What to do in the first hours of a cyber incident
Free, practical guidance for victims of ransomware, fraud, scams, breaches, and insider theft — the steps that protect your money, your evidence, and your composure before professional responders engage.
Subscribe via RSS— follow new advisories in your news reader.
Clear head, cold blood: managing panic during a cyber incident
Cyber incidents are psychological events before they are technical ones. Attackers weaponize urgency — deliberate calm is a countermeasure, and it can be practiced.
Do we have to tell anyone? Breach notification in plain language
Regulators, customers, partners — after a breach, who must hear about it, and by when? The clocks start earlier than most teams think, and the decision needs a written trail either way.
Your first cyber insurance claim: keep the coverage you paid for
The incident is real and the policy exists for exactly this. Between here and a paid claim sit notice deadlines, panel rules, and a documentation trail — start all three now.
Preserving digital evidence: what to save before responders arrive
In the gap between discovering an incident and professional response, evidence either survives or it doesn't. You don't need forensic tools — you need to stop destruction.
Sextortion: they have intimate images and are demanding money
Someone you trusted online is threatening to send private images to your family and followers unless you pay. Do not pay — payment escalates. There is a path through this, and you are not walking it alone.
Suspected insider data theft: investigate quietly, act correctly
When the threat has a badge and a login, the first days decide the case. Mishandled, they destroy the evidence, the legal position, and sometimes an innocent career.
Wrong recipient, public bucket: when the leak was an accident
A spreadsheet to the wrong client, a storage bucket open to the internet. No attacker, real exposure — and the clock does not care that it was a mistake.
Scammed online: your first moves after financial fraud
Investment platforms that vanish, "support" that drains accounts, a relationship that turned into transfers. Recovery depends on speed and evidence — not confrontation.
The CEO on the call wasn't the CEO: deepfake voice and video fraud
A live call, the right face, the right voice, an urgent confidential transfer. Cloned audio and video now survive real-time conversation — process is the only reliable defense.
Company network breach: contain it without destroying the evidence
An attacker is — or was — inside your network. Your next moves either preserve the ability to answer "what did they take?" or erase it permanently.
Payroll diversion: the "employee" who changed their bank details wasn't
HR processed a routine direct-deposit change, and salary went to a criminal's account. It is business email compromise aimed at payroll — and it responds to the same clock.
Your vendor was breached: assume nothing, rotate everything they held
The email says your provider "detected unauthorized access". Their incident just became your exposure — measured by what they could reach and what they stored.
Identity theft: contain the damage, step by step
Accounts you didn't open, charges you didn't make, a login that no longer accepts your password. Work account by account, in the right order, and write everything down.
Your company appeared on a leak site: verify before you react
A ransomware crew's blog lists your name, a countdown, and "proof" samples. What happens next should be driven by verification and law — not by the countdown.
Microsoft 365 or Google Workspace compromised: evict them from the tenant
An attacker is inside your productivity cloud — mail, files, identities. Password resets alone do not evict them; tokens, app grants, and rules do the persisting.
Business email compromise: the first 24 hours after wire fraud
A payment went to a criminal account after an email that looked exactly right. Funds can sometimes be frozen — but the window is measured in hours, not days.
Crypto wallet drained: trace it, report it, stop the bleeding
The balance is gone in transactions you never signed — or one you did sign, without understanding what it approved. Reversal is rare; tracing and freezing are not hopeless.
Website defaced: restore it without erasing the way they got in
Your homepage is showing someone else's message. The defacement is the visible symptom — the access that made it possible is the actual incident.
Ransomware attack: what to do in the first hour
Screens are locked and a ransom note is on your systems. What you do in the first hour decides how much you recover — and how much evidence survives.
DDoS attack: your site is down and the traffic keeps coming
The site is unreachable, monitoring is red, and traffic graphs are vertical. Mitigation lives upstream — and sometimes the flood is cover for something quieter.
Stolen laptop: from lost hardware to data exposure, and back
A laptop is gone — car, café, airport. Whether this is a hardware receipt or a data breach depends mostly on one fact: was the disk encrypted?
Malware on a work device: the alert fired — now what
The antivirus flagged something, or the machine started behaving strangely. What you do next either hands responders a clean picture or smears it.
SIM-swap attack: your phone number was just stolen
Your phone drops to "No service" and password-reset emails start arriving. Someone convinced your carrier to move your number — and every SMS code now goes to them.
Your social account is hijacked and messaging your followers
You are locked out, the profile is posting crypto scams, and your followers are getting DMs "from you". Recovery and damage control have to run in parallel.
Your password showed up in a breach dump: what it really means
A monitoring alert says your email and password are circulating. The danger is not the site that leaked — it is every other account where you reused that password.
After the fake support call: they had remote control of your computer
A "Microsoft technician" or "bank fraud team" walked you into installing remote-access software. Everything on that machine — and every account it touched — now needs a reset.
"We recorded you": extortion emails, and how to tell bluff from breach
An email claims they hacked your webcam, shows you a real password, and demands cryptocurrency. Almost always it is a mass-mailed bluff — here is how to check, and what to do either way.
I clicked a phishing link: what actually happens now
You clicked, maybe you typed a password — and now your stomach is in your shoes. What matters is the next ten minutes, not the last ten seconds.
In the middle of one of these right now?
The advisories cover the first hours. For everything after that, engage a responder — fixed fee, 24/7, worldwide.