14°C

broken clouds

TFL Updates
London Daily News

7 proven steps to handle a cybersecurity breach and protect your business

7 proven steps to handle a cybersecurity breach and protect your business

Last month, I received a panic call at around 3 AM from a client whose e-commerce site was displaying blank text and redirecting customers to a shady pharmacy website. The next thing is a 60-70 hour marathon of disaster control, forensic investigation, and demanding recovery, which reminded me that having a good incident response plan in place is underrated. It’s a matter of business survival.

I’ve handled dozens of breaches over my career, and one thing remains constant: how you respond in those first few hours determines everything. No breach is identical, but there’s a method to the madness of recovery that I’ve learned the hard way.

Step 1: Keep calm

That terrible moment when you realise the hackers didn’t just get in, but have a barracks base in your network for weeks? It makes your stomach drop. The key isn’t avoiding fear, it’s working through it.

This might sound easier said than done, especially when alarms are going off and files are acting strange. But here’s the deal: panic doesn’t solve anything. If anything, it often makes responses to breaches worse. People start pulling cables, shutting down everything, and deleting stuff they shouldn’t.

Take a breath. Pause. Then start thinking clearly. A calm and measured approach is your best ally right now. Gather yourself. This is a challenge, yes, but it’s one you can get through step by step.

Step 2: Detection: Differentiate Actual Threats from False Alarms

Before taking action, confirm it’s not just a glitch, a misconfiguration, or even user error. Don’t go into full lockdown mode just yet.  Look for the following signs:

  • Unforeseen system slowdowns
  • Check for unauthorised logging into systems
  • Strange files appearing or disappearing
  • Your antivirus software is screaming/beeping.

Before taking any technical actions, notify the relevant authorities or stakeholders within your organisation. If you have an IT or security team, they should lead the investigation, not an individual acting alone. If you’re the designated “tech person” in a smaller organisation, get explicit permission before accessing admin dashboards, server logs, or email records to investigate what happened.

Step 3: Establish the boundaries: Containment Strategies That Work.

Once you have confirmed a cybersecurity breach, the next logical step is to contain the damage. This means:

  • Isolating affected systems from the network
  • Changing passwords for admin-level users
  • Disabling features or systems that seem compromised

While disconnecting infected systems is standard protocol, I’ve seen cases where an immediate shutdown triggered the malware’s destructive payload. In one financial institution breach, keeping the compromised server online while monitoring traffic helped identify the exfiltration methods—context matters. Sometimes the textbook response isn’t the right one for your specific situation.

The goal here is simple: stop the bleeding. Don’t worry about cleanup yet, focus on making sure the problem doesn’t spread further. As you take action, keep a record of your notes. Document everything you’re doing. It might help later when you’re piecing together what happened or relaying the incident to the authorities or management.

A small accounting firm I worked with had its server encrypted with ransomware during tax season. What made recovery possible wasn’t fancy technology—it was the office manager who insisted on keeping one backup drive completely offline at all times, despite the IT consultant calling it “paranoid overkill.” That $89 external drive ended up saving them $50,000 in ransom demands. Sometimes the simplest precautions make all the difference.

7 Proven Steps to Handle a Cybersecurity Breach and Protect Your Business

Step 4: Clearing the attacker’s footprint

Don’t overlook the less obvious places attackers hide. During the containment phase, prioritise looking for EDR logs for signs of compromise, and also review your WAF settings for any suspicious rule changes. Some attackers love to create backdoor API endpoints that bypass normal authentication channels. I’ve seen clever hackers modify scheduled tasks to reestablish command-and-control channels days after a “successful” cleanup.

If you’re not confident doing this yourself, an experienced cybersecurity consultant can help identify hidden issues you may miss, such as backdoors or persistent threats.

Now, here’s where things get tricky. Once you’ve eliminated the attacker’s presence, you might be tempted to rush back to business as usual. Don’t. This next phase requires even more restraint and methodical thinking than the cleanup.

Step 5: The Steady Recovery Phase

Once the threat is gone and the environment is clean, it’s time to get things back to normal. Hopefully, you’ve been keeping good backups, because this is where they come into play. Restore your systems from a safe backup and keep them free from compromise.  Then:

  • Test everything thoroughly
  • Monitor traffic and user activity closely
  • Double-check configurations and access rights

Don’t rush. A slow, steady recovery is better than a fast one that reintroduces problems.

Also, keep your team informed. People work better when they know what’s happening. Silence breeds rumors, and rumors cause a lot of panic. A little transparency here goes a long way.

Step 6: Communication During Crisis

Whether you like it or not, communication is an essential part of the process. If customer data is affected, you should inform your clients. If it was serious, regulators or partners might also need to know.

It’s tempting to sweep things under the rug, but if it leaks (and it usually does), it looks worse. Own the situation. Be honest, but professional. Say what happened, what you’re doing about it, and how you’re protecting their interests in the future.

A simple message like this can help pacify your partners:

“We recently ran into a security breach affecting part of our system. We immediately executed a plan to contain and resolve it. Experts’ hands-on desk to ensure this doesn’t happen again. We greatly appreciate your trust and patience.”

Avoid pointing fingers or sharing technical jargon when communicating. Keep it clear, respectful, and responsible.

Step 7: Post-Incidence: Analysis of Results

A breach is a wake-up call. Yes, it’s stressful. But it’s an opportunity to grow stronger. Once the crisis is over, please take a moment to reflect and prevent it from happening again.

Ask:

  • What exactly happened?
  • How did we respond?
  • What did we miss?
  • What needs to change?

This step isn’t about blame, it’s about learning. Document your findings. Update your policies. Train your team better. You may need better backups, stronger passwords, or multi-factor authentication. Your staff may need training on phishing awareness. Every lesson learned is one more wall between you and the next attacker.

7 Proven Steps to Handle a Cybersecurity Breach and Protect Your Business

Conclusion: Get ready, don’t panic

Let’s face it, we live in a digital world where threats are a real concern. But that doesn’t mean you should walk around paranoid. It just means you should be better prepared.

  • Must have a Solid incident response plan.
  • Know who to call when something goes wrong.
  • Regularly back up your data
  • Employee training
  • Invest (as much as you can) in cybersecurity tools and services.

At the end of the day, how you respond is what defines the outcome. A well-handled breach might even build trust because people see that you’re responsible, transparent, and committed to improvement.

So, the next time the cyber criminals come knocking, you’ll know what to do.

 

Rasheed Afolabi is a cybersecurity professional pursuing a Master of Science in Information Systems at Baylor University, with a specialisation in system analysis and network security.

LinkedIn Profile: https://www.linkedin.com/in/rasheedafolabi1/

 

Pin It on Pinterest