
  • Notify your bank fast if money moved. Wire recalls have a short window. Minutes count here more than anywhere.

Do not do these things

Do not pay anyone, promise anything, or reply to the attacker. Do not wipe the machine, as tempting as a clean slate feels; you may destroy the only record of what was taken. And do not keep it a secret from your own leadership. Incidents handled quietly get handled badly.

The better version of this post is the plan you write before anything happens. Book a free consultation and we will build one with you, calmly, in advance.

Questions about your own setup?

Let’s Connect